Skip to main content

Threats Tagged 't1218'

View all threats tagged with 't1218'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: t1218

Threats Tagged 't1218'

Click on any threat for detailed analysis and mitigation recommendations

BambooToken is an emerging multiplatform malware family active since at least February 2023, utilizing the Message Queueing and Telemetry Transport (MQTT) protocol for covert command and control operations. The campaign targets Windows and Linux systems across Asia and South America, with infections observed on backend servers for mobile applications, legal and financial services, software companies, hotels, and GitLab instances. The malware leverages sideloading techniques through Tendyron's OnKey authentication software, commonly used in Chinese banking and government networks. Analysis reveals extensive host enumeration capabilities, plugins for antivirus detection, and potential keylogging and clipboard theft functions. Infrastructure analysis shows C2 domains ranking in Cloudflare's top 500,000, indicating widespread infections. The actor demonstrates sophisticated operational security, using MQTT's publish-subscribe architecture to hide infrastructure and employing Cloudflare proxies for additional o...

Join the discussion

In July 2026, IIJ discovered and analyzed an unknown .NET-based malicious tool hosted on a public directory. This tool, named PIVOTPIPE, exhibits functionality similar to Cobalt Strike Beacon, communicating with C2 servers using configurations close to default profiles and supporting numerous C2 commands. However, PIVOTPIPE differs from official Cobalt Strike Beacon through unique implementations including detection evasion code, custom loaders, and obfuscated strings. The tool consists of two components: a loader and RAT module. The loader implements AMSI bypass, indirect syscalls, and sleep masking for EDR evasion. PIVOTPIPE supports TCP Beacon and SMB Beacon functionality for peer-to-peer communication through compromised hosts. Debug artifacts suggest the tool was still under development at the time of discovery, indicating potential future enhancements.

Join the discussion

This threat involves a sophisticated malware infection chain that uses PowerShell loaders to deliver encrypted NetSupport Manager payloads hidden inside fake MP4 files. These MP4 files appear legitimate to basic file-type checks but contain encrypted data in ISO Base Media File Format uuid extension boxes instead of actual video content. The attack starts with PowerShell scripts delivered via Cloudflare-fronted infrastructure, which perform environment checks before retrieving the malicious carrier file. A secondary script extracts and decrypts a large embedded PowerShell payload that silently installs NetSupport Manager, a remote administration tool. The infrastructure includes multiple live endpoints across several autonomous systems, primarily located in Frankfurt and Los Angeles, with command-and-control gateways registered in rapid succession. The attackers use Russian-language business site decoys and frequently rotate carrier files without backward compatibility.

Join the discussion

In July 2026, a supply chain attack targeted the official AsyncAPI NPM organization, where attackers published malicious package versions under the trusted AsyncAPI namespace. These compromised packages deployed a multi-stage Remote Access Trojan (RAT) via obfuscated lifecycle hooks that executed during normal build workflows. The malware retrieved additional payloads from IPFS gateways, established persistence on infected systems, and communicated with external command-and-control infrastructure. The attack exploited trusted build automation and dynamic package retrieval mechanisms, impacting developers using version-pinned tasks in CI/CD pipelines.

Join the discussion

Analysis of over 400 AI-enabled malware samples shows that most remain confined to research and sandbox environments, with only a small fraction observed on protected endpoints across three countries. These samples span five malware families including FunkSec ransomware and Oyster backdoor. Existing behavioral detection, cloud sandboxing, and endpoint analytics successfully detect and block all observed samples. The AI component primarily accelerates malware development rather than enabling evasion of defenses. Distribution patterns are opportunistic rather than targeted.

Join the discussion

A sophisticated backdoor disguised as a legitimate Malwarebytes installer was distributed to over 100,000 machines through compromised automatic updates of one torrent client (Download Studio) and three adblockers (NetShield Kit, My AdBlock, and Net AdBlock). The backdoor creates a fake Malwarebytes installation directory containing legitimate signed files alongside malicious DLL files. Once executed, it establishes persistence through a Windows service and communicates with command-and-control servers to receive configuration updates and additional payloads. The primary observed payloads were cryptocurrency miners, though the infrastructure supports delivery of multiple persistent threats. The attack demonstrates abuse of software update mechanisms and affects primarily users in Russia, Ukraine, and Kazakhstan.

Join the discussion

A campaign uses fake websites impersonating CNN, Stremio, and Avast to distribute legitimate remote administration software O&O Syspectr pre-linked to attacker accounts. The lookalike sites closely mimic authentic homepages and trick Windows users into downloading installers that appear legitimate but grant attackers remote access to victim computers. Additional fake sites use cryptocurrency mining game lures to distribute the same tool. All installers are digitally signed legitimate software, making antivirus detection difficult. The campaign uses multiple Syspectr account IDs embedded in filenames, with CNN, Avast, and Stremio lures sharing one account while crypto-mining lures use another. O&O Software responded by disabling Remote Desktop and Remote Console access for free accounts and suspending the abusive accounts.

Join the discussion

An investigation uncovered a sophisticated infection chain beginning with a ClickFix lure and utilizing a legitimately signed IBM SPSS IDE alongside four decoy DLLs and a date-formatting API as a trampoline. This chain deploys BabaDeda loader stage that ultimately delivers CNCMachineRMS, a 1.14 MB x64 remote administration implant with no imports and runtime-built strings. The implant provides operators with comprehensive remote access capabilities including an interactive shell, file manager, screen capture, local account backdoor, and seven persistence mechanisms. It employs a custom scripting language and uses the same binary container format for configuration and C2 traffic. The implant beacons every 600 seconds, creates privileged local accounts, and supports twenty typed commands for downloading and executing additional payloads, indicating hands-on-keyboard access with follow-on stages determining actual damage.

Join the discussion

A threat actor published over 700 malicious packages to the NPM registry within 48 hours using AI-generated typo-squatting package names. These packages deploy a cross-platform RAT and infostealer without requiring install scripts, executing immediately upon import via require(). The downloader supports Windows, Linux, and macOS, rotating through three Cloudflare Workers hosts for payload delivery with a DNS TXT record fallback under wel1.ru. The macOS payload establishes persistence via LaunchAgents and downloads additional beacons. The Linux version delivers what appears to be a Sliver implant. The campaign shows connections to the earlier Moika malware operation, with shared tradecraft including focus on Russian financial institutions, fake telemetry camouflage, and similar kill switch mechanisms. The malware includes anti-analysis capabilities detecting debuggers, virtualization, and packet capture tools.

Join the discussion

A sophisticated macOS campaign has been discovered using a fake Zoom installer to deploy Overlord RAT, an open-source remote access framework. The attack employs a .NET-based downloader disguised as ZoomMeetings, representing an uncommon approach for macOS threats. The multi-stage attack fingerprints the victim's system to deliver platform-specific payloads for macOS ARM64, macOS Intel, or Windows from attacker-controlled infrastructure. The second stage deploys Overlord RAT with extensive capabilities including keylogging, screen capture, audio and webcam access, filesystem manipulation, and remote desktop streaming. The malware communicates with command-and-control servers over encrypted WebSockets and maintains persistence through LaunchAgents. The campaign shares characteristics with previous North Korean operations, including similarities to FlexibleFerret malware and the Contagious Interview campaign.

Join the discussion

Showing 1 to 10 of 70 results

Filters:Tag: t1218
Page 1 of 7
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses