Threats Tagged 't1222'
View all threats tagged with 't1222'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 't1222'
Click on any threat for detailed analysis and mitigation recommendations
An active malware campaign utilizes fraudulent software-download websites impersonating trusted vendors to distribute malicious installers. The operation primarily targets China-based operations of multinational organizations and Chinese-speaking users across healthcare, manufacturing, gaming, technology, logistics, government, and education sectors. The malicious installers deploy malware capable of establishing persistence, disabling Windows Update services, configuring Microsoft Defender exclusions, deleting volume shadow copies, and establishing command-and-control communications. Microsoft attributes this activity with moderate confidence to the Chinese threat cluster Silver Fox, known for using spoofed vendor download pages to distribute remote access trojans. The campaign leverages high-fidelity clones of legitimate vendor websites hosted on Chinese domains, delivering server-side generated payloads through ZIP archives. Join the discussion | AlienVault OTX General | 09/03/2026, 07:26:56 UTC Added: 09/03/2026, 07:52:49 UTC |
The Gentlemen is a ransomware group active since July 2025, operating a Ransomware-as-a-Service model with dual-extortion tactics. They target Windows, Linux, and ESXi systems, focusing on extensive preparation before encrypting data. Their methods include privilege escalation using legitimate tools, persistence via registry and scheduled tasks, disabling security tools, deleting logs, and terminating backup services. They use strong encryption algorithms XChaCha20 and Curve25519. The group primarily targets medium-to-large organizations in the Asia-Pacific region, with a recent surge in activity. Victims face ransom demands with about 10-day deadlines and threats of data publication if unpaid. Join the discussion | AlienVault OTX General | 08/27/2026, 13:05:03 UTC Added: 08/27/2026, 22:07:26 UTC |
Vect ransomware emerged in January 2026 as a new threat actor operating a Ransomware-as-a-Service program with strategic partnerships that significantly expand its reach. The group has partnered with TeamPCP, known for supply chain attacks compromising security tools like Trivy, KICS, and LiteLLM, and BreachForums, distributing affiliate keys to forum members. With 25 published victims primarily targeting the United States and Technology sector, Vect maintains an open affiliate program requiring only a $250 invite code. The operation offers multi-platform ransomware payloads for Windows, Linux, and ESXi with sophisticated lateral movement capabilities and tiered commission structures reaching 89% for top affiliates. Analysis reveals connections to the defunct Devman ransomware through shared code strings and ransom note similarities, suggesting possible rebranding or code reuse. Join the discussion | AlienVault OTX General | 04/30/2026, 23:40:32 UTC Added: 05/04/2026, 14:06:24 UTC |
A detailed technical analysis confirms that Kyber ransomware implements genuine hybrid post-quantum cryptography rather than mere branding. The Rust-based Windows variant encrypts files using AES-256-CTR with Kyber1024 and X25519 for key protection, appending a fixed 0x744-byte trailer containing encrypted metadata. Instrumented analysis validated the cryptographic implementation through fixture decryption but found no practical recovery path from the sample alone. The encryptor targets multiple file types, deploys standard recovery-inhibition techniques, and marks encrypted files with a .#~~~ extension. A separate ESXi variant was found to use different cryptography despite similar branding. As of April 2026, one victim was publicly listed: a large American defense contractor and IT services provider. Join the discussion | AlienVault OTX General | 04/29/2026, 09:40:17 UTC Added: 04/29/2026, 10:22:37 UTC |
Lazarus Group is conducting an active campaign targeting businesses through ClickFix attacks, distributing a newly identified macOS malware kit called "Mach-O Man". The attack begins with fake meeting invitations via Telegram, redirecting victims to fraudulent collaboration platforms impersonating Zoom, Microsoft Teams, or Google Meet. Victims are tricked into executing terminal commands that install the malware. The kit consists of Go-based Mach-O binaries including a stager, profiler, persistence mechanism, and stealer. The malware collects credentials, browser data, and macOS Keychain entries, exfiltrating data through Telegram. Primary targets include fintech, crypto, and high-value environments where macOS is prevalent. The campaign leverages social engineering and native macOS binaries to evade traditional EDR detection, ultimately enabling account takeover, unauthorized infrastructure access, and financial loss. Join the discussion | AlienVault OTX General | 04/22/2026, 01:40:36 UTC Added: 04/22/2026, 08:46:13 UTC |
RedSun.exe is a publicly available proof-of-concept exploit targeting a zero-day vulnerability in Microsoft Defender on Windows systems. It enables local privilege escalation from a standard user to SYSTEM-level access by exploiting flawed Defender remediation logic for cloud-tagged malicious files and redirecting high-privilege file operations to overwrite protected system locations such as C:\Windows\System32. This allows arbitrary code execution as SYSTEM without needing administrator privileges or kernel exploits. The exploit is reliable, actively weaponized, and potentially unpatched in some environments, posing a significant risk for persistence, lateral movement, and defense evasion. No official patch or remediation guidance is currently available. Organizations should enforce least privilege principles and deploy behavior-based detection focused on suspicious Defender-related file operations and privilege escalation attempts. Monitoring for filesystem manipulation targeting protected system directories is also recommended. Rapid patching should be applied once vendor updates are released. Join the discussion | AlienVault OTX General | 04/21/2026, 08:48:46 UTC Added: 04/21/2026, 09:31:05 UTC |
LockBit 5.0, the latest version of the notorious ransomware, has been released with support for Windows, Linux, and ESXi systems. This update brings improved defense evasion, faster encryption, and enhanced modularity. The Windows variant employs extensive anti-analysis techniques, while Linux and ESXi versions remain unpacked. All variants share a common encryption scheme using XChaCha20 and Curve25519. LockBit 5.0 demonstrates a focus on enterprise and infrastructure targets, including explicit support for Proxmox virtualization. The group's data leak site reveals a primary focus on the U.S.business sector, with victims spanning various industries. LockBit's infrastructure has shown connections to SmokeLoader, suggesting possible cooperation or infrastructure reuse among malware operators. Join the discussion | AlienVault OTX General | 02/12/2026, 15:08:39 UTC Added: 02/12/2026, 22:04:12 UTC |
RansomHouse, a ransomware-as-a-service operated by the Jolly Scorpius group, has upgraded its encryption capabilities with a new version of its Mario ransomware component. This upgrade introduces a sophisticated two-stage encryption process, enhanced memory management, and dynamic file processing, making the ransomware more efficient and harder to analyze. The attack chain involves MrAgent managing deployments and Mario performing file encryption, primarily targeting virtualized environments such as ESXi servers. Although no known exploits are currently in the wild, the improvements signal a trend toward more resilient ransomware variants. European organizations using virtualized infrastructure are at risk, especially those with ESXi deployments. The threat requires no known CVE but poses a medium severity risk due to its complexity and potential impact on availability and data confidentiality. Mitigation should focus on securing virtualization platforms, monitoring for indicators of compromise, and implementing robust backup and recovery strategies. Countries with high virtualization adoption and critical infrastructure reliance on virtual environments are most likely to be affected. Join the discussion | AlienVault OTX General | 12/17/2025, 14:28:36 UTC Added: 12/17/2025, 22:30:09 UTC |
The Shai-hulud 2.0 campaign is an advanced malware operation targeting cloud platforms (AWS, GCP, Azure) and developer ecosystems by stealing credentials and secrets. It automates backdooring of NPM packages maintained by victims, enabling rapid supply chain propagation. The malware abuses GitHub Actions workflows for command-and-control and secret exfiltration, leveraging cloud secret management services and destructive failsafes to maintain stealth and persistence. This campaign threatens the confidentiality and integrity of cloud and developer environments, potentially impacting thousands of downstream users. It requires no known exploits in the wild but uses sophisticated tactics to evade detection. European organizations relying heavily on cloud services and open-source development are at risk, especially those with significant use of NPM packages and GitHub repositories. The threat severity is assessed as high due to the broad impact on supply chains and credential theft without requiring user interaction. Immediate mitigation includes securing cloud credentials, auditing GitHub workflows, and monitoring supply chain dependencies for unauthorized changes. Join the discussion | AlienVault OTX General | 11/27/2025, 14:13:08 UTC Added: 11/27/2025, 18:22:36 UTC |
'The Gentlemen' ransomware group, active since July 2025, operates a Ransomware-as-a-Service (RaaS) platform that employs advanced dual-extortion tactics by encrypting data and exfiltrating sensitive information to coerce ransom payments. Their ransomware targets Windows, Linux, and ESXi platforms, encrypting both local and network-shared drives using strong cryptographic algorithms XChaCha20 and Curve25519. Recent updates include automatic self-restart, run-on-boot persistence, configurable encryption speeds, and attack methods, enhancing their operational resilience and adaptability. The group has publicly disclosed 47 victims within two months, indicating rapid propagation and impact. The malware leverages multiple MITRE ATT&CK techniques such as persistence (T1547.001), data encryption (T1486), and network share discovery (T1135). No known exploits or CVEs are associated yet, but the threat is significant due to its multi-platform support and dual-extortion approach. European organizations with mixed OS environments and ESXi virtualization are at particular risk. Mitigation requires tailored detection of persistence mechanisms, network segmentation, and robust incident response plans. Countries with high adoption of VMware ESXi and diverse enterprise IT infrastructures, such as Germany, France, and the UK, are likely most affected. Join the discussion | AlienVault OTX General | 11/19/2025, 08:48:43 UTC Added: 11/19/2025, 09:41:21 UTC |
Showing 1 to 10 of 20 results