Skip to main content

Threats Tagged 't1480'

View all threats tagged with 't1480'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: t1480

Threats Tagged 't1480'

Click on any threat for detailed analysis and mitigation recommendations

A previously undocumented Linux toolkit has been targeting South Korean automotive and media organizations with minimal detection since early 2025. The campaign employs a HAProxy instance called ted backdoor, compiled within the victim's existing HAProxy version 2.8.12, alongside trojanized versions of crond, agetty, atd, sshd, and polkitd. This sophisticated framework enables remote command execution, malicious script injection into web traffic, credential harvesting, and long-term surveillance. The ted backdoor uses HAProxy's native filter API and internal structures to intercept SSL-decrypted HTTP traffic while maintaining legitimate load balancing operations. Operating alongside are an SSH keylogger, a curl-based RAT with HAProxy health monitoring capabilities, and a deployment stager. The toolkit is attributed with medium confidence to DPRK APTs based on targeting patterns, simple XOR-based encryption schemes, custom substitution ciphers, and C2 infrastructure associated with APT37.

Join the discussion

Thirteen malicious Composer theme packages published on Packagist across five vendor namespaces inject JavaScript into Vietnamese movie and comic streaming sites. The injected code executes two operations: a mobile ad-fraud and gambling redirect chain, and on iPhones, a WebKit-to-kernel exploit chain installing spyware. The iOS chain weaponizes CVE-2025-31277 and CVE-2025-43529, targeting devices running iOS 18.4 through 18.6.x on iPhone XS through iPhone 16. The exploit chain progresses from WebKit renderer through GPU process to kernel escape via AppleM2ScalerCSCDriver, ultimately deploying spyware that exfiltrates keychain databases, cryptocurrency wallet seeds from seven wallet applications, Wi-Fi passwords, SMS, photos, contacts, and location data. Infrastructure resolves to FUNNULL, a sanctioned provider operated by Chinese national Liu Lizhi. The theme operators are Vietnamese-based, publishing trojanized forks of OphimCMS and KKPhim projects, affecting site operators who unknowingly serve malicious...

Join the discussion

This macOS malware campaign uses social engineering via fake CAPTCHA pages to trick users into running malicious AppleScript commands. It deploys a persistent backdoor that leverages EtherHiding by storing command-and-control (C2) addresses in Polygon blockchain smart contracts, complicating detection. The malware maintains persistence through LaunchAgents and delivers multiple payloads including the AMOS stealer, which targets cryptocurrency wallets, browser credentials, and macOS Keychain data, as well as the XMRig cryptominer for ongoing revenue. The campaign employs advanced evasion techniques such as character-ID obfuscation and abuse of legitimate macOS utilities. Blockchain transaction analysis reveals the full history of C2 infrastructure rotation and funding, aiding defenders despite the malware's memory-resident nature.

Join the discussion

A long-running campaign compromised the QuickFox VPN application, primarily used by Chinese users to access Chinese resources and improve gaming experiences. Active since August 2025, the attack involved trojanized Windows installers (versions 3.0.51.0 through 3.59.5) that deployed malicious JavaScript through modified Electron renderer HTML files. The JavaScript loader fingerprinted victim endpoints using process-based guardrails, checking for specific applications including administrative tools, cryptocurrency wallets, and Chinese translation software while avoiding Steam users. Successfully profiled targets received an FDMTP implant through DLL sideloading techniques using legitimate Microsoft Azure binaries. The infrastructure demonstrates active development with multiple staging domains masquerading as legitimate services. QuickFox removed malicious components from version 3.59.6 following responsible disclosure. Technical overlaps suggest possible connections to Twill Typhoon, though attribution remain

Join the discussion

ESET Research contributed to a global disruption operation targeting the Amadey botnet and Stealc infostealer, both malware-as-a-service offerings. The operation, coordinated by Microsoft Digital Crimes Unit, BitSight, Lumen, and MBSD, impacted approximately 50 domains and nearly 200 active IP-based command and control servers. ESET provided technical analyses, statistical information, C&C server lists, encryption keys, campaign identifiers, and affiliate-level insights gathered from three years of tracking. Both malware families operate through affiliate networks where operators deploy their own infrastructure, making disruption efforts particularly challenging. Amadey primarily functions as a modular loader distributing additional payloads, while Stealc focuses on credential theft from browsers, crypto wallets, and applications. The largest Amadey botnet cluster accounted for 34% of all samples and distributed an average of 14 payloads per victim, operating a pay-per-install model that monetized compromi...

Join the discussion

A highly sophisticated multi-stage post-exploitation framework targeting organizations in the Middle East and EMEA financial sectors exploits legitimate digitally signed Intel utilities through .NET AppDomainManager mechanism abuse. The attack leverages trusted binary proxy execution, bypassing EDR and antivirus solutions through JIT-based memory execution and sandbox evasion using computational delays and cryptographic key derivation loops. Initial access occurs via spear-phishing with Arabic-language decoys impersonating Saudi government documents. Once executed, the framework establishes command-and-control communication through Amazon CloudFront CDN domain fronting, employing reflective DLL loading, direct syscall usage, and anti-forensic memory cleanup techniques. The modular plugin-based architecture demonstrates capabilities consistent with advanced persistent threat actors, featuring sophisticated evasion mechanisms including PEB-based API resolution, custom PE export walking, and heap-walking cont...

Join the discussion

LockBit 5.0, the latest version of the notorious ransomware, has been released with support for Windows, Linux, and ESXi systems. This update brings improved defense evasion, faster encryption, and enhanced modularity. The Windows variant employs extensive anti-analysis techniques, while Linux and ESXi versions remain unpacked. All variants share a common encryption scheme using XChaCha20 and Curve25519. LockBit 5.0 demonstrates a focus on enterprise and infrastructure targets, including explicit support for Proxmox virtualization. The group's data leak site reveals a primary focus on the U.S.business sector, with victims spanning various industries. LockBit's infrastructure has shown connections to SmokeLoader, suggesting possible cooperation or infrastructure reuse among malware operators.

Join the discussion

Showing 1 to 7 of 7 results

Filters:Tag: t1480
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses