Threats Tagged 't1482'
View all threats tagged with 't1482'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 't1482'
Click on any threat for detailed analysis and mitigation recommendations
The China-nexus threat group Longlegs continues to deploy Warlock ransomware by exploiting Microsoft SharePoint vulnerabilities, particularly the ToolShell exploit chain. Over the past two months, the group targeted at least four organizations including water utilities, telecommunications providers, government bodies, and universities in Portuguese and Spanish-speaking countries across Europe, Africa, and Latin America. The attackers exploit SharePoint flaws for initial access, use DLL sideloading techniques, abuse vulnerable signed drivers like K7RKScan to disable security software, and leverage Visual Studio Code tunneling for covert remote access. They deploy ransomware at scale by staging payloads in domain SYSVOL shares for rapid network-wide distribution, successfully compromising over 40 hosts in some incidents. Join the discussion | CVE Database V5 | 10/01/2026, 15:37:42 UTC Added: 07/08/2025, 17:09:42 UTC |
0 On August 31, 2026, threat actors exploited two zero-day vulnerabilities in PaperCut MF affecting a customer in the Education sector. The attackers targeted an internet-facing print server running vulnerable PaperCut MF version 24.0.2, deploying an in-memory Java loader that established a web shell. Through this web shell, they delivered a trojanized Microsoft Copilot binary containing an AdaptixC2 implant. The implant connected to command-and-control infrastructure hosted on Alibaba servers. After remaining dormant for approximately one day, attackers returned to perform reconnaissance and Active Directory enumeration. They then stole a token from a domain-privileged service account and moved laterally to a domain controller. On the compromised domain controller, they dumped credentials from memory and registry, enabled Windows Restricted Admin mode for pass-the-hash attacks, and extracted the NTDS.dit database containing password hashes for all domain accounts, achieving complete domain compromise. Join the discussion | CVE Database V5 | 10/01/2026, 04:37:48 UTC Added: 08/28/2026, 15:38:05 UTC |
The TerminalFix campaign is a sophisticated multi-stage intrusion targeting organizations via compromised websites that display fake Cloudflare CAPTCHA overlays. Victims are tricked into executing malicious PowerShell commands that download and execute a signed legitimate binary alongside a malicious DLL for sideloading. This leads to steganographic payload extraction, extensive Active Directory reconnaissance, and deployment of a Python-based reverse-tunnel implant providing persistent network-level proxy access. The campaign enables attackers to pivot within the network, conduct domain enumeration, and maintain stealthy persistent access. Although no direct downstream actions were observed, the access gained could facilitate privilege escalation, data exfiltration, and ransomware deployment. The campaign combines advanced evasion techniques and persistent network access, posing a serious threat to enterprise environments. Join the discussion | Microsoft Security Blog | 08/31/2026, 00:14:29 UTC Added: 08/29/2026, 16:39:54 UTC |
Multiple ClickFix malware campaigns have been identified using three delivery methods: MSI packages with DLL sideloading, NodeJS-executed JavaScript, and Python 3.5 payload execution. These campaigns use aggressive social engineering, including phone calls directing victims to compromised WordPress sites. Post-compromise activities include extensive system discovery and Active Directory enumeration. The campaigns share infrastructure and tactics linked to the Lorem Ipsum malware family and Vanilla Tempest adversary, with potential ransomware deployment as a final goal. Join the discussion | AlienVault OTX General | 08/24/2026, 21:19:20 UTC Added: 08/25/2026, 10:52:01 UTC |
Since January 2026, a threat actor likely functioning as an initial access broker for ransomware operations has been targeting organizations through Microsoft Teams vishing attacks. Attackers impersonate IT helpdesk staff to convince victims to initiate Quick Assist remote sessions. Following initial compromise, PowerShell scripts deploy a Go-based backdoor called GoGRPC, which exists in four distinct variants: Lep, Giver, Pet, and Kind. These variants communicate with command-and-control infrastructure using gRPC over HTTP/2, an uncommon approach that helps blend malicious traffic with legitimate communications. Additional tools observed include BlindDoor backdoor, RevSocket and PyGRPC SOCKS proxies, S3Siphon data exfiltration utility, and RSOX Rust-based proxy relay. Recent campaigns show increased sophistication and selectivity, with heightened focus on corporate environments through enhanced PowerShell scripts capable of antivirus detection, domain controller fingerprinting, and system reconnaissance b... Join the discussion | AlienVault OTX General | 07/27/2026, 16:45:15 UTC Added: 07/28/2026, 10:22:27 UTC |
Check Point Research tracks Cavern Manticore, an Iran-nexus threat actor targeting Israeli government and IT sectors. The actor deploys a modular C2 framework built on .NET but compiled into different formats including Mixed-Mode C++/CLI and Native AOT, creating significant anti-analysis challenges. The framework consists of core agents and specialized post-exploitation modules providing capabilities for file system operations, database browsing, LDAP querying, network reconnaissance, and tunneling. Initial access is achieved through abuse of Remote Monitoring and Management software like SysAid. The actor demonstrates supply-chain compromise tactics, using IT providers as stepping stones to reach higher-value targets. Technical overlaps link Cavern Manticore to Iranian MOIS-aligned groups including MuddyWater and Lyceum subgroup of OilRig. Join the discussion | AlienVault OTX General | 07/06/2026, 14:02:13 UTC Added: 07/07/2026, 14:14:38 UTC |
The Gentlemen is a ransomware-as-a-service operation tracked as Storm-2697, distinguished by combining robust per-file encryption using Curve25519 with XChaCha20 stream cipher alongside aggressive self-propagation capabilities designed for broad network compromise. Emerging in mid-2025 and transitioning to RaaS by September 2025, the operation recently partnered with BreachForums to recruit affiliates including penetration testers and initial access brokers. Written in Go and obfuscated with Garble, the ransomware employs double extortion tactics, encrypting data while exfiltrating sensitive information. It utilizes 21 distinct lateral movement techniques per target host, including PsExec, WMI, scheduled tasks, services, and PowerShell remoting. The malware disables defenses, deletes shadow copies and forensic artifacts, and can optionally wipe free disk space to prevent recovery, impacting organizations globally across education, transportation, healthcare, and finance sectors. Join the discussion | AlienVault OTX General | 05/28/2026, 19:56:31 UTC Added: 05/29/2026, 10:48:34 UTC |
0 Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1 has Pre-authentication SQL injection in the virtuser_query plugin via a preg_replace() backslash escape bypass. Join the discussion | CVE Database V5 | 05/25/2026, 19:06:37 UTC Added: 05/25/2026, 19:40:00 UTC |
A sophisticated ClickFix campaign was observed in April 2026 deploying PySoxy, a decade-old open-source Python SOCKS5 proxy tool, to establish encrypted proxy access on compromised hosts. The attack chain begins with social engineering that tricks users into executing obfuscated PowerShell commands, which then establishes scheduled task persistence and deploys an in-memory PowerShell-based command-and-control agent. Following domain reconnaissance activities, attackers deploy PySoxy to create a redundant encrypted access channel. The persistence mechanism continues attempting re-execution even after initial connections are blocked, demonstrating how single ClickFix executions can evolve into modular post-exploitation chains. This development represents a significant evolution from simple one-time execution to durable access with multiple redundant pathways, requiring comprehensive remediation beyond blocking initial callbacks. Join the discussion | AlienVault OTX General | 05/13/2026, 16:41:05 UTC Added: 05/14/2026, 08:36:23 UTC |
The Gentlemen ransomware-as-a-service program has rapidly expanded since mid-2025, claiming over 320 victims with 240 attacks occurring in early 2026. The service provides multi-platform lockers for Windows, Linux, NAS, BSD, and ESXi, enabling comprehensive coverage of corporate environments. During an incident response engagement, an affiliate deployed SystemBC proxy malware for covert tunneling and payload delivery. Analysis of the SystemBC command-and-control server revealed a botnet of over 1,570 victims, primarily corporate and organizational targets. The intrusion progressed from domain controller compromise through credential validation, remote execution via administrative shares, and deployment of Cobalt Strike payloads. Attackers disabled defenses, established persistence through scheduled tasks and services, and ultimately deployed ransomware via Group Policy. The operation demonstrates sophisticated lateral movement capabilities, defense evasion techniques, and integration of mature post-exploit... Join the discussion | AlienVault OTX General | 04/20/2026, 15:00:35 UTC Added: 04/20/2026, 16:31:09 UTC |
Showing 1 to 10 of 17 results