Skip to main content

Threats Tagged 't1486'

View all threats tagged with 't1486'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: t1486

Threats Tagged 't1486'

Click on any threat for detailed analysis and mitigation recommendations

In late August, an organization was compromised by INC ransomware across at least 175 endpoints. The attack timeline spanned from early to late August with a 17-day gap, suggesting involvement of an initial access broker and a separate ransomware affiliate. Early August activity included scheduled tasks with randomized names and lateral movement via RDP using a compromised account. After the lull, attackers deployed AnyDesk for remote access, used Bring Your Own Vulnerable Driver tactics to disable security controls, and executed ransomware via Impacket tools. Uniquely, two ransom notes were discovered: the standard INC-README.txt and a subsequent DATALEAK_PRESS_RELEASE.txt containing detailed stolen file listings, threatening to contact media, employees, and partners within 48 hours to increase pressure on victims.

Join the discussion

Fraudulent organizations in Korea are exploiting private Home Trading System (HTS) software to distribute ransomware to victims. The unauthorized HTS program called 'UBP Asset' impersonates the legitimate Swiss financial institution Union Bancaire Privee (UBP) and has been used in investment scams since at least September 2025. Attackers lure victims through social media platforms like Telegram and KakaoTalk, convincing them to install the fraudulent HTS and deposit funds. The latest campaign involves distributing KRSID ransomware through the HTS update mechanism, which encrypts files using AES-256 and RSA-2048 algorithms. Previous campaigns used similar private HTS programs to distribute Quasar RAT. Victims not only lose their investment funds but also have their systems compromised and files encrypted for ransom demands.

Join the discussion

Settra is a ransomware variant first observed in June 2026 that targets organizations through VPNs or compromised credentials. Two incidents were investigated in July and September 2026, affecting the consumer services, retail, and manufacturing sectors. Attackers deployed MeshAgent RMM for persistence, naming ransomware executables after victim domain names. The malicious activity included file encryption with .locked or .locked_wip extensions, deployment of RESTORE_FILES.txt ransom notes, clearing Windows event logs, and disabling Windows recovery options using reagentc and diskpart utilities. One incident featured Bring Your Own Vulnerable Driver (BYOVD) tactics using gdrv.sys. A notable operational security failure occurred when attackers misspelled the Windows Defender Event Log path, preventing its deletion. Both attacks followed remarkably similar operational patterns, with MeshAgent installations pointing to different C2 IP addresses (45.13.122[.]7 and 193.5.65[.]114), and malicious workstation WIN...

Join the discussion

Cisco Talos is tracking active exploitation of two vulnerabilities in Secure Firewall Management Center (FMC) Software. CVE-2026-20079 is a critical authentication bypass vulnerability allowing remote attackers to execute scripts and obtain root access. CVE-2026-20316 enables remote login using low-privileged accounts and can be chained with other vulnerabilities for privilege escalation. Three distinct threat actor clusters have been identified conducting post-compromise activities: UAT-12197 deployed web shells and credential theft tools; UAT-11823, overlapping with Russian APT Sandworm, deployed Cyclops Blink malware and established reverse shells; UAT-11988, a Qilin ransomware operator, conducted extensive reconnaissance, credential harvesting, and deployed ransomware after establishing persistent network access through tunneling tools. Customers are strongly advised to apply available hotfixes immediately.

Join the discussion

Threat actors are exploiting anticipation for Grand Theft Auto VI by distributing malicious ISO files disguised as leaked game versions. These fake installers are spread through SEO poisoning, gaming forums, social media, and torrenting sites. The analyzed ISO contains multiple malicious components including several RAT variants (NJRAT and DCRAT), Mercurial Grabber infostealer, Chaos ransomware functioning as a wiper, and Yandex Browser. When executed, the fake installer displays Russian-language messages and deploys malware to %TEMP% folders. The package includes data exfiltration capabilities, credential theft, system control features, and destructive file encryption. Based on Russian language usage throughout the infection chain, the campaign appears to target Russian-speaking gamers. The malware components date back to 2023, suggesting repurposed tools for this opportunistic attack.

Join the discussion

A compilation artifact, specifically a developer's home directory path (/home/tcherber/.cargo/), linked multiple malware families including a Rust-based infostealer named Zer0day Stealer, an HVNC remote-control tool, and ENIGMA Locker ransomware to a single developer. The infostealer exfiltrates cryptocurrency wallets, browser credentials, Office documents, and VPN configurations. The HVNC tool enables hidden remote desktop sessions and implements AMSI and ETW evasion techniques. Analysis revealed an actively developed, cross-platform malware operation spanning Windows, Linux, and macOS. Multiple droppers written in C, Rust, and PowerShell were discovered delivering the malicious payloads. Build timestamps indicated development occurred within weeks, and infrastructure leaked evidence of additional tools including FUD-Crypter, Botnet, and C2 Agent components, demonstrating how overlooked compilation artifacts enable comprehensive attribution and threat mapping.

Join the discussion

This analysis discusses how poorly designed AI guardrails in security operations can unintentionally aid attackers by impeding defensive actions. Overly restrictive or inflexible AI filters controlled by third-party providers may cause delays or refusals in security investigations, giving adversaries more time to complete their objectives. The author recommends that security teams maintain operational sovereignty over guardrails, allowing customization and temporary adjustments to safeguards to better align with specific threat models. This flexibility is essential to prevent attackers from exploiting rigid controls to disrupt incident response processes.

Join the discussion

The Gentlemen is a ransomware group active since July 2025, operating a Ransomware-as-a-Service model with dual-extortion tactics. They target Windows, Linux, and ESXi systems, focusing on extensive preparation before encrypting data. Their methods include privilege escalation using legitimate tools, persistence via registry and scheduled tasks, disabling security tools, deleting logs, and terminating backup services. They use strong encryption algorithms XChaCha20 and Curve25519. The group primarily targets medium-to-large organizations in the Asia-Pacific region, with a recent surge in activity. Victims face ransom demands with about 10-day deadlines and threats of data publication if unpaid.

Join the discussion

Analysis of over 400 AI-enabled malware samples shows that most remain confined to research and sandbox environments, with only a small fraction observed on protected endpoints across three countries. These samples span five malware families including FunkSec ransomware and Oyster backdoor. Existing behavioral detection, cloud sandboxing, and endpoint analytics successfully detect and block all observed samples. The AI component primarily accelerates malware development rather than enabling evasion of defenses. Distribution patterns are opportunistic rather than targeted.

Join the discussion

Three financially motivated threat actors acquire expired malicious domains through dropcatch to inherit traffic from previously compromised websites. Stuffy Squirrel specializes in hiding activity within legitimate scripts and has operated since 2020, selling traffic to affiliate advertising networks. Shady Squirrel uses custom JavaScript and Keitaro injections with multi-step cloaking, partnering with initial access brokers to deliver tech support scams and SocGholish malware, notably facilitating SocGholish's return within weeks of Operation Endgame disruption. Swiping Squirrel, the most prolific actor, operates in greyhat territory by selling fraudulent traffic to zero-click advertising platforms like ZeroPark, often resulting in malvertising and malware distribution. These actors control thousands of domains collectively, exploiting lingering infections from previous compromises without conducting new attacks themselves.

Join the discussion

Showing 1 to 10 of 114 results

Filters:Tag: t1486
Page 1 of 12
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses