Threats Tagged 't1497'
View all threats tagged with 't1497'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 't1497'
Click on any threat for detailed analysis and mitigation recommendations
Vidar is an information stealer first observed in 2018 that has continuously evolved its string obfuscation techniques to evade detection and analysis. Between May and September 2026, the malware progressed from basic XOR encryption to ChaCha20-based algorithms, and most recently implemented a custom virtual machine executed via a lightweight bytecode interpreter combined with custom stream ciphers that change per build. The VM uses 14 opcode handlers with simple primitives including XOR, addition, rotation, and substitution. Version 2.0 introduced this VM approach, while versions 2.2 and later added ARX-based custom stream ciphers using FNV-1a hashing and golden ratio constants. These per-build variations in opcodes, constants, and substitution tables significantly hinder static and automated analysis capabilities. Join the discussion | AlienVault OTX General | 09/21/2026, 16:45:51 UTC Added: 09/22/2026, 08:02:57 UTC |
0 A previously unknown modular multi-stage framework named MovieReaper has been discovered targeting users through compromised torrent files. Attackers compromised the public torrent repository itorrents[.]org, enabling them to distribute malicious loaders disguised as popular movies, including "The Odyssey." The campaign began in mid-August 2026 and affected hundreds of victims across multiple countries. The malware employs a sophisticated infection chain with fileless execution, utilizing blockchain network Solana for C2 infrastructure resilience. The framework includes multiple stages: an initial loader with anti-sandbox checks, shellcode that retrieves C2 addresses from Solana blockchain, UAC bypass with persistence mechanisms, and a final file manager module providing comprehensive file system access. The campaign demonstrates advanced evasion techniques including manual API resolution, vectored exception handling, and in-memory execution. Join the discussion | CVE Database V5 | 09/17/2026, 16:23:20 UTC Added: 02/24/2026, 14:47:12 UTC |
In July 2026, IIJ discovered and analyzed an unknown .NET-based malicious tool hosted on a public directory. This tool, named PIVOTPIPE, exhibits functionality similar to Cobalt Strike Beacon, communicating with C2 servers using configurations close to default profiles and supporting numerous C2 commands. However, PIVOTPIPE differs from official Cobalt Strike Beacon through unique implementations including detection evasion code, custom loaders, and obfuscated strings. The tool consists of two components: a loader and RAT module. The loader implements AMSI bypass, indirect syscalls, and sleep masking for EDR evasion. PIVOTPIPE supports TCP Beacon and SMB Beacon functionality for peer-to-peer communication through compromised hosts. Debug artifacts suggest the tool was still under development at the time of discovery, indicating potential future enhancements. Join the discussion | AlienVault OTX General | 09/16/2026, 07:16:35 UTC Added: 09/16/2026, 12:16:36 UTC |
The Kimsuky threat group continues Operation GitPower campaigns utilizing malicious LNK files disguised as financial and business documents. Thirteen LNK variants collected between August 11-19, 2026, employ GitHub Personal Access Tokens (PAT) for command-and-control communications, delivering obfuscated PowerShell loaders through custom decoders. Notable evolution includes anti-analysis routines detecting virtualization tools, Pastebin as alternative C2 infrastructure, and diversified decoy formats (PDF, XLSX, PNG). Metadata analysis reveals AI-generated content using the 'opencode' AI coding agent and HeadlessChrome PDF conversion, with placeholder text remaining unreviewed. The group maintains persistence through hidden scheduled tasks masquerading as legitimate software (BitLocker, MATLAB), while hardcoded GitHub PATs enable raw content retrieval. Despite increased sophistication in evasion techniques and decoy production automation, endpoint behaviors remain detectable through behavioral correlation a... Join the discussion | AlienVault OTX General | 09/07/2026, 08:08:29 UTC Added: 09/07/2026, 15:52:27 UTC |
An emerging infostealer tracked as REVSTEALER under REF2859 has gained significant momentum with approximately 4,700 samples identified over the past year. The malware features comprehensive credential harvesting capabilities targeting browsers, VPN applications, password managers, cryptocurrency wallets, and gaming platforms. It incorporates sophisticated anti-analysis mechanisms including a weighted sandbox scoring system and uses Polygon blockchain-based dead drops for resilient infrastructure management. Distribution occurs primarily through social engineering campaigns targeting gamers via compromised YouTube channels advertising fake game cheats, though samples also impersonate legitimate software like Slack and qBittorrent. The malware delivers four additional modules extending capabilities to include wallet theft, clipboard manipulation, reverse proxy functionality, and cryptocurrency mining deployment. Most samples employ VMProtect packing and feature an App-Bound Encryption bypass using debugger-... Join the discussion | AlienVault OTX General | 09/06/2026, 12:08:52 UTC Added: 09/07/2026, 09:52:59 UTC |
Attack campaigns targeting Korean users have been observed deploying remote control tools including Radmin and UltraVNC to compromise systems. The initial intrusion vector remains unidentified, but attackers download compressed files containing batch scripts and remote administration software. Following Radmin installation, threat actors leverage access to deploy UltraVNC alongside proxy tools such as Netch-gateway and CCProxy, ultimately utilizing compromised systems as proxy nodes. Recent variants include SoftEther VPN deployment to establish VPN servers on infected infrastructure. PowerShell scripts containing Chinese language comments, combined with tools familiar to Chinese-speaking actors, suggest attribution to Chinese threat operators. The campaigns enable both remote system control and abuse of compromised infrastructure for proxy services. Join the discussion | AlienVault OTX General | 09/04/2026, 07:52:40 UTC Added: 09/04/2026, 11:52:34 UTC |
This is a sophisticated global phishing campaign that abuses legitimate Remote Management and Monitoring (RMM) software to gain unauthorized remote access. Initially targeting Canadians with fake Canada Revenue Agency tax documents, it has expanded to 46 countries, with nearly half of the activity in the United States. Attackers impersonate trusted organizations and use advanced techniques such as password-protected archives, browser fingerprinting, and Telegram-based victim filtering. The campaign uses rapidly rotating infrastructure hosted mainly on Vercel, leveraging legitimate TLS certificates and domain reputations. Signed commercial RMM tools are abused, making traditional signature-based detection ineffective. The campaign has been active steadily since January 2026. MediumCampaign Join the discussion | AlienVault OTX General | 08/26/2026, 12:32:30 UTC Added: 08/26/2026, 12:52:19 UTC |
In May 2026, threat actors exploited CVE-2026-35616, an improper access control vulnerability in Fortinet EMS versions 7.4.5 through 7.4.6, to deploy EKZ Stealer within an energy sector organization. The malware was disguised as FortiEndpoint_Patch.exe and harvested browser credentials from Chromium-based browsers and Firefox before exfiltrating data via PowerShell to a command-and-control server. EKZ Stealer employs sophisticated compiler-based obfuscation techniques including indirect jumps, control-flow flattening, and XOR-based string encryption to evade analysis. The technical analysis demonstrates how Binary Ninja Workflows can be leveraged to defeat these obfuscation methods by matching repeatable Intermediate Language patterns and rewriting LLIL/MLIL expressions to restore readable control flow, significantly accelerating malware reverse engineering efforts. Join the discussion | CVE Database V5 | 08/26/2026, 07:21:30 UTC Added: 04/04/2026, 01:00:30 UTC |
PavinLoader is a sophisticated multi-stage .NET loader used in various malicious campaigns such as ClickFix attacks, fake software downloads, and malicious RenPy games. It uses heavy obfuscation, abuses legitimate Windows tools like MSBuild, and employs an EtherHiding technique to retrieve command-and-control domains via blockchain. The infection chain includes anti-forensics, anti-analysis, and virtual environment detection stages, ultimately delivering payloads like the Amatera Stealer. The loader demonstrates advanced evasion techniques including custom obfuscation, API hashing, and targeting specific geographic regions. Evidence suggests it may be offered as a Loader-as-a-Service, with over 200 related files sharing common artifacts. Join the discussion | AlienVault OTX General | 08/25/2026, 07:12:42 UTC Added: 08/25/2026, 10:52:01 UTC |
Grandoreiro, a notorious banking trojan active since 2016 across Latin America, continues operations despite major law enforcement disruption in 2024. Recent campaigns leverage DLL sideloading techniques, abusing the legitimate Duplicate Files Finder application to execute malicious code. The loader incorporates extensive anti-analysis mechanisms including sandbox detection, virtual machine artifact checks, process blacklisting, and environment profiling to evade automated analysis systems. These defensive checks occur before C2 contact, indicating high priority on avoiding detection. Telemetry from June 2026 shows activity concentrated in Latin America, primarily Mexico, with limited presence in Europe and North America. The malware uses custom string obfuscation combining proprietary decryption with Base64 encoding, and communicates with C2 infrastructure over TCP port 6432 using encrypted requests containing host-specific information. Join the discussion | AlienVault OTX General | 08/19/2026, 20:39:08 UTC Added: 08/20/2026, 23:07:12 UTC |
Showing 1 to 10 of 153 results