Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.

Threats Tagged 't1518'

View all threats tagged with 't1518'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: t1518

Threats Tagged 't1518'

Click on any threat for detailed analysis and mitigation recommendations

Powercat malware campaign: Fake game cheats deliver infostealer
0

The Powercat malware campaign observed in February 2026 distributes an infostealer disguised as cheat software for popular PC games like Roblox, Minecraft, and Grand Theft Auto V. It uses a multi-stage infection chain involving an initial executable for profiling and persistence, followed by a Java-based loader that deploys the infostealer. The malware targets cryptocurrency wallets, browser data, Discord tokens, and gaming accounts with payment information. It also includes surveillance features such as keylogging, webcam capture, and screen recording. The campaign primarily targets children on gaming platforms and pay-to-cheat websites, with indications that stolen personal data may be used for blackmail or coercion into illegal activities.

Join the discussion
LabubaRAT: A Rust Based Remote Access Tool Masquerading as NVIDIA Software
0

A previously undocumented remote access tool named LabubaRAT has been identified, masquerading as NVIDIA software through fake metadata and runtime artifacts. This Rust-based malware creates persistent footholds enabling hands-on operator activity including host profiling, security tool identification, command execution, file transfers, screenshot capture, and traffic proxying. The implant supports multiple communication methods including HTTPS polling, WebView2-based communication, and DNS tunneling. It uses a configurable framework model with organization, group, server, and API key parameters suggesting a Malware-as-a-Service platform. The malware maintains local state in SQLite databases and provides comprehensive remote access capabilities including PowerShell and JavaScript execution, SOCKS5 proxy support, and user-level persistence through registry autoruns. Infrastructure analysis revealed LabubaPanel branding with associated command and control servers hosted on German providers.

Join the discussion

Showing 1 to 2 of 2 results

Filters:Tag: t1518
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses