Threats Tagged 't1526'
View all threats tagged with 't1526'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 't1526'
Click on any threat for detailed analysis and mitigation recommendations
A large-scale software supply chain attack compromised over 400 npm packages through a self-propagating worm called ChainDrop, a new variant of Mini Shai-Hulud. The campaign exploits stolen npm publishing credentials to automatically modify and republish legitimate software releases. ChainDrop targets developer workstations and CI/CD environments, harvesting credentials from npm, GitHub, AWS, Kubernetes, and HashiCorp Vault before validating access and enumerating resources. The malware uses preinstall lifecycle scripts for automatic execution, establishes persistence through repository configuration modifications, and abuses GitHub Actions OIDC trusted publishing workflows. After stealing credentials, it autonomously propagates by downloading packages, inserting malicious payloads, and republishing them with incremented versions, demonstrating how compromised developer identities can enable widespread ecosystem compromise. Join the discussion | AlienVault OTX General | 08/11/2026, 15:03:12 UTC Added: 08/11/2026, 15:26:15 UTC |
EvilTokens is a new Phishing-as-a-Service offering a turnkey Microsoft device code phishing kit. It enables attackers to harvest access and refresh tokens, granting unauthorized access to victims' Microsoft accounts. The kit supports post-compromise operations, allowing data exfiltration from various Microsoft services. EvilTokens has been rapidly adopted by cybercriminals since March 2026, impacting organizations globally. The service provides advanced capabilities for account takeover, including token conversion to Primary Refresh Tokens and browser cookies for persistent access. Phishing campaigns using EvilTokens target employees in finance, HR, logistics, and sales, primarily for Business Email Compromise attacks. MediumCampaign Join the discussion | AlienVault OTX General | 03/31/2026, 16:14:29 UTC Added: 03/31/2026, 18:38:16 UTC |
An AWS environment was targeted in a sophisticated attack, with the threat actor gaining administrative privileges in under 10 minutes. The operation showed signs of leveraging large language models for automation and decision-making. Initial access was obtained through credentials found in public S3 buckets, followed by rapid privilege escalation via Lambda function code injection. The attacker moved laterally across 19 AWS principals, abused Amazon Bedrock for LLMjacking, and launched GPU instances for potential model training. The attack involved extensive reconnaissance, data exfiltration, and attempts to establish persistence. Notable techniques included IP rotation, role chaining, and the use of AI-generated code. Join the discussion | AlienVault OTX General | 02/04/2026, 15:57:22 UTC Added: 02/04/2026, 21:00:08 UTC |
Threat actors associated with ShinyHunters-branded extortion operations are expanding their tactics, targeting cloud-based SaaS applications for data theft and extortion. The attackers use sophisticated voice phishing and credential harvesting to gain initial access, then exfiltrate sensitive data from various platforms. They employ aggressive extortion tactics, including harassment and DDoS attacks. The activity involves multiple threat clusters (UNC6661, UNC6671, UNC6240) and targets a growing number of cloud platforms. The attackers leverage social engineering to bypass MFA and use tools like ToogleBox Recall to cover their tracks. This activity highlights the effectiveness of social engineering and the importance of phishing-resistant MFA methods. Join the discussion | AlienVault OTX General | 01/31/2026, 08:41:02 UTC Added: 02/02/2026, 10:45:14 UTC |
A large-scale attack infrastructure dubbed TruffleNet has been identified, built around the open-source tool TruffleHog. This infrastructure is used to systematically test compromised credentials and perform reconnaissance across AWS environments. The campaign involves over 800 unique hosts across 57 distinct Class C networks, characterized by consistent configurations and the use of Portainer. Alongside TruffleNet, adversaries are exploiting Amazon Simple Email Service (SES) to facilitate Business Email Compromise (BEC) campaigns. The attackers create email identities using compromised WordPress sites and conduct aggressive cloud reconnaissance. This activity highlights the evolving tactics of threat actors in exploiting cloud infrastructure at scale, combining credential theft, reconnaissance automation, and SES abuse to conduct high-volume fraud with minimal detection. Join the discussion | AlienVault OTX General | 11/01/2025, 10:24:25 UTC Added: 11/03/2025, 10:56:13 UTC |
Over the past few weeks, Rapid7 has observed increased activity of a new threat group attacking AWS cloud environments with the goal of data exfiltration and subsequent extortion of the victim. This threat group refers to itself as ‘Crimson Collective’ and has recently announced that it is behind an attack on Red Hat, wherein it claims to have stolen private repositories from Red Hat’s GitLab. Join the discussion | AlienVault OTX General | 10/10/2025, 17:12:14 UTC Added: 10/10/2025, 17:24:52 UTC |
Recent cybersecurity news has shifted focus from AI and ransomware to breaches, particularly those involving compromised OAuth tokens linked to Salesloft's Drift integration. The main themes emerging are supply chain and identity attacks, with a need to redefine these concepts in the context of SaaS environments. Supply chain attacks now extend beyond hardware and software to include the datapath, while identity attacks increasingly target interconnected applications. The article emphasizes the importance of broadening cybersecurity focus and introduces the Cyber Threat Intelligence Capability Maturity Model (CTI-CMM) as a framework for organizations to assess and enhance their cyber threat intelligence programs. Join the discussion | AlienVault OTX General | 09/12/2025, 00:05:00 UTC Added: 09/12/2025, 08:32:44 UTC |
An AWS access key compromise led to a sophisticated SES abuse campaign in May 2025. The attacker exploited the stolen key to bypass SES restrictions, verify new sender identities, and conduct a large-scale phishing operation. They used multi-regional PutAccountDetails requests to escape the SES sandbox, a novel technique in SES abuse. The campaign involved creating multiple email identities using attacker-owned and legitimate domains with weak DMARC protections. The subsequent phishing campaign targeted various organizations, using tax-related lures to steal credentials. This incident highlights the importance of monitoring cloud service usage, especially for services like SES that can be exploited for monetization. Join the discussion | AlienVault OTX General | 09/04/2025, 23:40:56 UTC Added: 09/05/2025, 08:24:07 UTC |
0 A threat actor nicknamed ViciousTrap has compromised over 5,500 edge devices, transforming them into honeypots. The actor targets more than 50 brands of SOHO routers, SSL VPNs, DVRs, and BMC controllers, possibly to collect exploited vulnerabilities. The infection chain involves exploiting CVE-2023-20118 to deploy a script called NetGhost, which redirects incoming traffic to the attacker's infrastructure. The compromised devices, mostly end-of-life, are used to create a distributed honeypot-like network across Asia. The actor, likely of Chinese-speaking origin, may be attempting to observe exploitation attempts and collect non-public or zero-day exploits. The infrastructure uses servers in Malaysia, and the campaign has been ongoing since March 2025. Join the discussion | AlienVault OTX General | 05/23/2025, 18:38:49 UTC Added: 05/23/2025, 19:06:51 UTC |
Showing 1 to 9 of 9 results