Skip to main content

Threats Tagged 't1539'

View all threats tagged with 't1539'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: t1539

Threats Tagged 't1539'

Click on any threat for detailed analysis and mitigation recommendations

PolinRider operators compromised a GitHub account to insert malicious code into development versions of visanduma/nova-two-factor, a Packagist package with over 700,000 downloads. The campaign spreads through compromised developer accounts and Git repositories across multiple ecosystems including npm, PyPI, Go modules, Packagist, and Chrome extensions. The operators use Git history rewriting, payload concealment in configuration files and font files, automatic execution through IDE tasks, and staged payload delivery via dead-drop mechanisms like EtherHiding and NullReceiver. Primary infection occurs through Git-based collaboration rather than direct package registry compromise, with PHP projects targeted using obfuscated JavaScript executed through shell_exec. The campaign appears linked to North Korean operators focused on cryptocurrency theft.

Join the discussion

Brazilian banking malware operation REF9334 has been deploying KREMLIN toolkit since May 2025, targeting Brazilian financial institutions through malicious browser extensions. The operation uses multi-stage JavaScript loaders, custom C++ installers, and exploits Chromium integrity mechanisms by manipulating Secure Preferences and regenerating required HMACs. Infrastructure leverages Ethereum smart contracts as dead-drop resolvers for dynamic C2 configuration. Seven distinct campaigns over 15 months show evolution from PULSAR RAT to REMCOS RAT delivery. Attackers impersonate twelve Brazilian banks through Portuguese-language lures, with transaction patterns clustering during São Paulo working hours. The malicious extensions intercept credentials, session tokens, and sensitive banking data through keylogging and request interception capabilities. Over 1,500 infections have been temporarily disrupted through network canary registration, with 98.75% of victims located in Brazil.

Join the discussion

Cybercriminals have created numerous fake websites mimicking Bitrefill, a legitimate cryptocurrency-based gift card and eSIM retailer. These fraudulent sites appear in search engine results and use lookalike domains incorporating the Bitrefill brand name with added words or character substitutions, including internationalized domain names using Punycode. Victims are guided through convincing checkout processes that replicate Bitrefill's legitimate payment flow, complete with cryptocurrency options, QR codes, and countdown timers. However, payments are sent directly to attacker-controlled cryptocurrency addresses rather than Bitrefill, with virtually no chance of recovery. The operation demonstrates sophisticated measurement using commercial analytics software to optimize conversion rates, indicating organized criminal activity rather than opportunistic fraud.

Join the discussion

A malicious browser extension called 'Twitch Enhanced Viewer | JeetBot' distributed on Chrome Web Store and Firefox Add-ons captures and forwards users' live Twitch OAuth session tokens to Russian-controlled proxy servers. The extension, with approximately 30,000 Chrome users and 552 Firefox users, markets itself as a quality-of-life tool for blocking ads and unlocking streams. While delivering these features, it secretly extracts users' account-scoped OAuth tokens and forwards them as query parameters to operator-controlled infrastructure. Current versions append tokens inline during video playlist redirects, while earlier builds explicitly POSTed tokens to dedicated collection endpoints. The operator is identified as a commercial Russian bot service called JeetBot, with infrastructure hosted across German and cloud providers.

Join the discussion
0

KATARU is an IoT malware variant discovered in August 2026 through Telnet credential brute-forcing against a honeypot from Vietnam. While maintaining traditional Mirai-style botnet capabilities, it distinguishes itself through an extensive feature set including multiple Linux local privilege escalation exploits, comprehensive persistence mechanisms across Linux and embedded platforms, encrypted C2 communications using X25519 and ChaCha20-Poly1305, anti-analysis techniques, and decoy traffic generation. Implementation artifacts strongly suggest AI-assisted development, evidenced by architecture-mismatched x86 shellcode in ARM binaries, RFC test vectors as configuration values, and untested cross-platform persistence logic. The malware attempts various privilege escalation paths through system misconfigurations and public exploits, establishes persistence across numerous startup mechanisms, and supports multiple DDoS attack vectors alongside SSH brute-forcing capabilities.

Join the discussion

Six Chrome and Firefox extensions linked through shared code, C2 infrastructure, and publishing history have been identified targeting cryptocurrency traders. Four malicious extensions steal authenticated session tokens and wallet data from Axiom Trade and Padre users, while two earlier extensions reveal a pattern of repackaging crypto trading tools. The extensions J7Tracker, VREO, and Orbit Tracker automatically retrieve user information, wallet bundles, Firebase tokens, and application state, then exfiltrate data to threat actor-controlled Vercel deployments. The campaign targets an active trading community with Axiom processing over $15 billion in volume across 650,000 wallets. The malicious code runs inside authenticated sessions, collecting localStorage, IndexedDB data, and API responses containing authentication tokens and wallet keys. Data is Base64-encoded and transmitted via browser navigation to avoid CORS restrictions, enabling account compromise and cryptocurrency theft.

Join the discussion

Threat actors are exploiting anticipation for Grand Theft Auto VI by distributing malicious ISO files disguised as leaked game versions. These fake installers are spread through SEO poisoning, gaming forums, social media, and torrenting sites. The analyzed ISO contains multiple malicious components including several RAT variants (NJRAT and DCRAT), Mercurial Grabber infostealer, Chaos ransomware functioning as a wiper, and Yandex Browser. When executed, the fake installer displays Russian-language messages and deploys malware to %TEMP% folders. The package includes data exfiltration capabilities, credential theft, system control features, and destructive file encryption. Based on Russian language usage throughout the infection chain, the campaign appears to target Russian-speaking gamers. The malware components date back to 2023, suggesting repurposed tools for this opportunistic attack.

Join the discussion

A massive cybercrime campaign tracked as CL-CRI-1171 has operated undetected for at least two years, utilizing a pay-per-install marketplace to distribute multiple malware families. The operation targeted primarily young gamers through YouTube channels with hundreds of thousands of followers, while simultaneously using SEO poisoning to compromise corporate endpoints including critical infrastructure and government entities. The campaign employed OfferLoader, a custom loader capable of delivering unique payload combinations through sophisticated gating mechanisms. Three distinct malware families were identified: Insomnia RAT, a cross-platform backdoor targeting Windows and macOS; ARKTunnel, a WebSocket tunneling tool hidden via steganography; and Docro Hijacker, a Chrome browser hijacker. Over 10,000 distinct loader samples were discovered, indicating a much larger deployment campaign affecting numerous organizations globally.

Join the discussion

MacSync Stealer is a macOS information stealer and remote-access stager delivered through ClickFix social engineering and malvertising campaigns. Operating under a malware-as-a-service model, it employs sophisticated evasion techniques including process daemonization, single-byte XOR obfuscation, and in-memory AppleScript execution to bypass Apple Gatekeeper, XProtect, and EDR solutions. The malware exfiltrates credentials, browser data, cryptocurrency wallets, and SSH keys through fault-tolerant 10MB chunked uploads to command-and-control infrastructure. MacSync targets professionals in software engineering, cryptocurrency, fintech, and corporate environments across North America, Europe, and Asia-Pacific regions, with campaigns impersonating legitimate services like Google Meet, Claude AI, Docker, and TradingView to trick victims into executing malicious Terminal commands.

Join the discussion

In June 2026, researchers uncovered BigBear 2.0, a rebranded Evilginx2-based phishing-as-a-service framework targeting Microsoft 365 credentials globally. The operation, managed by operator 'General Boss', deployed 42 VPS nodes primarily hosted on Vultr infrastructure, utilizing the 'offy' phishlet configuration. The platform employed adversary-in-the-middle techniques with geo-matched residential proxy pools across 69 countries, real-time Telegram exfiltration, and automated cookie replay to bypass MFA. The campaign exfiltrated 5,137 credential records including 474 complete MFA-bypassed authentications, 1,032 plaintext passwords, and 4,148 session cookies, affecting 3,331 unique victim IPs across 40+ countries. The multi-user PhaaS panel was leased to at least five identified affiliate operators. Custom JavaScript injections disabled FIDO2/WebAuthn MFA while residential proxies bypassed anti-bot detection, enabling persistent access to compromised Microsoft 365 environments.

Join the discussion

Showing 1 to 10 of 150 results

Filters:Tag: t1539
Page 1 of 15
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses