Threats Tagged 't1547.006'
View all threats tagged with 't1547.006'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 't1547.006'
Click on any threat for detailed analysis and mitigation recommendations
0 A Chinese-speaking threat actor tracked as Red Heron rapidly weaponized CVE-2026-60004, a critical Gitea remote code execution vulnerability, within days of public disclosure in July 2026. The actor scanned 1,386 Gitea instances across seven countries, successfully compromising organizations in Canada, Argentina, Taiwan, the United States, and Sri Lanka. Activities included source code theft, credential collection, SSH persistence, and lateral movement, with one case escalating from a vulnerable Gitea server to root access across a three-node Proxmox cluster. An exposed staging server revealed targeting taxonomies using Simplified Chinese labels covering defense, elections, energy, aerospace, telecommunications, and government sectors. The campaign deployed JITTERLY, a C++ Linux implant with 30+ post-exploitation commands, embedding SIXZUT, a previously undocumented LD_PRELOAD rootkit capable of hiding files, processes, and network connections while protecting the implant from termination. Join the discussion | SecurityWeek | 09/15/2026, 13:05:50 UTC Added: 08/26/2026, 05:22:13 UTC |
A large-scale malvertising campaign targeting U.S.tax form searchers has been uncovered. The attack chain begins with Google Ads, using dual commercial cloaking services to evade detection. Victims are directed to rogue ScreenConnect installers, leading to a multi-stage crypter that ultimately deploys a BYOVD (Bring Your Own Vulnerable Driver) tool. This tool, named HwAudKiller, exploits a previously undocumented Huawei audio driver to terminate antivirus and EDR processes from kernel mode. The campaign's sophistication lies in its use of commodity tools and services, combining free-tier ScreenConnect instances, off-the-shelf crypters, and a signed driver with an exploitable weakness. The attackers consistently deploy multiple remote access tools on compromised hosts for redundancy, indicating a likely pre-ransomware or initial access broker operation. Join the discussion | AlienVault OTX General | 03/19/2026, 23:58:08 UTC Added: 03/20/2026, 08:08:28 UTC |
A sophisticated malware campaign is increasingly targeting WordPress websites to inject online casino spam content. This malware uses multiple redundancy and reinfection techniques, storing payloads in databases and non-standard file extensions to evade detection and maintain persistence. The campaign exploits the popularity of online gambling and leverages the decline of other spam sources, such as essay writing services, to focus on lucrative casino spam. Although primarily noted in Indonesia due to strict gambling laws, the campaign has international reach. The malware's complexity and persistence mechanisms pose risks to website integrity, SEO rankings, and user trust. European organizations running WordPress sites could be targeted, especially those with lax security or outdated plugins. Mitigation requires advanced detection, continuous monitoring, and tailored cleanup strategies. The threat is assessed as medium severity due to its impact on website integrity and SEO rather than direct data breach or system compromise. Join the discussion | AlienVault OTX General | 11/07/2025, 23:18:21 UTC Added: 11/10/2025, 11:35:31 UTC |
This investigation uncovered new tools and techniques used by the Curly COMrades threat actor to establish covert, long-term access to victim networks. The attackers exploited Hyper-V virtualization on compromised Windows 10 machines to create hidden remote operating environments. They deployed a minimalistic Alpine Linux-based virtual machine hosting custom malware for reverse shell and proxy operations. This approach effectively bypassed traditional host-based EDR detections. The threat actor also demonstrated persistence through PowerShell scripts, Kerberos ticket manipulation, and local account creation. International collaboration with the Georgian CERT aided in analyzing the command and control infrastructure. Join the discussion | AlienVault OTX General | 11/05/2025, 09:27:48 UTC Added: 11/05/2025, 09:41:20 UTC |
Phantom Taurus, a newly identified Chinese state-sponsored threat actor, has been conducting espionage operations targeting government and telecommunications organizations across Africa, the Middle East, and Asia. The group's primary focus includes ministries of foreign affairs, embassies, and military operations, with the objective of gathering sensitive information. Phantom Taurus employs distinctive tactics, techniques, and procedures, including a new malware suite called NET-STAR. This suite consists of three web-based backdoors designed to target Internet Information Services (IIS) web servers. The group has recently shifted from targeting emails to directly accessing databases, demonstrating their ability to adapt and evolve their methods. Phantom Taurus' activities align with Chinese strategic interests, and their infrastructure overlaps with other known Chinese APT groups. Join the discussion | AlienVault OTX General | 09/30/2025, 17:21:27 UTC Added: 09/30/2025, 19:55:06 UTC |
This analysis examines a campaign distributing Atomic macOS Stealer (AMOS), targeting macOS users through fake 'cracked' applications. Attackers use two main delivery methods: malicious .dmg installers and terminal commands that bypass Gatekeeper protection. AMOS employs rotating domains to evade detection and steals a wide range of sensitive data, including credentials, browser information, cryptocurrency wallets, and system files. The campaign demonstrates sophisticated tactics, adapting to macOS security improvements and leveraging social engineering. The report emphasizes the importance of comprehensive endpoint detection, user education, and defense-in-depth strategies to combat such threats. Join the discussion | AlienVault OTX General | 09/04/2025, 17:54:49 UTC Added: 09/04/2025, 21:23:56 UTC |
Akira affiliates have been observed exploiting two common drivers as part of a suspected AV/EDR evasion effort following initial access involving SonicWall abuse. The drivers, rwdrv.sys and hlpdrv.sys, are being used to facilitate AV/EDR evasion or disablement through a Bring Your Own Vulnerable Driver (BYOVD) exploitation chain. This behavior has been prevalent in recent Akira ransomware incident response cases. The campaign may be driven by an unreported zero-day vulnerability in SonicWall VPNs. Defenders are advised to harden SonicWall VPNs, implement recommended mitigations, and use provided YARA rules for detection and response to pre-ransomware activity. Join the discussion | AlienVault OTX General | 08/08/2025, 08:07:28 UTC Added: 08/08/2025, 08:17:47 UTC |
A new Go-based Linux botnet named PumaBot has been identified targeting IoT devices, particularly surveillance systems. It brute-forces SSH credentials using lists from a C2 server, then deploys itself and establishes persistence. The malware disguises itself as legitimate system files, creates systemd services, and adds SSH keys for backdoor access. It also includes components for credential theft and system monitoring. The botnet demonstrates sophisticated evasion techniques and aims for long-term access to compromised devices. Join the discussion | AlienVault OTX General | 06/04/2025, 20:39:09 UTC Added: 06/05/2025, 00:58:17 UTC |
Showing 1 to 8 of 8 results