Skip to main content

Threats Tagged 't1548'

View all threats tagged with 't1548'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: t1548

Threats Tagged 't1548'

Click on any threat for detailed analysis and mitigation recommendations

A previously undocumented Linux toolkit has been targeting South Korean automotive and media organizations with minimal detection since early 2025. The campaign employs a HAProxy instance called ted backdoor, compiled within the victim's existing HAProxy version 2.8.12, alongside trojanized versions of crond, agetty, atd, sshd, and polkitd. This sophisticated framework enables remote command execution, malicious script injection into web traffic, credential harvesting, and long-term surveillance. The ted backdoor uses HAProxy's native filter API and internal structures to intercept SSL-decrypted HTTP traffic while maintaining legitimate load balancing operations. Operating alongside are an SSH keylogger, a curl-based RAT with HAProxy health monitoring capabilities, and a deployment stager. The toolkit is attributed with medium confidence to DPRK APTs based on targeting patterns, simple XOR-based encryption schemes, custom substitution ciphers, and C2 infrastructure associated with APT37.

Join the discussion

A sophisticated credential theft campaign manipulates DNS and HTTP traffic on captive portal networks at hotels, conference centers, and hospitality venues to redirect victims to attacker-controlled infrastructure. The operation harvests Microsoft 365 credentials through phishing pages, device code phishing abusing Microsoft Entra ID authentication flow, and malware delivery via ClickFix social engineering techniques. Evidence indicates compromised shared captive portal services rather than individual venue breaches, with affected gateways identified in several U.S. cities, India, and Saudi Arabia. The campaign deploys two primary malware tools: CornFlake, a Go-based RAT providing persistent access and extensive surveillance capabilities, and ChocoShell, an in-memory PowerShell stealer that harvests browser credentials, Microsoft 365 tokens, and Azure AD tokens. The operation targets travelers across multiple sectors and has expanded to include Android devices through malicious APK files.

Join the discussion

Check Point has released urgent security updates addressing three critical vulnerabilities affecting Security Management, Multi-Domain Management, Quantum Security Gateway, and Gaia operating systems. The most severe vulnerability, CVE-2026-16232, allows unauthenticated remote attackers to bypass SmartConsole login and gain full administrative access to exposed Management Servers. The vulnerability has been actively exploited against customers with internet-exposed management infrastructure. Successful exploitation enables attackers to modify firewall policies, create administrator accounts, weaken security protections, and establish persistent access. Two additional vulnerabilities were patched: CVE-2026-62144 enabling unauthenticated command execution, and CVE-2026-62145 allowing privilege escalation from read-only to root access. CISA added CVE-2026-16232 to its Known Exploited Vulnerabilities catalog with an exceptionally short remediation deadline, reflecting the severity of this authentication bypass...

Join the discussion

A security update addresses multiple vulnerabilities discovered during routine security review, including authentication bypass issues affecting management products. One vulnerability (CVE-2026-16232) has been exploited in the wild against a limited number of customers with specific configurations where Management is exposed directly to the internet without IP restrictions. The affected systems include Security Management and Multi-Domain Management across multiple versions. Two additional vulnerabilities address authentication bypass with privilege escalation and local privilege escalation in GaiaOS WebUI. All impacted customers have been notified, and Smart-1 Cloud customers are already protected. Indicators of compromise include six IP addresses associated with the exploitation activity. Installation of the latest Jumbo hotfix is recommended along with implementation of security best practices.

Join the discussion

In early 2026, a threat actor targeted SD-WAN infrastructure at a service provider, exploiting a zero-day vulnerability in Cisco Catalyst SD-WAN to escalate privileges. The attacker initially gained access through unauthorized peering connections and manipulated default account passwords. They then exploited CVE-2026-20245, a privilege escalation flaw in the file upload feature, by uploading a malicious CSV file to achieve root-level access. The vulnerability allowed the creation of a privileged user account through manipulation of system password files. Throughout the intrusion, the threat actor employed extensive anti-forensic techniques, systematically deleting malicious files, restoring modified system configurations, and executing validation scripts to ensure removal of indicators. This campaign demonstrates the living off the edge paradigm, where adversaries compromise network appliances to bypass traditional security perimeters and maintain persistent access.

Join the discussion

An active malware campaign is targeting Thailand's healthcare sector, including Ministry of Health personnel and affiliated organizations. The operation leverages healthcare-themed spear-phishing lures distributed through malicious RAR archives containing obfuscated batch scripts and executable payloads. The infection chain employs multiple stages of obfuscation, GitHub-hosted payload delivery, and persistence mechanisms. The final payload is a Python-based information stealer designed to harvest browser credentials, session data, and cookies, with exfiltration attempts through Telegram Bot API. The campaign demonstrates sophisticated tradecraft including Rouki-obfuscated batch loaders, Startup folder persistence, and bundled Python interpreters. Active operational window spans from April to June 2026, with all samples uploaded from Thailand.

Join the discussion
0

CVE-2026-46316 is a guest-to-host escape vulnerability in the vGIC-ITS emulation within KVM on ARM64 platforms. It is caused by a race condition in the vgic_its_invalidate_cache() function leading to a double-put use-after-free, which allows execution of code in the host kernel context. This flaw resides in the in-kernel KVM module, enabling successful exploitation to gain host kernel privileges. The vulnerability affects multi-tenant ARM64 cloud environments and can be chained with local privilege escalation when guest root access is unavailable. A patch fixing this vulnerability was applied in the Linux kernel at commit 13031fb6b835. Two YARA rules have been developed to detect exploitation attempts based on specific constants and behavioral patterns. There are no known exploits in the wild as of the latest information.

Join the discussion

In April 2026, Cato CTRL identified and blocked an attempted intrusion against a global manufacturing customer involving TencShell, a previously undocumented, Go-based implant derived from the open-source Rshell C2 framework. The activity appeared in traffic associated with a third-party user connected to the customer environment.

Join the discussion

RedSun.exe is a publicly available proof-of-concept exploit targeting a zero-day vulnerability in Microsoft Defender on Windows systems. It enables local privilege escalation from a standard user to SYSTEM-level access by exploiting flawed Defender remediation logic for cloud-tagged malicious files and redirecting high-privilege file operations to overwrite protected system locations such as C:\Windows\System32. This allows arbitrary code execution as SYSTEM without needing administrator privileges or kernel exploits. The exploit is reliable, actively weaponized, and potentially unpatched in some environments, posing a significant risk for persistence, lateral movement, and defense evasion. No official patch or remediation guidance is currently available. Organizations should enforce least privilege principles and deploy behavior-based detection focused on suspicious Defender-related file operations and privilege escalation attempts. Monitoring for filesystem manipulation targeting protected system directories is also recommended. Rapid patching should be applied once vendor updates are released.

Join the discussion
0

Mirai, a notorious botnet targeting IoT devices, has evolved since its 2016 debut. Initially known for massive DDoS attacks, newer variants employ sophisticated techniques like UPX packing and common network utilities for evasion and adaptability. Modern Mirai samples extend beyond DDoS, focusing on data exfiltration and long-term persistence. The analysis compares a June 2025 variant with the original, highlighting differences in execution, network behavior, and file characteristics. The new variant demonstrates increased stealth, modularity, and versatility, making it a more significant threat in the interconnected device landscape. Prevention strategies include updated antivirus software, avoiding suspicious links, and regular system and network monitoring.

Join the discussion

Showing 1 to 10 of 12 results

Filters:Tag: t1548
Page 1 of 2
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses