Threats Tagged 't1553.005'
View all threats tagged with 't1553.005'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 't1553.005'
Click on any threat for detailed analysis and mitigation recommendations
Threat actors are conducting a multi-wave campaign using social engineering lures themed around Zoom updates, business documents, and system utilities to deploy ScreenConnect Remote Monitoring and Management agents. The operation employs VBScript droppers, batch loaders, compiled .NET executables, and HTML phishing pages, all retrieving payloads from a WsgiDAV staging server at 207.174.0.143:8080. Victims receive silently installed ScreenConnect agents that beacon to three attacker-controlled relay servers, providing persistent remote access. The campaign demonstrates technical evolution from obfuscated VBScript with XOR encryption to aggressive .NET loaders executing nine-step Windows Defender destruction sequences. Cross-platform variants target both Windows and macOS systems. All payloads are legitimately signed ConnectWise ScreenConnect MSIs, designed to evade security controls that trust code signing. The threat actor actively rotates payload hashes and recently pivoted to stealth tactics specifically... Join the discussion | AlienVault OTX General | 08/04/2026, 18:20:59 UTC Added: 08/05/2026, 09:26:29 UTC |
Cybercriminals are conducting phishing campaigns by hosting malicious pages on Vercel, a legitimate website hosting platform. The attack involves sending phishing emails with links to fake Adobe PDF viewer pages that prompt users to download executable files disguised as documents. The malware, distributed as Invoice06092025.exe.bin, automatically installs LogMeIn remote access software upon execution, enabling attackers to remotely control compromised machines. Over a two-month period, more than 28 distinct campaigns have been observed targeting over 1,271 users. The attackers leverage trusted platforms to disguise their malicious activity, making detection more challenging and increasing the likelihood of successful compromise. Join the discussion | AlienVault OTX General | 07/09/2026, 22:16:03 UTC Added: 07/10/2026, 07:47:32 UTC |
An active malware campaign has been discovered distributing malicious VBScript files through WhatsApp direct messages since June 2026. The operation affects users across multiple countries, with Malaysia experiencing the highest concentration of victims. Attackers compromise WhatsApp accounts and send weaponized VBS files disguised as business and financial documents to contacts. The multi-stage infection chain ultimately deploys legitimate ManageEngine Endpoint Central RMM software, providing persistent remote access to compromised systems. The scripts employ heavy obfuscation, Chinese-language comments, and modify Windows UAC settings. Infrastructure overlaps with ValleyRAT and Gh0st RAT operations suggest possible Chinese-speaking operators, though attribution remains uncertain. The campaign primarily targets individual users through opportunistic rather than focused methods, exploiting social engineering techniques with localized filenames in multiple languages. Join the discussion | AlienVault OTX General | 06/22/2026, 11:01:01 UTC Added: 06/22/2026, 20:24:23 UTC |
In March 2026, trojans represented 21% of attachment-based threats, while phishing attacks using fake pages dropped from 42% to 15% month-over-month. Script-based malware increased significantly, with HTML at 14% and JavaScript at 11%. Compressed files including ZIP (14%), RAR (8%), and 7Z (5%) were common distribution methods. Document-based threats utilized PDF (13%), XLS (5%), and DOCX (2%) files. Attackers impersonated courier services like FedEx and DHL, as well as financial institutions including Hana Bank and Woori Bank. Distribution methods included HTML scripts and PDF hyperlinks leading to credential-stealing pages. Notable malware families included RemcosRAT and AgentTesla, with command-and-control infrastructure utilizing Telegram API tokens and external mail servers for data exfiltration. Join the discussion | AlienVault OTX General | 04/22/2026, 07:06:43 UTC Added: 04/22/2026, 08:31:37 UTC |
An attack campaign targeting organizations in the US, Canada, UK, and Northern Ireland exploits ConnectWise ScreenConnect vulnerabilities. The attack chain begins with a spoofed email containing a malicious .cmd attachment, which executes silently, escalates privileges, disables Windows SmartScreen, and removes the Mark-of-the-Web. It then installs a legitimate Remote Monitoring and Management tool, ScreenConnect, which is abused as a Remote Access Trojan for persistent command-and-control access. The campaign focuses on sectors with high-value data, including government, healthcare, and logistics. The attackers use various techniques to evade detection, including UAC bypass, registry modification, and silent MSI installation. The ScreenConnect client used has a revoked certificate, highlighting the importance of blocking vulnerable software versions and enforcing strict RMM allowlists. Join the discussion | AlienVault OTX General | 02/12/2026, 10:39:02 UTC Added: 02/12/2026, 22:04:12 UTC |
0 A threat group is targeting Afghan government employees using a fake lure mimicking an official government document. The campaign, named Operation Nomad Leopard, uses a malicious ISO file containing a PDF decoy, LNK file, and the FALSECUB malware. The infection chain involves executing the LNK file to display the PDF and run the malware, which establishes persistence and connects to a command and control server. The malware performs system reconnaissance, file enumeration, and data exfiltration. The threat actor, believed to be regionally focused with low-to-moderate sophistication, uses GitHub for malware distribution and has connections to Pakistan. The campaign demonstrates careful attention to detail in creating convincing lures and leverages legitimate platforms for malicious purposes. Join the discussion | AlienVault OTX General | 01/20/2026, 08:51:25 UTC Added: 01/20/2026, 09:05:55 UTC |
Threat actors exploited Cloudflare's free-tier infrastructure and Python environments to deploy AsyncRAT, demonstrating advanced evasion techniques. The attack begins with phishing emails containing Dropbox links to malicious files. It uses legitimate Python downloads and sophisticated code injection targeting explorer.exe. The campaign ensures persistence through multiple vectors, including startup folder scripts and WebDAV mounting. It abuses trusted infrastructure like Cloudflare to mask activities and evade detection. The attackers employ social engineering tactics, such as displaying legitimate PDF documents, to reduce suspicion. This campaign highlights the trend of abusing cloud services for malware delivery and execution, emphasizing the need for multi-layered security approaches. Join the discussion | AlienVault OTX General | 01/12/2026, 20:30:28 UTC Added: 01/13/2026, 16:11:30 UTC |
A malicious campaign has compromised 19 Visual Studio Code extensions by embedding malware within dependency folders, specifically by modifying the legitimate npm package 'path-is-absolute'. Active since February 2025, the attackers disguise malicious binaries as PNG images within archives to evade detection. When VS Code starts, a JavaScript dropper decodes and executes two malicious binaries using living-off-the-land binaries, enabling stealthy execution. This attack leverages trusted components from the VS Code Marketplace, complicating detection and mitigation. Although no known exploits in the wild have been reported, the campaign demonstrates advanced evasion techniques and targets a widely used development environment. The malware involves a Rust-based trojan and employs multiple tactics such as code obfuscation, masquerading files, and abuse of legitimate binaries. European organizations using VS Code with affected extensions are at risk of compromise, data theft, or further lateral movement. Mitigation requires careful vetting of extensions, monitoring for suspicious activity, and restricting execution of untrusted binaries. Countries with strong software development sectors and high VS Code adoption are most likely to be impacted. Given the stealth, potential for privilege escalation, and broad impact, the threat severity is assessed as high. Join the discussion | AlienVault OTX General | 12/11/2025, 12:06:21 UTC Added: 12/11/2025, 14:54:37 UTC |
The ShadyPanda threat actor has conducted a sophisticated seven-year malware campaign infecting 4.3 million Chrome and Edge browsers via malicious extensions that were verified and featured by Google, enabling widespread trust and distribution. The campaign operates two main components: a 300,000-user remote code execution (RCE) backdoor and a 4-million-user spyware operation that harvests extensive user data such as browsing history, search queries, and mouse clicks, sending it to servers in China. This malware exploits vulnerabilities in browser extension marketplaces and trusted update mechanisms to maintain persistence and evade detection. The campaign highlights significant risks to user privacy and organizational security, especially for entities relying heavily on Chrome and Edge browsers. European organizations face risks of data exfiltration, espionage, and potential lateral movement within networks. Mitigation requires proactive extension management, network monitoring for suspicious domains, and enhanced user awareness. Countries with high Chrome/Edge usage and strategic geopolitical interest in China-related cyber espionage are most at risk. The threat severity is assessed as high due to the scale, stealth, and potential impact on confidentiality and integrity without requiring user interaction post-installation. Join the discussion | AlienVault OTX General | 12/03/2025, 20:19:10 UTC Added: 12/04/2025, 11:23:20 UTC |
APT-C-60 continues to target Japan and East Asia with spear-phishing attacks impersonating job seekers. The attack flow has evolved, now directly attaching malicious VHDX files to emails. The malware, including Downloader1, Downloader2, and SpyGlace, has been updated with new features and communication methods. SpyGlace versions 3.1.12, 3.1.13, and 3.1.14 were observed, with changes in Mutex values and execution paths. The attackers use GitHub for payload distribution and employ sophisticated encoding and encryption techniques. The campaign abuses legitimate services and maintains consistent behavioral patterns despite infrastructure changes. Join the discussion | AlienVault OTX General | 11/05/2025, 08:16:16 UTC Added: 11/05/2025, 08:56:30 UTC |
Showing 1 to 10 of 20 results