Threats Tagged 't1555'
View all threats tagged with 't1555'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 't1555'
Click on any threat for detailed analysis and mitigation recommendations
An intrusion was investigated that began with exploitation of CVE-2026-48558, a critical authentication bypass vulnerability in SimpleHelp RMM software. The threat actor obtained unauthorized technician access and deployed two previously undocumented malware samples: TaskWeaver and Djinn Stealer. TaskWeaver is a heavily obfuscated Node.js loader that establishes encrypted communications and delivers additional payloads. Djinn Stealer targets credentials across Windows, macOS, and Linux systems, collecting authentication data for cloud platforms, source control, package registries, AI development assistants, browsers, SSH keys, and cryptocurrency wallets. The attacker leveraged legitimate RMM capabilities to transfer files and execute commands across managed systems. Stolen AI assistant tokens provided extensive access to repositories, databases, and cloud accounts. The intrusion demonstrated how a single authentication bypass in trusted management infrastructure can enable widespread credential theft and p... Join the discussion | Bleeping Computer | 09/10/2026, 12:49:58 UTC Added: 06/29/2026, 14:06:27 UTC |
An emerging infostealer tracked as REVSTEALER under REF2859 has gained significant momentum with approximately 4,700 samples identified over the past year. The malware features comprehensive credential harvesting capabilities targeting browsers, VPN applications, password managers, cryptocurrency wallets, and gaming platforms. It incorporates sophisticated anti-analysis mechanisms including a weighted sandbox scoring system and uses Polygon blockchain-based dead drops for resilient infrastructure management. Distribution occurs primarily through social engineering campaigns targeting gamers via compromised YouTube channels advertising fake game cheats, though samples also impersonate legitimate software like Slack and qBittorrent. The malware delivers four additional modules extending capabilities to include wallet theft, clipboard manipulation, reverse proxy functionality, and cryptocurrency mining deployment. Most samples employ VMProtect packing and feature an App-Bound Encryption bypass using debugger-... Join the discussion | AlienVault OTX General | 09/06/2026, 12:08:52 UTC Added: 09/07/2026, 09:52:59 UTC |
A resurgence in Node.js abuse has been observed since February 2026, targeting government departments, technology companies, and hotels. Attackers leverage the legitimate, signed node.exe binary to execute malicious JavaScript payloads, evading signature-based detection. In one intrusion at an Asian technology company, attackers downloaded the official Node.js installer after repeated payload blocks and used it to run an implant communicating with Ethereum blockchain gateways via EtherHiding techniques. The same threat actors compromised a U.S. fintech firm, deploying the Rust-based C2Looper backdoor linked to ransomware operations. Multiple attacks involved ModeloRAT, associated with initial access broker Woodgnat, connected to ransomware families including Qilin, Interlock, Rhysida, Akira, 8Base, Black Basta, and Embargo. Attackers employ ClickFix techniques for initial access and combine living-off-the-land tools with commodity malware. Join the discussion | AlienVault OTX General | 09/03/2026, 12:57:55 UTC Added: 09/03/2026, 16:22:14 UTC |
BraZetsu is a sophisticated Python-based Windows malware framework attributed to the Brazilian threat actor Exilware, functioning as a comprehensive toolkit for Initial Access Brokers. Unlike standard infostealers, BraZetsu transforms compromised systems into commercial assets through deep reconnaissance capabilities targeting Iberian and Latin American corporate, financial, industrial, and law enforcement environments. The framework scans for standardized financial remittance files in Brazilian CNAB format, extracts detailed browser histories, and employs AI-enhanced data triage for target prioritization. Operating through a modular architecture with stealth techniques, BraZetsu powers the Infected Marketplace where Exilware commercializes initial access to compromised hosts. The platform allows criminal customers to remotely execute secondary malicious payloads on purchased access, creating a persistent threat-multiplier effect. Tracked since February 2026, BraZetsu demonstrates rapid technical progressi... Join the discussion | AlienVault OTX General | 08/31/2026, 15:42:36 UTC Added: 09/01/2026, 08:52:34 UTC |
In May 2026, threat actors exploited CVE-2026-35616, an improper access control vulnerability in Fortinet EMS versions 7.4.5 through 7.4.6, to deploy EKZ Stealer within an energy sector organization. The malware was disguised as FortiEndpoint_Patch.exe and harvested browser credentials from Chromium-based browsers and Firefox before exfiltrating data via PowerShell to a command-and-control server. EKZ Stealer employs sophisticated compiler-based obfuscation techniques including indirect jumps, control-flow flattening, and XOR-based string encryption to evade analysis. The technical analysis demonstrates how Binary Ninja Workflows can be leveraged to defeat these obfuscation methods by matching repeatable Intermediate Language patterns and rewriting LLIL/MLIL expressions to restore readable control flow, significantly accelerating malware reverse engineering efforts. Join the discussion | CVE Database V5 | 08/26/2026, 07:21:30 UTC Added: 04/04/2026, 01:00:30 UTC |
A path traversal vulnerability affecting the Windows version of WinRAR allows the attackers to execute arbitrary code by crafting malicious archive files. This vulnerability was exploited in the wild and was discovered by Anton Cherepanov, Peter Košinár, and Peter Strýček from ESET. Join the discussion | CVE Database V5 | 08/24/2026, 00:00:00 UTC Added: 08/08/2025, 11:32:48 UTC |
SynkLoader is a sophisticated modular malware loader that uses multiple programming languages to evade detection. It begins with a Microsoft Teams phishing attack impersonating IT helpdesk staff to trick victims into installing a fake PowerShell cleaner via an MSI installer. The malware operates in memory, using Python, C#, C++, and PowerShell components to profile systems, maintain persistence through scheduled tasks, and deploy a fake Windows lock screen to phish credentials. Additional modules provide reverse proxy capabilities for network tunneling, remote shell, and VNC access, enabling attackers to move laterally and perform hands-on-keyboard operations. The complexity and multi-stage infection chain indicate potential use for ransomware or initial access brokering. Join the discussion | AlienVault OTX General | 08/21/2026, 02:04:26 UTC Added: 08/21/2026, 08:08:25 UTC |
Jewelbug is a China-based threat actor conducting dual operations: espionage campaigns targeting foreign governments and militaries, alongside a for-profit cryptocurrency fraud business administered from the same control panel. Operating as a small development team with role-based access controls and documented roadmaps, the group recorded over one million implant check-ins, 580,000+ stolen browser cookies, and 2,300+ exfiltrated emails between February and May 2026. Espionage attacks targeted government entities in the Middle East, Southeast Asia, and South Asia with confirmed intrusions. The group deploys the Antino backdoor, a malicious Chrome/Firefox extension called 'PDF Viewer,' and a Linux implant named ClientKing targeting servers and routers. The financially motivated arm operates as a registered Hunan company running industrial-scale SEO poisoning funneling Chinese-speaking victims to fake cryptocurrency exchange sites. Join the discussion | AlienVault OTX General | 08/13/2026, 11:13:15 UTC Added: 08/13/2026, 13:26:13 UTC |
Vanta Stealer is a Python-based information stealer utilizing PyArmor protection and PyInstaller packaging to complicate defensive analysis. The malware systematically harvests credentials from Chromium-based browsers, communication platforms like Discord and Telegram, gaming applications including Steam, Riot Games, Roblox and Minecraft, cryptocurrency wallets, Mullvad VPN configurations, and sensitive documents. It performs token enrichment by validating stolen Discord credentials against the API to retrieve account details, billing information, Nitro status, and server privileges. The modular architecture downloads dedicated browser extraction utilities at runtime, maintains independence between collection modules, and generates structured inventory reports before consolidating harvested data into ZIP archives. Exfiltration occurs via HTTP POST to attacker-controlled infrastructure with victim metadata. Distribution likely occurs through social engineering campaigns involving phishing emails, trojanized... Join the discussion | AlienVault OTX General | 08/06/2026, 17:04:55 UTC Added: 08/07/2026, 10:26:18 UTC |
After months of dormancy, XCSSET malware version 40 emerged in April 2026 targeting macOS developers through supply chain attacks. The malware hides in Xcode projects of legitimate applications on GitHub, spreading through infected development environments. V40 features advanced detection evasion through polymorphic payload generation, fileless persistence, and in-memory execution while weakening security mechanisms. It introduces 17 distinct modules including a Chrome hijacking backdoor via Chrome DevTools Protocol and a Telegram trojanizer. The malware employs multi-layered encryption, disables system security updates, terminates cloud telemetry, and locks XProtect signature databases. Primary targeting focuses on developers across South Asia. The infrastructure utilizes approximately 40 domains registered in Russia and India, demonstrating a geographic pivot in operations. Join the discussion | AlienVault OTX General | 08/03/2026, 09:05:16 UTC Added: 08/03/2026, 09:33:01 UTC |
Showing 1 to 10 of 147 results