Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.

Threats Tagged 't1557'

View all threats tagged with 't1557'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: t1557

Threats Tagged 't1557'

Click on any threat for detailed analysis and mitigation recommendations

Inhospitable: Tracking Russian Cyber Espionage Infrastructure
0

This analysis examines infrastructure used by multiple Russian cyber espionage clusters targeting individuals in academia, think tanks, and organizations across Europe and the United States. The investigation expands on three threat clusters (UNC6293, UNC7005, and UNC5976) that employed OAuth phishing, Microsoft device code phishing, and WhatsApp targeting. UNC6293 utilized lure domains impersonating the Council on Foreign Relations and government portals, with possible Evilginx configurations. UNC7005 demonstrated lower sophistication with poor operational security, using domains like my-invite[.]org for phishing campaigns. UNC5976 employed Google Drive impersonation domains for OAuth phishing. The analysis leverages historical DNS data, CSS hash similarities, favicon analysis, registration patterns, and certificate information to identify additional infrastructure and tracking methods for discovering related malicious domains and IP addresses.

Join the discussion
737 Chrome VPN Extensions Linked to Brand Impersonation and Browser Traffic Redirection
0

Socket's Threat Research Team identified a campaign of 737 malicious VPN and proxy extensions in the Chrome Web Store, accumulating over 75,000 installs. The extensions, published across 40 developer accounts, target Russian-speaking users seeking access to blocked services. 274 extensions impersonate 66 established VPN brands including Proton VPN, NordVPN, and AmneziaVPN. The extensions route all browser traffic through SOCKS5 proxies controlled by a single operator on port 1082, placing the threat actor in an adversary-in-the-middle position. Premium subscription tiers advertise servers in five countries that do not resolve. The campaign employs DNS-over-HTTPS for evasion, post-approval code substitution, and coordinated review gaming. The operation is linked to a Russian subscription VPN business that names a tax-registered self-employed individual as the contracting party.

Join the discussion

Showing 1 to 2 of 2 results

Filters:Tag: t1557
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses