Threats Tagged 't1560'
View all threats tagged with 't1560'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 't1560'
Click on any threat for detailed analysis and mitigation recommendations
For the latest discoveries in cyber research for the week of 5th October, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Arizona’s state court system has suffered a phishing-led cyberattack after an employee clicked a malicious link. Attackers copied backup files containing protective-order records and more than 150,000 Foster Care Review Board reports dating back to 2010, exposing personal and case-related information belonging to current and former participants. Japanese car-sharing service Times Car has disclosed a data breach affecting approximately 6.6 million current and former accounts. Exposed information includes personal data, while identity-verification documents, including driver’s-license images, were exposed for about 1.6 million accounts. Payment card information was not affected. South Africa’s air navigation provider has suffered a ransomware attack affecting operational technology supporting aviation weather services. Preliminary findings identified suspicious activity in weather-related environments, while separate reporting cited possible data theft. The provider has sought independent digital forensics to determine the scope of the incident. Fakturownia, a Polish online invoicing platform used by more than 600,000 businesses, has disclosed a data breach after an attacker exploited a system vulnerability. Copied information included account and company data, password hashes, bank account details, authentication tokens, contractor information, and portions of invoices stored on the platform. AI THREATS Researchers observed autonomous AI agents attempting rudimentary hacking techniques while gathering public information from US and Canadian government websites. Activity included failed SQL injection attempts against the US Department of Education and Library and Archives Canada. Officials reported no compromise, while the origin of the agents remains unconfirmed. Researchers demonstrated that malicious Custom GPTs hosted on ChatGPT were used in a ClickFix campaign to deliver remote access malware. Victims were redirected to a Google Sites page and tricked into running commands. Huntress investigated at least 40 related incidents, including two confirmed infections that began through Custom GPTs. Researchers outlined how JadePuffer, an AI-enabled threat actor tracked as Storm-3168, used compromised Azure service principals to automate cloud reconnaissance and destructive actions. The activity included deleting storage and application resources, targeting backup-related assets, and attempting to retrieve access keys, reflecting agent-driven post-compromise operations in cloud environments. VULNERABILITIES AND PATCHES Citrix has issued fixes for critical NetScaler vulnerabilities CVE-2026-88771-2, affecting NetScaler ADC and Gateway. Attackers have exploited the flaws to gain remote access, deploy web shells and tunneling malware, steal credentials, and move from exposed appliances into internal networks. Check Point IPS provides protection against these threats (Citrix NetScaler Multiple Products Buffer Overflow (CVE-2026-88772), Citrix NetScaler Multiple Products Command Injection (CVE-2026-88771)) Cisco has alerted about CVE-2026-76504, a critical (CVSS 9.8) vulnerability in Catalyst SD-WAN Manager. The flaw allows an unauthenticated remote attacker to send crafted requests and gain administrator access. Cisco reported active exploitation and stated that no fixes are available. Check Point IPS provides protection against this threat (Cisco Catalyst SD-WAN Manager Authentication Bypass (CVE-2026-76504)) Apple has patched CVE-2026-86950, a CoreGraphics memory corruption vulnerability affecting iPhones, iPads, and Macs. Processing a malicious image or PDF can allow arbitrary code execution. Apple reported exploitation in highly targeted attacks and addressed the flaw through improved bounds checking across affected iOS, iPadOS, and macOS releases. GitLab has released patches for CVE-2… Join the discussion | CVE Database V5 | 10/07/2026, 21:37:31 UTC Added: 09/27/2026, 16:33:34 UTC |
An Iranian state-aligned threat actor, CL-STA-1178, has been conducting the Blinder Tunnel campaign since November 2025, targeting Iraqi critical infrastructure by impersonating the Dubai Airports IT department. The campaign delivers trojanized coding challenges that deploy ShelbyLoader V2 malware through a multi-stage attack chain involving AppDomainManager hijacking and DLL sideloading. The attackers use GitHub API infrastructure for command-and-control communications, including repositories and issues as fallback channels. Operational security errors revealed links to a separate credential harvesting campaign targeting Israeli entities with conflict-themed Google Drive lures in mid-2026. Join the discussion | AlienVault OTX General | 10/07/2026, 09:47:16 UTC Added: 10/07/2026, 10:03:26 UTC |
SectopRAT (also known as ArechClient2) is a .NET-based remote access trojan (RAT) that provides a range of functions through multiple control commands. These include collecting sensitive data from the victim’s device, capturing screens, remotely managing processes and files, controlling bots, and other forms of remote device management. Join the discussion | AlienVault OTX General | 09/25/2026, 14:42:13 UTC Added: 09/25/2026, 14:48:04 UTC |
A Windows malware called CLOSEDQUORUM is built to take orders from a vote of up to four AI models instead of an attacker's server, Cisco Talos said on September 22. The models can choose to steal Windows credentials, saved browser passwords, and crypto wallet data. Talos has not seen this setup work from start to finish, and the public version of the malware does not work as it is. Join the discussion | AlienVault OTX General | 09/23/2026, 20:08:58 UTC Added: 09/23/2026, 20:17:47 UTC |
A third variant of PamStealer has been identified, distributed through a fake Wavel cryptocurrency wallet application. The malware employs a sophisticated server-side decryption chain using a purpose-built utility called pkgunpack that performs live ECIES key exchange with command-and-control infrastructure, making offline payload decryption impossible. The second stage has been rewritten from Rust to Swift while maintaining PAM-based credential validation. The infostealer targets seventeen browsers including Arc, Zen, Waterfox, and LibreWolf, extracts keychain credentials, collects system fingerprints, and harvests user files including shell history and account photos via Open Directory. Persistence is maintained through four redundant repair mechanisms including LaunchAgent installation, shell hooks, Git hooks, and a local backup tarball, with notification suppression achieved by killing background task management processes. Join the discussion | AlienVault OTX General | 09/22/2026, 20:35:41 UTC Added: 10/02/2026, 08:01:51 UTC |
LabubaRAT is a custom 64-bit Rust-based remote access trojan targeting Windows systems, masquerading as legitimate NVIDIA software. It offers extensive remote control features such as command execution, file operations, screen capture, and SOCKS5 proxying. The malware is part of a malware-as-a-service framework, managed via a backend called LabubaPanel hosted on German infrastructure. It uses its own JavaScript execution for delivery and employs evasion techniques including impersonation of NVIDIA components and abuse of Microsoft build utilities. First observed in July 2026, it is unsigned and designed for persistence and stealth. Join the discussion | AlienVault OTX General | 09/18/2026, 12:51:24 UTC Added: 09/18/2026, 14:01:41 UTC |
Noodle RAT, also known as ANGRYREBEL or Nood RAT, is a modular remote access trojan with dual versions for Windows and Linux, actively used by Chinese-speaking threat actors since at least mid-2016. Previously misclassified as variants of Gh0st RAT or Rekoobe, it is now recognized as a distinct backdoor family. The malware has been deployed in espionage and cybercrime campaigns targeting entities across the Asia-Pacific region, including Thailand, India, Japan, Malaysia, and Taiwan. Multiple threat groups including Iron Tiger, Calypso APT, Rocke, and Cloud Snooper have utilized this tool. Both variants feature shared command-and-control architecture, similar configuration structures, and modular capabilities. The Windows version operates as an in-memory backdoor with file management and proxy capabilities, while the Linux variant provides reverse shell, SOCKS tunneling, and task scheduling functionalities. Evidence suggests an actively maintained, possibly commercial malware toolkit. Join the discussion | AlienVault OTX General | 09/16/2026, 17:02:59 UTC Added: 09/17/2026, 10:46:37 UTC |
An intrusion was investigated that began with exploitation of CVE-2026-48558, a critical authentication bypass vulnerability in SimpleHelp RMM software. The threat actor obtained unauthorized technician access and deployed two previously undocumented malware samples: TaskWeaver and Djinn Stealer. TaskWeaver is a heavily obfuscated Node.js loader that establishes encrypted communications and delivers additional payloads. Djinn Stealer targets credentials across Windows, macOS, and Linux systems, collecting authentication data for cloud platforms, source control, package registries, AI development assistants, browsers, SSH keys, and cryptocurrency wallets. The attacker leveraged legitimate RMM capabilities to transfer files and execute commands across managed systems. Stolen AI assistant tokens provided extensive access to repositories, databases, and cloud accounts. The intrusion demonstrated how a single authentication bypass in trusted management infrastructure can enable widespread credential theft and p... Join the discussion | Bleeping Computer | 09/10/2026, 12:49:58 UTC Added: 06/29/2026, 14:06:27 UTC |
A previously undocumented Linux toolkit has been targeting South Korean automotive and media organizations with minimal detection since early 2025. The campaign employs a HAProxy instance called ted backdoor, compiled within the victim's existing HAProxy version 2.8.12, alongside trojanized versions of crond, agetty, atd, sshd, and polkitd. This sophisticated framework enables remote command execution, malicious script injection into web traffic, credential harvesting, and long-term surveillance. The ted backdoor uses HAProxy's native filter API and internal structures to intercept SSL-decrypted HTTP traffic while maintaining legitimate load balancing operations. Operating alongside are an SSH keylogger, a curl-based RAT with HAProxy health monitoring capabilities, and a deployment stager. The toolkit is attributed with medium confidence to DPRK APTs based on targeting patterns, simple XOR-based encryption schemes, custom substitution ciphers, and C2 infrastructure associated with APT37. Join the discussion | AlienVault OTX General | 09/04/2026, 16:53:57 UTC Added: 09/07/2026, 10:22:27 UTC |
Two distinct multi-stage network intrusion campaigns are actively targeting Latin American organizations, with attackers leveraging artificial intelligence tools to enhance their capabilities. The Mexican transportation campaign (CL-CRI-1131) impacted transportation organizations and government entities in Mexico and Ecuador, utilizing living-off-the-land techniques and self-hosted NextChat instances. The Brazilian financial campaign (CL-CRI-1163) employed custom RATs and tunneling tools including a Go-based SOCKS5 proxy. Both operations demonstrate technical overlaps including shared SOCKS5 infrastructure and reliance on commercial large language models like Claude and GPT-4.1 for operational orchestration. Attackers used AI to generate scripts and troubleshoot execution failures, evidenced by iterative file naming patterns and exposed NextChat interfaces. However, fundamental operational security failures, including exposed staging directories and unsecured interfaces, provided defenders clear visibility... Join the discussion | AlienVault OTX General | 09/03/2026, 12:45:15 UTC Added: 09/03/2026, 16:22:14 UTC |
Showing 1 to 10 of 38 results