Threats Tagged 't1562'
View all threats tagged with 't1562'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 't1562'
Click on any threat for detailed analysis and mitigation recommendations
Galago is a newly identified ransomware operation that emerged in September 2026, claiming operational partnership with the Panzer ransomware group. The connection is suggested through shared infrastructure, specifically matching prefixes in their Tor leak-site addresses (pnzr4del for Galago and pnzruro for Panzer). Galago was first detected following an alleged attack on an Icelandic healthcare organization on 9 September 2026, though this claim remains unverified as their dark leak site showed no published victims. Panzer, described as a ransomware-as-a-service operation, has published 32 victims between August and September 2026 and employs double extortion tactics. While the naming pattern and self-reported claims suggest a relationship, no independent evidence confirms shared operators, malware, or infrastructure control between the two groups. Join the discussion | AlienVault OTX General | 09/24/2026, 12:40:33 UTC Added: 09/24/2026, 19:33:01 UTC |
In April 2026, a manufacturing organization in the Middle East suffered a ransomware attack where threat actors with domain admin privileges weaponized Active Directory Group Policy Objects to achieve domain-wide impact without deploying ransomware binaries on Windows endpoints. The attackers created malicious GPOs linked at the domain root, delivering ransom notes, hijacking wallpapers and lock screens, enforcing logon banners, and disabling local administrator accounts across all domain-joined workstations. No file encryption occurred on Windows systems; instead, the operation focused on encryptionless extortion through operational disruption and data exfiltration. Initial access was gained via compromised VPN credentials. The attack remained dormant for one day between GPO creation and detonation, evading file-based detection entirely by abusing trusted AD infrastructure. Join the discussion | AlienVault OTX General | 09/21/2026, 11:54:10 UTC Added: 09/21/2026, 15:31:54 UTC |
This analysis discusses how poorly designed AI guardrails in security operations can unintentionally aid attackers by impeding defensive actions. Overly restrictive or inflexible AI filters controlled by third-party providers may cause delays or refusals in security investigations, giving adversaries more time to complete their objectives. The author recommends that security teams maintain operational sovereignty over guardrails, allowing customization and temporary adjustments to safeguards to better align with specific threat models. This flexibility is essential to prevent attackers from exploiting rigid controls to disrupt incident response processes. Join the discussion | AlienVault OTX General | 08/27/2026, 21:51:45 UTC Added: 08/28/2026, 09:07:13 UTC |
0 A sophisticated credential theft campaign manipulates DNS and HTTP traffic on captive portal networks at hotels, conference centers, and hospitality venues to redirect victims to attacker-controlled infrastructure. The operation harvests Microsoft 365 credentials through phishing pages, device code phishing abusing Microsoft Entra ID authentication flow, and malware delivery via ClickFix social engineering techniques. Evidence indicates compromised shared captive portal services rather than individual venue breaches, with affected gateways identified in several U.S. cities, India, and Saudi Arabia. The campaign deploys two primary malware tools: CornFlake, a Go-based RAT providing persistent access and extensive surveillance capabilities, and ChocoShell, an in-memory PowerShell stealer that harvests browser credentials, Microsoft 365 tokens, and Azure AD tokens. The operation targets travelers across multiple sectors and has expanded to include Android devices through malicious APK files. Join the discussion | CVE Database V5 | 08/12/2026, 02:31:33 UTC Added: 01/26/2026, 17:21:12 UTC |
0 An authentication bypass vulnerability, CVE-2026-18577, affecting N-able N-central Remote Monitoring and Management platform has been actively exploited since August 1, 2026. This vulnerability emerged after an incomplete fix for a previous authentication bypass issue CVE-2026-18556. The flaw allows remote unauthenticated attackers to bypass authentication mechanisms and gain administrative control over vulnerable N-central servers. Attackers have exploited this vulnerability to leverage the platform's Take Control functionality for remote access to managed endpoints and deployed Cloudflare Tunnel (cloudflared) to establish persistent remote access. Given that N-central is widely used by managed service providers and enterprise IT teams with extensive administrative privileges, successful compromise provides attackers an efficient pathway to compromise downstream managed systems. CISA added this vulnerability to its Known Exploited Vulnerability catalog on August 3, 2026. Join the discussion | CVE Database V5 | 08/06/2026, 09:39:27 UTC Added: 08/02/2026, 22:33:37 UTC |
0 Check Point has released urgent security updates addressing three critical vulnerabilities affecting Security Management, Multi-Domain Management, Quantum Security Gateway, and Gaia operating systems. The most severe vulnerability, CVE-2026-16232, allows unauthenticated remote attackers to bypass SmartConsole login and gain full administrative access to exposed Management Servers. The vulnerability has been actively exploited against customers with internet-exposed management infrastructure. Successful exploitation enables attackers to modify firewall policies, create administrator accounts, weaken security protections, and establish persistent access. Two additional vulnerabilities were patched: CVE-2026-62144 enabling unauthenticated command execution, and CVE-2026-62145 allowing privilege escalation from read-only to root access. CISA added CVE-2026-16232 to its Known Exploited Vulnerabilities catalog with an exceptionally short remediation deadline, reflecting the severity of this authentication bypass... Join the discussion | CVE Database V5 | 07/24/2026, 21:40:32 UTC Added: 07/22/2026, 14:08:07 UTC |
0 A security update addresses multiple vulnerabilities discovered during routine security review, including authentication bypass issues affecting management products. One vulnerability (CVE-2026-16232) has been exploited in the wild against a limited number of customers with specific configurations where Management is exposed directly to the internet without IP restrictions. The affected systems include Security Management and Multi-Domain Management across multiple versions. Two additional vulnerabilities address authentication bypass with privilege escalation and local privilege escalation in GaiaOS WebUI. All impacted customers have been notified, and Smart-1 Cloud customers are already protected. Indicators of compromise include six IP addresses associated with the exploitation activity. Installation of the latest Jumbo hotfix is recommended along with implementation of security best practices. Join the discussion | CVE Database V5 | 07/24/2026, 14:24:56 UTC Added: 06/08/2026, 11:33:51 UTC |
A misconfigured Python HTTP server on a Budapest VPS exposed the complete operational infrastructure of three distinct phishing operators. The investigation uncovered codemado, an Egyptian threat actor operating since 2018, running a full AiTM platform with custom tools including MaDoO Blaster; saroula01, deploying OAuth Device Code Flow attacks that accumulated 218 victims across 12 countries over a year; and mail-argenta, a Nigerian operator identified through infostealer logs containing his own credentials. All three actors leveraged customized Evilginx forks and AI-assisted development to build MFA-bypass infrastructure from public GitHub repositories. The campaigns targeted Microsoft 365 accounts primarily, with codemado maintaining ties to RockyBelling's "The Quarry" cybercrime ecosystem. The exposed server contained phishing configurations, credential logs, RMM installers, combolists, and Telegram session files, revealing sustained operations from at least January 2025 through May 2026. Join the discussion | AlienVault OTX General | 07/13/2026, 10:36:53 UTC Added: 07/13/2026, 11:03:04 UTC |
Prinz Eugen is a newly discovered Go-based ransomware family first observed in April 2026, attributed to an actor known as ROOTBOY. The encryptor employs sophisticated techniques including ChaCha20-Poly1305 encryption, prioritizes recently modified files to maximize pressure on victims, and implements anti-forensic measures such as memory scrubbing and self-deletion. Unlike typical ransomware, it leaves no ransom note on disk, conducting all extortion communications out-of-band through leak sites and direct contact. The threat actor gains initial access through compromised RDP credentials, uses legitimate RMM tools like RemotePC for persistence, and creates backdoor admin accounts. Victims span multiple countries and sectors, with notable incidents including Standard Bank Group in South Africa and Transitions Pro Centre Val de Loire in France. Join the discussion | AlienVault OTX General | 06/25/2026, 14:55:43 UTC Added: 06/25/2026, 15:16:16 UTC |
Since late 2025, cybercriminals have been exploiting Wallpaper Engine, a popular live wallpaper application on Steam, to distribute malware through Steam Workshop. Attackers target primarily Chinese and Russian gamers by embedding malicious code within application wallpapers shared on the platform. These compromised wallpapers deliver various malware types including infostealers, backdoors, crypto miners, and ransomware. One analyzed sample dropped DarkKomet backdoor while hijacking Steam sessions to steal account credentials. The malware modifies system libraries to locate Steam installations and exfiltrate data to attacker-controlled servers. Compromised accounts are then used to upload additional malicious wallpapers. The diverse malware families suggest multiple independent hacking groups are exploiting this distribution method. Infected wallpapers received thousands of downloads before removal, with 89% of infections occurring in China. Join the discussion | AlienVault OTX General | 06/16/2026, 09:50:13 UTC Added: 06/16/2026, 11:30:21 UTC |
Showing 1 to 10 of 50 results