Threats Tagged 't1564.003'
View all threats tagged with 't1564.003'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 't1564.003'
Click on any threat for detailed analysis and mitigation recommendations
BraZetsu is a Python-based Windows malware framework used by the Brazilian threat actor Exilware. It acts as a toolkit for Initial Access Brokers, turning compromised systems into commercial assets. The malware targets corporate, financial, industrial, and law enforcement sectors in Iberia and Latin America. It harvests financial transaction files in Brazilian CNAB format, browsing histories, and digital certificates. BraZetsu supports the 'Infected Marketplace' where initial access is sold to criminal clients for further exploitation. It has evolved rapidly since early 2026, incorporating AI-enhanced reconnaissance and advanced evasion techniques. Join the discussion | AlienVault OTX General | 10/02/2026, 13:14:24 UTC Added: 10/05/2026, 09:03:32 UTC |
A sophisticated PowerShell-based backdoor named TASK#STOMP has been discovered that specifically targets business documents while maintaining persistent remote access to compromised systems. The infection begins with VBScript execution, establishing persistence through scheduled tasks and startup folder entries. The malware deploys two primary PowerShell payloads that scan fixed drives for Word, PDF, PowerPoint, Excel, and archive files modified within the past year, excluding files larger than 500MB. It employs filesystem watchers for continuous collection of new documents. Additional capabilities include screenshot capture, Wi-Fi password theft, clipboard monitoring, and arbitrary command execution. The backdoor communicates with two command-and-control domains and uses compiled C helpers to bypass TLS certificate validation, enabling connections to servers with invalid certificates. Join the discussion | AlienVault OTX General | 09/24/2026, 12:41:15 UTC Added: 09/24/2026, 19:33:01 UTC |
Threat actors exploited trusted brands and cloud services in a sophisticated web campaign combining fraudulent DocuSign workflows, Florida healthcare screening lures, and deceptive cloud infrastructure to deploy ConnectWise ScreenConnect Access clients. The attack utilized Cloudflare Pages hosting with fake Cloudflare verification workflows to establish legitimacy. Victims were socially engineered to download a ZIP archive containing a malicious HTA file that employed Base64-encoded VBScript, fake Adobe interfaces, UAC privilege escalation, and Microsoft Defender SmartScreen registry modifications. The attack leveraged living-off-the-land techniques using native Windows tools like mshta.exe, curl.exe, and msiexec.exe for silent ScreenConnect installation, ultimately providing unauthorized remote access. The campaign was classified as Zero Hour Fraudulent and blocked at the web entry point before payload delivery could occur. Join the discussion | AlienVault OTX General | 09/11/2026, 03:23:51 UTC Added: 09/11/2026, 14:47:25 UTC |
A compilation artifact, specifically a developer's home directory path (/home/tcherber/.cargo/), linked multiple malware families including a Rust-based infostealer named Zer0day Stealer, an HVNC remote-control tool, and ENIGMA Locker ransomware to a single developer. The infostealer exfiltrates cryptocurrency wallets, browser credentials, Office documents, and VPN configurations. The HVNC tool enables hidden remote desktop sessions and implements AMSI and ETW evasion techniques. Analysis revealed an actively developed, cross-platform malware operation spanning Windows, Linux, and macOS. Multiple droppers written in C, Rust, and PowerShell were discovered delivering the malicious payloads. Build timestamps indicated development occurred within weeks, and infrastructure leaked evidence of additional tools including FUD-Crypter, Botnet, and C2 Agent components, demonstrating how overlooked compilation artifacts enable comprehensive attribution and threat mapping. Join the discussion | AlienVault OTX General | 09/01/2026, 22:50:50 UTC Added: 09/02/2026, 16:22:27 UTC |
BraZetsu is a sophisticated Python-based Windows malware framework attributed to the Brazilian threat actor Exilware, functioning as a comprehensive toolkit for Initial Access Brokers. Unlike standard infostealers, BraZetsu transforms compromised systems into commercial assets through deep reconnaissance capabilities targeting Iberian and Latin American corporate, financial, industrial, and law enforcement environments. The framework scans for standardized financial remittance files in Brazilian CNAB format, extracts detailed browser histories, and employs AI-enhanced data triage for target prioritization. Operating through a modular architecture with stealth techniques, BraZetsu powers the Infected Marketplace where Exilware commercializes initial access to compromised hosts. The platform allows criminal customers to remotely execute secondary malicious payloads on purchased access, creating a persistent threat-multiplier effect. Tracked since February 2026, BraZetsu demonstrates rapid technical progressi... Join the discussion | AlienVault OTX General | 08/31/2026, 15:42:36 UTC Added: 09/01/2026, 08:52:34 UTC |
A sophisticated infection chain leverages PowerShell loaders to deliver encrypted NetSupport client payloads concealed within fake MP4 files. The malicious MP4 containers appear valid to basic file-type checks but contain 6.5 MB of encrypted data in ISO Base Media File Format uuid extension boxes rather than playable video content. The attack begins with PowerShell delivered via Cloudflare-fronted infrastructure, performing environment checks before retrieving the carrier file. A secondary script parses the MP4 structure, extracts and decrypts an embedded 16.8 MB PowerShell payload, then deploys NetSupport Manager with silent operation configured. Infrastructure spans 40 live endpoints across six autonomous systems, primarily in Frankfurt and Los Angeles, with command-and-control gateways registered 77 seconds apart. The toolkit employs Russian-language business site decoys and rotates carriers frequently without backward compatibility. Join the discussion | AlienVault OTX General | 08/29/2026, 00:24:24 UTC Added: 08/31/2026, 09:52:14 UTC |
Grandoreiro, a notorious banking trojan active since 2016 across Latin America, continues operations despite major law enforcement disruption in 2024. Recent campaigns leverage DLL sideloading techniques, abusing the legitimate Duplicate Files Finder application to execute malicious code. The loader incorporates extensive anti-analysis mechanisms including sandbox detection, virtual machine artifact checks, process blacklisting, and environment profiling to evade automated analysis systems. These defensive checks occur before C2 contact, indicating high priority on avoiding detection. Telemetry from June 2026 shows activity concentrated in Latin America, primarily Mexico, with limited presence in Europe and North America. The malware uses custom string obfuscation combining proprietary decryption with Base64 encoding, and communicates with C2 infrastructure over TCP port 6432 using encrypted requests containing host-specific information. Join the discussion | AlienVault OTX General | 08/19/2026, 20:39:08 UTC Added: 08/20/2026, 23:07:12 UTC |
HoneyMyte APT group (also known as Mustang Panda) has significantly upgraded its CoolClient backdoor with kernel-level rootkit capabilities. The latest variant deploys a signed kernel-mode driver (msagent.sys) as a Windows service, enabling advanced stealth features including process hiding, file and registry protection, and network traffic filtering. The multi-stage malware uses DLL sideloading through a legitimate Sangfor application, establishes persistence via scheduled tasks and AutoRun entries, and implements UAC bypass techniques. CoolClient now injects into synchost.exe and communicates with the kernel driver through IOCTL requests. The driver hooks Nsiproxy to filter C2 addresses from network information. Victims have been identified in Myanmar, Mongolia, Pakistan, and Russia, with PlugX serving as the initial infection vector before CoolClient deployment. Join the discussion | AlienVault OTX General | 08/14/2026, 10:50:02 UTC Added: 08/14/2026, 11:26:13 UTC |
A threat hunting investigation identified suspicious PowerShell content served from an IP address (203.188.171.166) and domain (dorenzaa.com), both retrieving ZIP archives from Vercel-hosted infrastructure. The PowerShell loaders extract and execute payloads locally, including Grape.exe, UltraToolliteSetup.exe, and draw.io.exe. Analysis revealed heavily obfuscated PowerShell stages utilizing Base64 encoding, XOR-based obfuscation with the key 'Write', dynamically constructed IEX commands, and hidden PowerShell execution. A decoy 'Verification complete!' message disguised as Google.com was presented to victims during execution. Multiple Vercel instances hosted additional artifacts including loader scripts and executables. The initial infection vector remains unidentified, suggesting these PowerShell-hosting URLs represent second-stage delivery points in a multi-stage attack chain. Join the discussion | AlienVault OTX General | 08/10/2026, 14:20:36 UTC Added: 08/10/2026, 15:56:14 UTC |
The Kimsuky threat group has integrated artificial intelligence capabilities into its attack operations, establishing local large language model environments using Ollama, GPT4All, and Msty. Evidence indicates the group is accumulating technologies to incorporate AI across attack operations, including AI-generated decoy documents and retrieval-augmented generation for document analysis. The campaign, dubbed Operation GitPower, continues targeting foreign diplomatic missions and sectors including military, security, and virtual assets. Attacks utilize malicious LNK files contained in ZIP archives, executing obfuscated PowerShell scripts that abuse Git-based repositories as command-and-control infrastructure. The group distributes encrypted AsyncRAT payloads disguised as image files through GitHub. Linguistic indicators including North Korean vocabulary patterns such as "싸이트", "가입리력", and "로출되였는지" support attribution to North Korean state-sponsored operations under the Reconnaissance General Bureau. Join the discussion | AlienVault OTX General | 08/10/2026, 13:45:54 UTC Added: 08/10/2026, 15:56:14 UTC |
Showing 1 to 10 of 34 results