Threats Tagged 't1565'
View all threats tagged with 't1565'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 't1565'
Click on any threat for detailed analysis and mitigation recommendations
Iran's Ministry of Intelligence has broadened its Handala brand beyond cyber operations to include physical threats and influence campaigns targeting US and Israeli interests. The expansion encompasses multiple personas: Handala Popular Resistance Front claiming physical attacks inside Israel, VIPEmployment recruiting proxies globally for espionage and sabotage, and MOISIRAN conducting surveillance operations. These entities engage in coordinated amplification across platforms, soliciting individuals to conduct attacks for financial rewards. The consolidation creates a multi-domain threat combining hacktivist activities with physical operations, espionage recruitment, and influence campaigns. This approach leverages Handala Hack Team's recognition to amplify recruitment efforts while increasing risks to law enforcement, military, intelligence personnel, and critical infrastructure across targeted regions. Join the discussion | AlienVault OTX General | 06/02/2026, 14:38:53 UTC Added: 06/03/2026, 09:33:37 UTC |
A sophisticated phishing campaign impersonating Tesseract OCR was discovered, utilizing typosquatting and ClickFix techniques. The attack chain, named OCRFix, employed multi-stage malware deployments with heavy obfuscation and defense evasion techniques, including EtherHiding. The campaign used BNB Smart Chain TestNet to hide C2 domains through smart contracts. The malware delivery process involved three stages: a loader, a secondary loader for persistence, and a bot listener. The final payload connected to a bot control panel, allowing attackers to manage infected hosts and deploy additional malware. The campaign demonstrated a combination of simple initial access methods with complex delivery chains, highlighting the ongoing effectiveness of techniques like ClickFix and the importance of robust phishing defenses. Join the discussion | AlienVault OTX General | 02/27/2026, 09:28:41 UTC Added: 02/27/2026, 09:55:15 UTC |
In late 2025, Poland's energy system was targeted by a major cyberattack, now attributed to the Russia-aligned APT group Sandworm by ESET Research. The attack involved data-wiping malware named DynoWiper, detected as Win32/KillFiles.NMO. While the full impact is still under investigation, researchers noted the attack's timing coincided with the 10th anniversary of Sandworm's 2015 attack on Ukraine's power grid. Sandworm continues to target critical infrastructure, particularly in Ukraine, with regular wiper attacks. The group's history of disruptive cyberattacks and the similarities in tactics, techniques, and procedures led to a medium-confidence attribution of this latest incident to Sandworm. Join the discussion | AlienVault OTX General | 01/23/2026, 22:47:09 UTC Added: 01/23/2026, 23:05:56 UTC |
Multiple Russia-linked influence operations are targeting Moldova's September 2025 parliamentary elections, aiming to destabilize the process and impede Moldova's EU accession. These operations, including Operation Overload, Operation Undercut, Foundation to Battle Injustice, and Portal Kombat, are projecting negative views of President Maia Sandu and the ruling Party of Action and Solidarity. They portray EU integration as disastrous for Moldova's economy and sovereignty, while suggesting closer ties with Russia as a favorable alternative. The operations employ various tactics, including inauthentic news content, social media manipulation, and automated content generation. While their impact on voter behavior appears limited so far, they pose risks to media integrity and public trust. Join the discussion | AlienVault OTX General | 09/03/2025, 16:52:11 UTC Added: 09/03/2025, 19:47:48 UTC |
A sophisticated SEO spam infection was discovered utilizing a cleverly crafted plugin that mimics the infected domain's name to avoid detection. The malware injects spam content into websites, targeting search engine rankings, and only activates under specific conditions like when a crawler is detected. The plugin's code is heavily obfuscated, using thousands of variable assignments broken into small parts. When decoded, the malware downloads files from external hosts, fetches remote content, and delivers custom spam to search engines while appearing normal to regular users. The attacker's domain, mag1cw0rld[.]com, is used for remote control. This technique allows the spam to remain undetected for longer periods, making it challenging to identify with traditional tools. Join the discussion | AlienVault OTX General | 07/06/2025, 13:13:42 UTC Added: 07/07/2025, 09:54:20 UTC |
Showing 1 to 5 of 5 results