Skip to main content

Threats Tagged 't1567'

View all threats tagged with 't1567'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: t1567

Threats Tagged 't1567'

Click on any threat for detailed analysis and mitigation recommendations

This document analyzes multiple cybersecurity incidents involving various threat actors and malicious campaigns. The analysis covers sophisticated attack methodologies including exploitation of vulnerabilities, deployment of specialized malware tools, and targeting of critical infrastructure across multiple sectors. The campaigns demonstrate advanced persistent threat capabilities with focus on data exfiltration, system compromise, and lateral movement within targeted networks. Key observations include the use of social engineering tactics, exploitation of remote access vulnerabilities, and deployment of custom malware frameworks. The threat landscape encompasses government, technology, financial, and defense sectors with significant emphasis on supply chain attacks and credential harvesting operations.

Join the discussion

The GrelosGTM cybercriminal group abuses the legitimate functionality of Google Tag Manager to compromise e-commerce websites, primarily those running Magento CMS. Since early 2020, they have injected malicious Google Tag Manager scripts that load multi-stage JavaScript payloads via WebSocket connections. The final payload is a heavily obfuscated JavaScript sniffer designed to steal payment card information during checkout through fake payment forms. Stolen data is exfiltrated to attacker-controlled servers. The campaign has affected at least seven websites across Belgium, Italy, the United Kingdom, and the United States.

Join the discussion

Multiple cloud accounts have been compromised through passkey-themed social engineering campaigns since May 2026. Attackers impersonate IT helpdesk staff via phone calls or SMS, directing victims to phishing sites that mimic Microsoft sign-in pages. After obtaining credentials through adversary-in-the-middle or device code authentication flows, attackers establish persistence by adding unauthorized MFA methods. They then conduct extensive reconnaissance using Microsoft Graph API to map users, groups, permissions, and resources. The intrusion culminates in high-volume data collection from SharePoint, OneDrive, and Exchange using automated tools, with exfiltration occurring over hours or days at controlled rates to avoid detection.

Join the discussion

Two distinct multi-stage network intrusion campaigns are actively targeting Latin American organizations, with attackers leveraging artificial intelligence tools to enhance their capabilities. The Mexican transportation campaign (CL-CRI-1131) impacted transportation organizations and government entities in Mexico and Ecuador, utilizing living-off-the-land techniques and self-hosted NextChat instances. The Brazilian financial campaign (CL-CRI-1163) employed custom RATs and tunneling tools including a Go-based SOCKS5 proxy. Both operations demonstrate technical overlaps including shared SOCKS5 infrastructure and reliance on commercial large language models like Claude and GPT-4.1 for operational orchestration. Attackers used AI to generate scripts and troubleshoot execution failures, evidenced by iterative file naming patterns and exposed NextChat interfaces. However, fundamental operational security failures, including exposed staging directories and unsecured interfaces, provided defenders clear visibility...

Join the discussion

A campaign identified by the Socket Threat Research team involves 19 malicious browser extensions (18 for Chrome, 1 for Edge) active since February 2024. These extensions deliver a modular malware framework that communicates with command and control servers via WebSocket, strips Content Security Policy headers, and uses cross-site scripting (XSS) injection to execute payloads. The primary goal is to steal cryptocurrency wallet secrets and drain crypto assets, as well as harvest credentials. The threat actor either creates malicious extensions from scratch or compromises legitimate extensions with existing user bases, such as the 'Enable Right Click & Copy' extension with tens of thousands of users. The campaign, named 'Superior,' shows sophisticated and evolving capabilities targeting multiple cryptocurrency platforms and exchanges.

Join the discussion

This analysis discusses how poorly designed AI guardrails in security operations can unintentionally aid attackers by impeding defensive actions. Overly restrictive or inflexible AI filters controlled by third-party providers may cause delays or refusals in security investigations, giving adversaries more time to complete their objectives. The author recommends that security teams maintain operational sovereignty over guardrails, allowing customization and temporary adjustments to safeguards to better align with specific threat models. This flexibility is essential to prevent attackers from exploiting rigid controls to disrupt incident response processes.

Join the discussion

The Gentlemen is a ransomware group active since July 2025, operating a Ransomware-as-a-Service model with dual-extortion tactics. They target Windows, Linux, and ESXi systems, focusing on extensive preparation before encrypting data. Their methods include privilege escalation using legitimate tools, persistence via registry and scheduled tasks, disabling security tools, deleting logs, and terminating backup services. They use strong encryption algorithms XChaCha20 and Curve25519. The group primarily targets medium-to-large organizations in the Asia-Pacific region, with a recent surge in activity. Victims face ransom demands with about 10-day deadlines and threats of data publication if unpaid.

Join the discussion

A China-linked cyber espionage infrastructure provider operates a multi-component 'quartermaster' system that offers reconnaissance, proxy orchestration, and traffic routing services to Chinese state-sponsored actors. The infrastructure includes QScan for reconnaissance, Fast Labyrinth for encrypted relay networks using commercial proxy services, QTRouter for proxy access management, and QTProxy for operational node control. It targets research universities, defense networks, government agencies, and critical infrastructure worldwide, with notable focus on the U.S., U.K., and Asia-Pacific regions. The operation leverages commercial proxy services designed to bypass China's Great Firewall, enabling multiple threat actors to maintain anonymity and coordinate operations via shared infrastructure. This represents an advanced evolution in state-enabled cyber espionage capabilities.

Join the discussion

Socket identified a coordinated campaign involving 77 Firefox extensions designed to steal cryptocurrency wallet secrets and credentials. The operation, tracked as 'Offside Wallet Theft Factory', includes 40 confirmed malicious extensions that exfiltrate recovery phrases, private keys, and credentials through Supabase-controlled remote switches, Cloudflare Workers, and hardcoded command-and-control infrastructure. An additional 37 deceptive sports-score shells share publishing artifacts and version histories showing transitions from benign utilities into wallet-stealing malware. The campaign operated from at least March 2026 through August 2026, targeting Web3 users through impersonations of OKX, Rabby Wallet, TronLink, and other cryptocurrency products. Extensions capture secrets through phishing interfaces, modified wallet code, and direct credential theft, enabling immediate cryptocurrency theft and financial harm.

Join the discussion
0

Multiple clusters of North Korean IT workers, designated as PurpleDelta, have been identified applying to over 1,100 companies between late 2024 and early 2025, primarily targeting software, technology, staffing, consulting, and healthcare sectors. The operators maintained at least 22 fabricated personas supported by AI-generated profile photos, custom ChatGPT assistants, and fraudulent identity documents. They demonstrated sophisticated tradecraft, applying to up to 60 positions daily using multi-account management browsers and detailed tracking spreadsheets. During interviews, operators employed screen recording software and AI transcription tools to generate real-time answers, often repeating ChatGPT responses verbatim. Once employed at ten or more organizations, they recorded internal meetings, used personal devices and bank accounts, and coordinated via Telegram and Slack with facilitators who maintained company-issued hardware. This activity represents an ongoing insider threat to organizations hirin...

Join the discussion

Showing 1 to 10 of 77 results

Filters:Tag: t1567
Page 1 of 8
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses