Threats Tagged 't1571'
View all threats tagged with 't1571'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 't1571'
Click on any threat for detailed analysis and mitigation recommendations
Fake Zoom Installer Delivers Overlord RAT on macOS 0 A sophisticated macOS campaign has been discovered using a fake Zoom installer to deploy Overlord RAT, an open-source remote access framework. The attack employs a .NET-based downloader disguised as ZoomMeetings, representing an uncommon approach for macOS threats. The multi-stage attack fingerprints the victim's system to deliver platform-specific payloads for macOS ARM64, macOS Intel, or Windows from attacker-controlled infrastructure. The second stage deploys Overlord RAT with extensive capabilities including keylogging, screen capture, audio and webcam access, filesystem manipulation, and remote desktop streaming. The malware communicates with command-and-control servers over encrypted WebSockets and maintains persistence through LaunchAgents. The campaign shares characteristics with previous North Korean operations, including similarities to FlexibleFerret malware and the Contagious Interview campaign. Join the discussion | AlienVault OTX General | 08/07/2026, 07:15:31 UTC Added: 08/07/2026, 10:11:41 UTC |
Fake Xeno Roblox Cheats Deliver Powerful Java Stealer Through Discord and Forums 0 A sophisticated malware campaign targets Roblox players by distributing fake versions of the Xeno script executor through gaming forums and Discord communities. The attack deploys a multi-stage Java infection chain that mimics legitimate Windows and gaming components, including files disguised in Xbox Game Bar directories. The final payload functions as both an information stealer and remote access trojan, capable of stealing browser cookies, Discord, Roblox, and Minecraft accounts, cryptocurrency wallets, and payment data. Beyond typical credential theft, it records keystrokes, accesses webcams, streams desktops, manipulates files, executes PowerShell commands, and provides attackers with interactive system control. Previously documented as Powercat, the malware continues active development with new command-and-control infrastructure. Activity increased significantly in March 2026, particularly threatening children and teenagers who may expose personal accounts, webcam images, and financial information fr... Join the discussion | AlienVault OTX General | 08/04/2026, 18:21:00 UTC Added: 08/05/2026, 09:11:32 UTC |
QuickFox Supply Chain Attack Used to Deploy FDMTP Implant 0 A long-running campaign compromised the QuickFox VPN application, primarily used by Chinese users to access Chinese resources and improve gaming experiences. Active since August 2025, the attack involved trojanized Windows installers (versions 3.0.51.0 through 3.59.5) that deployed malicious JavaScript through modified Electron renderer HTML files. The JavaScript loader fingerprinted victim endpoints using process-based guardrails, checking for specific applications including administrative tools, cryptocurrency wallets, and Chinese translation software while avoiding Steam users. Successfully profiled targets received an FDMTP implant through DLL sideloading techniques using legitimate Microsoft Azure binaries. The infrastructure demonstrates active development with multiple staging domains masquerading as legitimate services. QuickFox removed malicious components from version 3.59.6 following responsible disclosure. Technical overlaps suggest possible connections to Twill Typhoon, though attribution remain Join the discussion | AlienVault OTX General | 08/05/2026, 08:30:10 UTC Added: 08/05/2026, 08:56:25 UTC |
Almost Half of Malware Samples Communicate Direct to IP 0 Analysis of 4 million dynamic malware reports reveals that 45.32% of malware samples with command-and-control activity establish direct-to-IP (D2IP) connections, bypassing DNS entirely and evading DNS-based security defenses. D2IP traffic accounts for 23.17% of all C2 connection attempts. This behavior is observed across diverse threats including Phorpiex ransomware droppers using hard-coded IP addresses, persistent data exfiltration campaigns employing obfuscated HTTP GET requests, SectopRAT targeting educational institutions with in-browser proxy capabilities, and IoT botnets like Mozi and Boatnet propagating through P2P networks. The research introduces zero trust IP (ZT-IP), a network-level enforcement approach that verifies whether outbound connection destinations were previously sanctioned by DNS responses, effectively blocking malicious D2IP communications that traditional DNS-based security controls cannot detect. Join the discussion | AlienVault OTX General | 08/04/2026, 13:08:10 UTC Added: 08/04/2026, 14:41:34 UTC |
XMRig Covert Ops: The Cryptomining Campaign That Abuses Trusted Access and Deploys Forensic Smokescreens 0 In May 2026, a sophisticated Monero cryptomining campaign was identified targeting Linux environments. Attackers gained initial access through trusted third-party relationships, then escalated to root privileges. Rather than operating openly as root, they weaponized Linux Pluggable Authentication Modules (PAM) to impersonate multiple low-privileged users, creating a forensic smokescreen and establishing redundant persistence through cronjobs. The operators suppressed system logging and deployed a customized XMRig 6.25.0 implant that self-unlinks after execution, running entirely in memory. The binary uses XOR encryption for configuration obfuscation and employs process masquerading to blend with legitimate processes. Campaign tracking revealed operations linked to the V25 Generation 26 family, connecting to the domain unable.download for mining pool communication. Join the discussion | AlienVault OTX General | 07/30/2026, 10:18:36 UTC Added: 07/31/2026, 06:22:12 UTC |
Ongoing PLC Exploitation Against Critical U.S. Infrastructure 0 Multiple federal agencies have updated a joint advisory warning of active exploitation targeting programmable logic controllers (PLCs) in U.S. critical infrastructure. Attackers scan for internet-exposed industrial control systems and connect using legitimate engineering software with valid credentials, appearing as authorized technicians. Once inside, they alter controller logic and manipulate operator displays to hide anomalies. The campaign has expanded beyond Rockwell Automation to include Schneider Electric and Siemens equipment. Unlike a similar 2023 campaign that caused minimal disruption, this ongoing activity has resulted in confirmed operational disruption and financial losses. Targeted sectors include government facilities, water systems, and energy infrastructure. The exploitation leverages architectural weaknesses rather than software vulnerabilities, with attackers accessing systems through ports 22, 102, 502, 2222, and 44818. Join the discussion | AlienVault OTX General | 07/24/2026, 12:34:37 UTC Added: 07/24/2026, 14:52:06 UTC |
Miasma Worm Returns to npm 0 Four AsyncAPI npm packages were compromised in July 2026, delivering Miasma v3, a new variant of the worm previously found in Red Hat packages. The malicious versions (@asyncapi/generator, @asyncapi/generator-helpers, @asyncapi/generator-components, and @asyncapi/specs) were published through AsyncAPI's legitimate GitHub Actions workflow using npm's OIDC integration, creating packages with valid provenance attestations. Unlike previous variants, this attack triggers when applications load the poisoned library rather than during installation. The payload downloads a second stage from IPFS, establishing a persistent Node.js backdoor with arbitrary shell command execution capabilities. While the codebase contains credential theft, propagation, and AI-tool poisoning modules, this deployment primarily functions as a remote access trojan. The attack began with an unauthorized commit to the repository's release branch, highlighting the importance of branch protection even when using trusted-publisher mechanisms. Join the discussion | AlienVault OTX General | 07/15/2026, 14:20:02 UTC Added: 07/15/2026, 14:48:32 UTC |
Compromised npm Packages in the AsyncAPI Namespace Deliver Miasma Botnet Loader 0 Four npm packages in the AsyncAPI namespace were compromised to distribute a multi-stage botnet loader called Miasma. The attack utilized trusted GitHub Actions publishing but originated from a poisoned source commit. Malicious code was injected into legitimate source files that execute when imported, launching a detached Node.js process to download an 8.25 MB encrypted payload from IPFS. The final payload is a sophisticated tasking framework supporting multiple command-and-control channels including REST, Nostr relays, IPFS, Ethereum smart contracts, and BitTorrent DHT. The framework establishes persistence via systemd services on Linux and fake NodeJS directories, supporting file operations, shell execution, data collection, and cross-ecosystem propagation capabilities for npm, PyPI, RubyGems, and Cargo ecosystems. Join the discussion | AlienVault OTX General | 07/14/2026, 16:36:49 UTC Added: 07/14/2026, 17:47:48 UTC |
Lucide Proxy: Turning Student Web Proxies into DDoS Bots 0 A sophisticated campaign deployed 148 malicious npm packages disguised as student web proxy applications under brands like Riverbend Tutoring and Northstar Tutoring. Published by accounts terminal3airport and eerikakirk, these packages weaponized visitor browsers into distributed denial-of-service botnets while generating advertising revenue. The applications functioned as working proxies but secretly executed mutable remote code and high-performance WebSocket traffic generators compatible with the Wisp protocol. During a critical two-week period in May 2026, active deployments launched HTTP floods generating 2GB/s aggregate traffic and control-plane attacks establishing 10,240 socket connections per second against target servers. The campaign abused npm as a content delivery network, affecting users who visited proxy instances rather than through traditional dependency infection. Join the discussion | AlienVault OTX General | 07/14/2026, 16:14:42 UTC Added: 07/14/2026, 16:47:35 UTC |
Sign here… and install an unwanted RMM 0 A sophisticated phishing campaign impersonates DocuSign's branding to compromise victims through malicious JavaScript embedded in fraudulent webpages. The attack leverages social engineering to trick users into downloading MSI installers disguised as legitimate DocuSign updates or documents. These payloads establish remote access through legitimate Remote Monitoring and Management tools from Atera Network Ltd and ConnectWise/ScreenConnect. Investigation revealed extensive attacker infrastructure spanning hundreds of domains, with tracking mechanisms via Telegram bots collecting detailed victim telemetry including IP addresses, geolocation, ISP information, and user-agent strings. The campaign targets both Windows and macOS systems, utilizing deployment kits across multiple infrastructures with similar URL patterns and JavaScript mechanisms. Join the discussion | AlienVault OTX General | 07/10/2026, 17:25:52 UTC Added: 07/13/2026, 10:32:46 UTC |
Showing 1 to 10 of 10 results