Skip to main content

Threats Tagged 't1571'

View all threats tagged with 't1571'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: t1571

Threats Tagged 't1571'

Click on any threat for detailed analysis and mitigation recommendations

RemControl is an Android banking trojan first observed in July 2026 that targets financial institutions across Western Europe, the Middle East, and Canada. The malware is distributed through fake Google Play Store pages advertising TVTap, an IPTV application, using malvertising campaigns with geo-targeted delivery. Once installed, the dropper creates a local VPN to block Play Protect checks and generates unique signing certificates per installation. RemControl exploits Android Accessibility Service permissions to display phishing overlays for over 30 banking applications, capturing PINs, mobile banking codes, and card details. The malware includes remote control capabilities, screen streaming, keylogging, and lock-screen pattern capture. It operates as Malware-as-a-Service with infrastructure showing evidence of AI-assisted development in phishing page creation and documentation.

Join the discussion
0

A deep technical analysis reveals updates to Hangro, North Korea's state VPN and mail product, operating on servers in Pyongyang and the Russian Far East. A new certificate hierarchy deployed in July 2026 differs significantly from the 2024 version, with both containing cryptographic anomalies where signatures fail verification. Investigation uncovered six network assignments in Chinese address space linked to a single registry contact associated with Silibank, plus infrastructure in Russian Far East networks designated KPOST. The service evolved from a commercial email gateway in 2001 to a certificate-bound VPN deployment issued to trade representatives through consulates. Technical evidence indicates structured infrastructure spanning North Korean, Russian, and Chinese address space, with mail systems configured for bulk transfers over intermittent connections using ten gigabyte message limits and ETRN capabilities.

Join the discussion

Infrastructure analysis reveals a cluster of SpiceRAT command and control servers active from late 2025 through August 2026, linked through shared TLS certificates, domain registrations, and a cloned RTX Corporation webpage. The infrastructure connects to multiple threat families including SpiceRAT, NodeEdgeRAT, NomadRAT, and BloodAlchemy, suggesting either a single operator managing multiple toolsets or shared support infrastructure. A TLS certificate impersonating Uzbekistan's railway authority was issued by TLC, a Chinese state-affiliated certificate authority. Domains spoof Central Asian government entities including Türkmengaz, the Galkynysh gas field, Tojiktelecom, and Turkmenistan's Ministry of Foreign Affairs. Passive DNS analysis reveals subdomain infrastructure dating to mid-2022, indicating at least four years of ongoing operations. The infrastructure shares characteristics with previously documented China-nexus actors FamousSparrow and IndigoZebra, both known for targeting Central Asian governm...

Join the discussion

VectraRAT is a previously undocumented Malware-as-a-Service platform combining a Go-based control server (VectraHub) with a native C++ Windows implant, renting from $250 monthly. The developer, operating under the handle 'Vectra' (formerly 'Nyxel'), has been active since August 2022 without prior public documentation. The platform offers hidden desktop control, keylogging, clipboard hijacking with cryptocurrency address replacement, browser credential theft, and a UAC bypass achieving elevation without user prompts. Delivered through Amadey loader and ClickFix campaigns targeting tax-themed lures, 48% of observed victims run corporate Windows editions including Windows Server 2025. Infrastructure analysis revealed exposed directories and operational panels across multiple hosting providers, with victims spanning the United States, Russia, Germany, and other nations.

Join the discussion

Mythic is an open-source command-and-control (C2) framework used by red teams and threat actors. Analysis found 131 unique Mythic C2 hosts exposed on the public Internet, with most using default TLS certificates. These deployments span major cloud providers and are concentrated in the US, Hong Kong, and China. Default artifacts such as TLS certificates with O=Mythic and port 7443 responses enable detection. Some clusters appear to be training environments, while isolated deployments with custom domains and advanced transport methods like Discord and steganography indicate operational use.

Join the discussion

An exposed directory at 188.245.99.156 revealed a comprehensive cryptomining toolkit containing 147 files including Python exploit source code, campaign logs, and Windows registry hives. Analysis confirms 3,562 Redis servers were compromised across two campaign runs targeting 12,966 hosts. The operation exploited unauthenticated Redis instances using rogue replication techniques to inject cron jobs that deployed XMRig miners. Victims spanned Redis versions 2.8.17 through 7.2.0 across outdated and current Linux distributions, indicating misconfiguration rather than version-specific vulnerabilities. The toolkit also targeted WordPress, MongoDB, and SSH but achieved zero confirmed compromises through those vectors. A separate February 2026 open directory linked by wallet reuse revealed Meterpreter deployment capabilities, extending the operator's known activity timeline by five months. The operation mined Monero through pool.moneroocean.stream with the same wallet used on the operator's own Windows-based work...

Join the discussion

An unpatched zero-day vulnerability dubbed StyleSmuggler affects all current versions of Magento and Adobe Commerce, including 2.4.9, enabling unauthenticated remote code execution. Active exploitation began on September 4th, 2026. The attack operates in two stages: injecting malicious PHP code into Magento's template system using styles properties to evade safeguards, then executing the poisoned code via failed payment emails. Upon successful compromise, attackers deploy a Rust-based backdoor disguised as legitimate system processes (kworker, fc-cache, or chronyd) that connects to command and control servers. The backdoor uses NTP-shaped UDP traffic for C2 communication to evade detection. A second unrelated attacker has also been observed exploiting the same vulnerability to deploy PHP web shells. Affected merchants should deploy immediate mitigation measures, scan for compromise, and temporarily disable GraphQL until an official patch is released.

Join the discussion

In March 2026, a sophisticated SEO poisoning campaign was identified leading to malware distribution and tech support scams. Operating since at least 2015, this operation is attributed to individuals and IT service providers in Rajasthan, India, collectively tracked as BengalSEO. Two primary entities were identified: WeConnect Solutions LLC operates tech support call centers, while Garage2Global develops malicious web infrastructure. The group leverages extensive black hat SEO techniques including backlink generation, DOM injection, and keyword stuffing to promote lure pages mimicking legitimate technical support portals. A custom Traffic Distribution System routes victims through rotating redirector domains, utilizing Matomo analytics for tracking and fingerprinting. The operation deploys custom malware named MayaBot to further enable scam activities. Infrastructure analysis revealed hundreds of domains registered primarily through Spaceship and Namecheap, hosted via Cloudflare and Hostmaza, with GitHub e...

Join the discussion

Attack campaigns targeting Korean users have been observed deploying remote control tools including Radmin and UltraVNC to compromise systems. The initial intrusion vector remains unidentified, but attackers download compressed files containing batch scripts and remote administration software. Following Radmin installation, threat actors leverage access to deploy UltraVNC alongside proxy tools such as Netch-gateway and CCProxy, ultimately utilizing compromised systems as proxy nodes. Recent variants include SoftEther VPN deployment to establish VPN servers on infected infrastructure. PowerShell scripts containing Chinese language comments, combined with tools familiar to Chinese-speaking actors, suggest attribution to Chinese threat operators. The campaigns enable both remote system control and abuse of compromised infrastructure for proxy services.

Join the discussion

Jamf Threat Labs discovered a cluster of 14 trojanized macOS applications distributed as DMG and PKG files impersonating legitimate software like The Unarchiver, Sketch, and Bartender. These samples are linked to the Contagious Interview campaign, a DPRK-attributed operation using fake job interviews as a pretext. The malware chain begins with unsigned, modified applications containing hidden executables that download staging scripts from infrastructure at 162.0.239[.]85. The attack progresses through multiple stages, ultimately deploying OtterCookie malware, which provides remote access capabilities, credential stealing from browsers and crypto wallets, filesystem scanning, and clipboard monitoring. The delivery method represents an evolution from previous Git hook and VS Code task-based attacks to standalone installer packages requiring manual quarantine attribute removal to execute.

Join the discussion

Showing 1 to 10 of 153 results

Filters:Tag: t1571
Page 1 of 16
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses