Skip to main content

Threats Tagged 't1573'

View all threats tagged with 't1573'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: t1573

Threats Tagged 't1573'

Click on any threat for detailed analysis and mitigation recommendations

A sophisticated six-month campaign targeting quantitative and DeFi developers through malicious npm packages disguised as legitimate mathematics libraries. The operation employs encrypted loaders that trigger only when specific cryptographic operations are performed, specifically when solving linear equations with predetermined matrices. Command and control infrastructure uses Ethereum Sepolia testnet smart contracts as dead drops, alongside a secondary Slack channel, enabling encrypted tasking of compromised systems. The threat actors manufactured millions of fake downloads using GitHub Actions workers to establish false credibility. Fourteen smart contracts were deployed across five operator wallets, managing over 1,000 encrypted taskings to enrolled victims. The campaign demonstrates advanced operational security with disposable accounts, encrypted payloads sealed under ephemeral keys, and infection markers hidden in license files.

Join the discussion

Vidar is an information stealer first observed in 2018 that has continuously evolved its string obfuscation techniques to evade detection and analysis. Between May and September 2026, the malware progressed from basic XOR encryption to ChaCha20-based algorithms, and most recently implemented a custom virtual machine executed via a lightweight bytecode interpreter combined with custom stream ciphers that change per build. The VM uses 14 opcode handlers with simple primitives including XOR, addition, rotation, and substitution. Version 2.0 introduced this VM approach, while versions 2.2 and later added ARX-based custom stream ciphers using FNV-1a hashing and golden ratio constants. These per-build variations in opcodes, constants, and substitution tables significantly hinder static and automated analysis capabilities.

Join the discussion
0

A deep technical analysis reveals updates to Hangro, North Korea's state VPN and mail product, operating on servers in Pyongyang and the Russian Far East. A new certificate hierarchy deployed in July 2026 differs significantly from the 2024 version, with both containing cryptographic anomalies where signatures fail verification. Investigation uncovered six network assignments in Chinese address space linked to a single registry contact associated with Silibank, plus infrastructure in Russian Far East networks designated KPOST. The service evolved from a commercial email gateway in 2001 to a certificate-bound VPN deployment issued to trade representatives through consulates. Technical evidence indicates structured infrastructure spanning North Korean, Russian, and Chinese address space, with mail systems configured for bulk transfers over intermittent connections using ten gigabyte message limits and ETRN capabilities.

Join the discussion

Blackpoint's Adversary Pursuit Group identified ChainScript, a previously unnamed Node.js remote access trojan discovered during ClickFix investigation. The malware disguises itself as legitimate software including Spotify, Zoom Workplace, and Microsoft Teams through malicious Windows Installer packages. ChainScript employs an EtherHiding-style C2 discovery technique utilizing a Polygon smart contract to dynamically locate active WebSocket infrastructure, enabling operators to rotate backend services without rebuilding agents. The RAT provides comprehensive remote access capabilities including interactive shell sessions, file operations, screenshots, payload deployment, cryptocurrency wallet discovery, remote JavaScript execution, self-update mechanisms, and cleanup functions. Multiple builds appeared under different names (ComponentTask33, UpdateDigital, HostShared, OrchidViolet66) while maintaining consistent core agent architecture. Analysis revealed automated contract deployment integrated into the mal...

Join the discussion

A new JavaScript infostealer dubbed WeaselBiscuit has been discovered hidden in 11 malicious npm packages. This lean malware shares operational similarities with DPRK-linked BeaverTail and OtterCookie families but features a stripped-down architecture. WeaselBiscuit deploys through npm imports, executes a detached Node process, retrieves its payload from Npoint URLs, and communicates with a C2 server at 103.170.217.184:8787. The malware profiles infected hosts, steals Chrome extension storage containing wallet signing states, captures clipboard contents, and logs Windows keystrokes when commanded. Unlike its predecessors, it lacks wallet-draining code, browser password decryption, Python second stages, screenshots, and remote shell capabilities. The operation uses numeric campaign identifiers embedded in package names for tracking. While technical overlap suggests DPRK attribution, particularly through Npoint dead-drop patterns and nested IP geolocation lookups, definitive attribution requires additional c...

Join the discussion

Fraudulent organizations in Korea are exploiting private Home Trading System (HTS) software to distribute ransomware to victims. The unauthorized HTS program called 'UBP Asset' impersonates the legitimate Swiss financial institution Union Bancaire Privee (UBP) and has been used in investment scams since at least September 2025. Attackers lure victims through social media platforms like Telegram and KakaoTalk, convincing them to install the fraudulent HTS and deposit funds. The latest campaign involves distributing KRSID ransomware through the HTS update mechanism, which encrypts files using AES-256 and RSA-2048 algorithms. Previous campaigns used similar private HTS programs to distribute Quasar RAT. Victims not only lose their investment funds but also have their systems compromised and files encrypted for ransom demands.

Join the discussion
0

A previously unknown modular multi-stage framework named MovieReaper has been discovered targeting users through compromised torrent files. Attackers compromised the public torrent repository itorrents[.]org, enabling them to distribute malicious loaders disguised as popular movies, including "The Odyssey." The campaign began in mid-August 2026 and affected hundreds of victims across multiple countries. The malware employs a sophisticated infection chain with fileless execution, utilizing blockchain network Solana for C2 infrastructure resilience. The framework includes multiple stages: an initial loader with anti-sandbox checks, shellcode that retrieves C2 addresses from Solana blockchain, UAC bypass with persistence mechanisms, and a final file manager module providing comprehensive file system access. The campaign demonstrates advanced evasion techniques including manual API resolution, vectored exception handling, and in-memory execution.

Join the discussion

An analysis of Atomic macOS (AMOS) stealer infections from early August 2026 reveals this information stealer targeting macOS systems has been advertised since April 2024. AMOS exfiltrates system information, login credentials, and sensitive data from web browsers and cryptocurrency wallets. Distribution methods include ClickFix campaigns, malicious advertisements, and fake cracked software sites offering macOS toolkits. The examined infection chain begins with malicious instructions on getmacouscloud[.]com, leading to execution of a Zsh script that retrieves and installs Mach-O binaries establishing persistence in system directories. The malware collects data from various applications including Binance, TonKeeper, Telegram, AWS, Docker, and FileZilla, compressing it into an out.zip file before exfiltrating to command and control servers. Post-infection traffic consists of HTTP POST requests with specific stage parameters indicating collected data types. The malware demonstrates active development with con...

Join the discussion

Illegal online gambling infrastructure spans three distinct cybercrime categories that defenders often overlook. First, over 1.7 million Chinese-language casino domains facilitate illegal gambling and transnational money laundering, primarily operated by triad-aligned syndicates. Second, thousands of "scambling" websites target global audiences with rigged games and withdrawal fraud, using deposit bonuses to lure victims. Third, China-aligned APT groups deploy the PeckBirdy malware framework within fake casino and adult websites as command-and-control infrastructure, targeting education, government, finance and technology sectors across Asia. These operations exploit U.S. and European hosting providers through infrastructure laundering while maintaining bulletproof Asian hosting. The campaigns have escalated sharply since 2023, with PeckBirdy domains achieving zero detection rates on VirusTotal. All three types appear visually identical, creating detection challenges for security teams.

Join the discussion

In July 2026, IIJ discovered and analyzed an unknown .NET-based malicious tool hosted on a public directory. This tool, named PIVOTPIPE, exhibits functionality similar to Cobalt Strike Beacon, communicating with C2 servers using configurations close to default profiles and supporting numerous C2 commands. However, PIVOTPIPE differs from official Cobalt Strike Beacon through unique implementations including detection evasion code, custom loaders, and obfuscated strings. The tool consists of two components: a loader and RAT module. The loader implements AMSI bypass, indirect syscalls, and sleep masking for EDR evasion. PIVOTPIPE supports TCP Beacon and SMB Beacon functionality for peer-to-peer communication through compromised hosts. Debug artifacts suggest the tool was still under development at the time of discovery, indicating potential future enhancements.

Join the discussion

Showing 1 to 10 of 248 results

Filters:Tag: t1573
Page 1 of 25
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses