Skip to main content

Threats Tagged 't1583'

View all threats tagged with 't1583'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: t1583

Threats Tagged 't1583'

Click on any threat for detailed analysis and mitigation recommendations

Threat actors are leveraging generative AI to enhance financial fraud campaigns targeting enterprise organizations. Between August 3-5, over one million phishing emails were distributed through third-party infrastructure, primarily targeting US-based organizations (87.7%). The attacks employed sophisticated executive impersonation, specifically CEOs and CFOs, combined with fabricated ServiceNow invoices requesting ACH transfers of approximately $50,000. The campaign demonstrated multiple AI-assisted indicators including extensive HTML comments, structured section labeling, and uniform template construction. Attackers registered lookalike domains and created elaborate forwarded email threads between spoofed executives to establish legitimacy. The fraudulent invoices contained detailed branding, personalized recipient information, and specific payment instructions to attacker-controlled bank accounts. Multiple layered social engineering techniques were deployed to reduce recipient skepticism and convince acc...

Join the discussion

A Magecart campaign uses EtherHiding techniques to perform card-skimming on e-commerce platforms. Attackers compromise legitimate online storefronts, mainly WooCommerce, but also PrestaShop, Magento, and WordPress sites, injecting malicious loaders disguised as Google Tag Manager code. The skimming payloads are staged inside Ethereum blockchain smart-contract storage, making detection more difficult. Over 40 websites across 15 countries have been impacted since April 2026. The infrastructure involves 144 Sepolia contracts controlled by a single wallet, with 20 distinct contracts and skimmer-hosting domains identified. The malicious code appears as normal analytics but steals credit card data from shoppers.

Join the discussion

This analysis examines infrastructure used by multiple Russian cyber espionage clusters targeting individuals in academia, think tanks, and organizations across Europe and the United States. The investigation expands on three threat clusters (UNC6293, UNC7005, and UNC5976) that employed OAuth phishing, Microsoft device code phishing, and WhatsApp targeting. UNC6293 utilized lure domains impersonating the Council on Foreign Relations and government portals, with possible Evilginx configurations. UNC7005 demonstrated lower sophistication with poor operational security, using domains like my-invite[.]org for phishing campaigns. UNC5976 employed Google Drive impersonation domains for OAuth phishing. The analysis leverages historical DNS data, CSS hash similarities, favicon analysis, registration patterns, and certificate information to identify additional infrastructure and tracking methods for discovering related malicious domains and IP addresses.

Join the discussion

RecruitTrap is a sophisticated phishing campaign targeting enterprise credentials by impersonating HR personnel from well-known companies. It uses Browser-in-the-Browser techniques on desktop and full-screen fake login pages on mobile without visible URL indicators. The campaign actively screens victims to focus on corporate accounts, rejecting personal emails. Attackers impersonate multiple global brands and use persistent hosting on Amazon and SEDO networks. Detection of malicious domains is significantly delayed by traditional threat feeds. The campaign facilitates credential harvesting, OAuth token theft, and lateral movement within organizations.

Join the discussion

Educational institutions continue to be the most targeted sector globally, experiencing an average of 4,696 weekly cyberattacks per organization between January and July 2026, representing an 8% increase year-over-year and more than double the cross-industry average. The back-to-school period sees intensified malicious activity, with July 2026 recording 4,848 weekly attacks. Threat actors are registering thousands of education-themed domains, with one in every 226 newly registered domains being malicious. APAC leads with 7,452 weekly attacks, while Europe and Latin America show the fastest growth at 18% and 42% respectively. Attackers deploy phishing campaigns impersonating retailers, schools, and Microsoft 365 to steal credentials and financial information from students, educators, and families during peak enrollment periods.

Join the discussion

A sophisticated traffic distribution system has been operating for over 14 months, using more than 12,700 structurally similar fake CAPTCHA PDFs hosted on Webflow's CDN. The operation begins with search engine optimization, where victims searching for legitimate content encounter malicious PDFs through Google searches. These documents contain fake CAPTCHA panels that route users through a custom Elixir/Phoenix traffic distribution system employing IP filtering, bot detection, and geographic targeting. The infrastructure sorts visitors and redirects qualifying traffic to three distinct endpoints: Legion Loader distribution, a TDS reseller gate, and premium-SMS subscription scams targeting Spanish-speaking users. Non-qualifying traffic is monetized through search-arbitrage advertising. The operation primarily targets English-speaking countries and has recently been surfaced by AI assistants including Google Gemini and Claude, expanding its reach beyond traditional search engines.

Join the discussion

A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to log in to an affected device using a low-privileged account to access sensitive data within the impacted systems. This vulnerability is due to the presence of static user credentials for a low-privileged account. An attacker could exploit this vulnerability by using the account to log in to an affected system. A successful exploit could allow the attacker to log in to the affected system and access sensitive data as the low-privileged user.  Note: If the FMC management interface does not have public internet access, the attack surface that is associated with this vulnerability is reduced.   Cisco has assigned this security advisory a Security Impact Rating (SIR) of High rather than Medium as the score indicates. The reason is that this vulnerability can be used with other Cisco Secure FMC Software vulnerabilities to elevate privileges.

Join the discussion

Kratos is a mature Phishing-as-a-Service operation targeting Microsoft 365 users across the United States, Europe, and other regions. The platform enables attackers to steal credentials through trusted platforms, anti-bot verification, and convincing login pages. Researchers traced three generations of the kit and uncovered 1,484 previously unattributed detonations. The operation targets organizations across more than 20 countries with particularly strong concentration in the US, Spain, and Southern Europe. Kratos includes an operator panel allowing deployment of phishing domains, configurable Telegram or email delivery, geographic restrictions, and multiple anti-bot systems. The kit has evolved through three page generations (V0, V1, V2) with different exfiltration code. Activity has been visible since January 2026, with the operator panel active since September 2025.

Join the discussion

Children are targeted by a sprawling ecosystem of websites exploiting their interest in Roblox and Minecraft through offerwall reward schemes and phishing campaigns. These sites promise free in-game currency in exchange for completing tasks, collecting personal data, enrolling minors in paid subscriptions, and violating platform terms of service that can result in account bans. The infrastructure relies on cheap, disposable hosting with aggressive domain rotation. Using Internet-wide scan data from Censys, this analysis characterizes two categories: offerwall get-paid-to reward sites and credential harvesting generators. The exposed infrastructure handles children's data with minimal security, monetizing their attention at scale through affiliate commissions while presenting significant privacy and security risks.

Join the discussion

Scam advertising campaigns have been identified that impersonate trusted brands to redirect consumers to unrelated online gambling sites. These operations utilize paid social media advertisements on platforms like Facebook, Instagram, and TikTok, combined with fake app store pages and Progressive Web Apps. The campaigns target UK consumers primarily, with variants observed in German and Spanish. Scammers impersonate major brands including financial institutions like Monzo, Revolut, and Barclays, as well as household names such as Tesco, Amazon, Netflix, and Facebook. The scheme involves three stages: paid ads claiming brands have launched official casino products, fake landing pages mimicking app stores, and PWAs that redirect to gambling sites through affiliate tracking links. Typical affiliate payouts range from $50 to $350 per depositing player, indicating significant financial motivation behind these operations.

Join the discussion

Showing 1 to 10 of 69 results

Filters:Tag: t1583
Page 1 of 7
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses