Threats Tagged 't1590'
View all threats tagged with 't1590'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 't1590'
Click on any threat for detailed analysis and mitigation recommendations
Beginning in 2024, a financially motivated threat actor designated BREEZE COMET has conducted sophisticated operations targeting Brazilian financial services, retail, and eCommerce organizations. The group specializes in manipulating payment systems including Pix, STR, and Boleto to conduct fraudulent transfers worth tens of thousands of USD. Their evolved tactics leverage customized malware suites written in multiple languages including Rust, Nim, Golang, and Java, alongside compromised government websites for initial access and command and control. The threat actor demonstrates advanced capabilities by targeting banking software, payment APIs, and mTLS credentials while maintaining persistent access through multiple backdoors. Evidence indicates BREEZE COMET uses generative AI to accelerate malware development and script creation, suggesting potential expansion to other Latin American and African countries based on infrastructure replication observed in Nigeria, Paraguay, Ghana, and Venezuela. Join the discussion | AlienVault OTX General | 09/01/2026, 07:05:40 UTC Added: 09/01/2026, 08:37:15 UTC |
RecruitTrap is a sophisticated phishing campaign targeting enterprise credentials by impersonating HR personnel from well-known companies. It uses Browser-in-the-Browser techniques on desktop and full-screen fake login pages on mobile without visible URL indicators. The campaign actively screens victims to focus on corporate accounts, rejecting personal emails. Attackers impersonate multiple global brands and use persistent hosting on Amazon and SEDO networks. Detection of malicious domains is significantly delayed by traditional threat feeds. The campaign facilitates credential harvesting, OAuth token theft, and lateral movement within organizations. Join the discussion | AlienVault OTX General | 08/25/2026, 02:55:59 UTC Added: 08/25/2026, 10:52:01 UTC |
In June 2026, infrastructure pivoting from TencShell C2 nodes revealed an active intrusion campaign utilizing AI language models for attack automation. Thirteen Hong Kong-based servers across four ASNs exposed an open directory containing victim source code, custom exploits, operational logs, and cloned login pages with notes in Simplified Chinese. The operation employed Claude Code for execution and DeepSeek-v4-pro for attack logic, targeting government systems in Afghanistan, Thailand, and Taiwan, along with reconnaissance against U.S. government portals. The campaign also pursued financial services firms across Europe, Australia, and Asia. Attackers deployed TencShell implants, webshells, and custom exploits including SQL injection and Laravel deserialization attacks, successfully compromising administrative systems and exfiltrating sensitive data including citizen complaints and government employee information. Join the discussion | AlienVault OTX General | 07/14/2026, 21:17:46 UTC Added: 07/15/2026, 14:19:07 UTC |
Tomorrowland Belgium 2026, spanning two weekends in July at De Schorre in Boom, sold out rapidly, creating opportunities for cybercriminals. Investigation uncovered approximately a dozen fraudulent websites impersonating the festival brand to target ticket seekers and travellers. These scams include fake ticket shops mimicking official sales with countdown timers and fraudulent biometric checks, travel sites offering bogus accommodation and transport packages, and affiliate schemes. The operations harvest complete identity data, payment credentials, and personal information through sophisticated social engineering. Victims lose money with no recourse, face identity theft risks, and ultimately receive invalid or non-existent tickets. The scammers exploit high demand, tight supply, and rushed purchasing decisions, with sites registered weeks in advance and pushed hardest when official tickets are sold out. Join the discussion | AlienVault OTX General | 07/14/2026, 07:19:34 UTC Added: 07/14/2026, 09:47:42 UTC |
Children are targeted by a sprawling ecosystem of websites exploiting their interest in Roblox and Minecraft through offerwall reward schemes and phishing campaigns. These sites promise free in-game currency in exchange for completing tasks, collecting personal data, enrolling minors in paid subscriptions, and violating platform terms of service that can result in account bans. The infrastructure relies on cheap, disposable hosting with aggressive domain rotation. Using Internet-wide scan data from Censys, this analysis characterizes two categories: offerwall get-paid-to reward sites and credential harvesting generators. The exposed infrastructure handles children's data with minimal security, monetizing their attention at scale through affiliate commissions while presenting significant privacy and security risks. Join the discussion | AlienVault OTX General | 07/03/2026, 10:55:03 UTC Added: 07/03/2026, 11:06:38 UTC |
Between June 16 and 19, 2026, a sophisticated adversary-in-the-middle phishing campaign targeted AWS console users through three domains registered within 48 hours and hosted on Cloudflare. The campaign impersonated AWS login pages and captured credentials along with real-time multi-factor authentication codes through email, SMS, and authenticator apps. Phishing emails were delivered through legitimate platforms like SendGrid and Nimbu to bypass spam filters. The kit employed JavaScript-based credential harvesting with victim validation through encrypted URL parameters, preventing sandbox analysis. Targets were primarily US-based software engineers and engineering leadership, suggesting a curated target list rather than mass phishing. The same kit was linked to concurrent SendGrid impersonation campaigns and previous cryptocurrency wallet targeting since July 2025. The small sample of fewer than 50 targeted email addresses indicates highly selective targeting of technical personnel with AWS access. Join the discussion | AlienVault OTX General | 06/25/2026, 15:26:35 UTC Added: 06/25/2026, 15:46:12 UTC |
An FBI investigation identified Denis Nikolayevich Obrezko, a Russian national, as facilitating cyber intrusions conducted by the Russia-aligned threat group Void Blizzard. Between June and July 2024, multiple U.S. companies across various sectors were targeted in a large-scale cyber espionage campaign involving mass email harvesting and unauthorized access. The threat actors utilized stolen session tokens, proxy services, and VPNs to authenticate to victim Office 365 environments and exfiltrate data. Obrezko allegedly obtained critical infrastructure including a virtual private server and domain registration used in these attacks. FBI investigation linked Obrezko through cryptocurrency transactions, email accounts, phone numbers, and IP addresses to domains and infrastructure used in the intrusion campaign. Eleven U.S. companies have confirmed unauthorized access, representing only a fraction of suspected victims nationwide. Join the discussion | AlienVault OTX General | 06/11/2026, 21:09:37 UTC Added: 06/15/2026, 19:30:18 UTC |
Lookalike attacks exploit human cognitive shortcuts rather than technical vulnerabilities, designing domain names that resemble legitimate services to bypass security controls. These attacks leverage predictable patterns in how people read and process text, using techniques including homographs, typosquatting, domain embedding, and keyword association. The domain name itself embeds targeting intent, making attacks visible in DNS infrastructure before malicious activity occurs. Attackers face deliberate tradeoffs between plausibility and uniqueness, often maintaining domains in dormant states between campaigns to evade takedown. DNS provides early structural signals about attacker intent and brand targeting, though ambiguity remains inherent as legitimate services often exhibit similar patterns. Effective detection requires separating targets from imposters and understanding that domain-based analysis surfaces risk rather than definitive verdicts. Join the discussion | AlienVault OTX General | 06/11/2026, 16:31:57 UTC Added: 06/15/2026, 19:30:18 UTC |
A sophisticated Chinese-origin fraud operation is targeting FIFA World Cup 2026 attendees through pixel-perfect website clones and a multi-tenant phishing infrastructure. The actors deploy typosquatted domains and a commercially developed administrative system to mimic legitimate FIFA ticketing platforms. Technical analysis reveals high-fidelity brand cloning, real-time card skimming capabilities, and a distributed reseller ecosystem supporting at least 15 active operator instances. The platform functions as an active Man-in-the-Middle framework intercepting payment card details and bypassing SMS-based two-factor authentication in real time. Traffic is primarily driven through Facebook and Instagram in-app browsers. Simplified Chinese localizations and operator geolocations from IP addresses in China indicate PRC-based actors. The core payment routing hub tbpay[.]uk lacks financial regulatory authorization and has historical malicious patterns. Join the discussion | AlienVault OTX General | 06/11/2026, 16:31:35 UTC Added: 06/15/2026, 19:30:18 UTC |
Iran's Ministry of Intelligence has broadened its Handala brand beyond cyber operations to include physical threats and influence campaigns targeting US and Israeli interests. The expansion encompasses multiple personas: Handala Popular Resistance Front claiming physical attacks inside Israel, VIPEmployment recruiting proxies globally for espionage and sabotage, and MOISIRAN conducting surveillance operations. These entities engage in coordinated amplification across platforms, soliciting individuals to conduct attacks for financial rewards. The consolidation creates a multi-domain threat combining hacktivist activities with physical operations, espionage recruitment, and influence campaigns. This approach leverages Handala Hack Team's recognition to amplify recruitment efforts while increasing risks to law enforcement, military, intelligence personnel, and critical infrastructure across targeted regions. Join the discussion | AlienVault OTX General | 06/02/2026, 14:38:53 UTC Added: 06/03/2026, 09:33:37 UTC |
Showing 1 to 10 of 37 results