Threats Tagged 't1598'
View all threats tagged with 't1598'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 't1598'
Click on any threat for detailed analysis and mitigation recommendations
Cybercriminals are using fake websites that mimic the legitimate Bitrefill site to defraud users. These lookalike sites appear in search engine results and use domains similar to Bitrefill's, including Punycode variants. Victims are tricked into completing checkout processes that resemble Bitrefill's, paying cryptocurrency to attacker-controlled addresses with no recovery option. The campaign uses sophisticated analytics to optimize victim conversion, indicating organized criminal activity. Join the discussion | AlienVault OTX General | 09/15/2026, 12:44:15 UTC Added: 09/15/2026, 13:47:19 UTC |
0 KATARU is an IoT malware variant discovered in August 2026 through Telnet credential brute-forcing against a honeypot from Vietnam. While maintaining traditional Mirai-style botnet capabilities, it distinguishes itself through an extensive feature set including multiple Linux local privilege escalation exploits, comprehensive persistence mechanisms across Linux and embedded platforms, encrypted C2 communications using X25519 and ChaCha20-Poly1305, anti-analysis techniques, and decoy traffic generation. Implementation artifacts strongly suggest AI-assisted development, evidenced by architecture-mismatched x86 shellcode in ARM binaries, RFC test vectors as configuration values, and untested cross-platform persistence logic. The malware attempts various privilege escalation paths through system misconfigurations and public exploits, establishes persistence across numerous startup mechanisms, and supports multiple DDoS attack vectors alongside SSH brute-forcing capabilities. Join the discussion | AlienVault OTX General | 09/11/2026, 17:55:38 UTC Added: 05/04/2026, 14:36:50 UTC |
Threat actors are leveraging generative AI to enhance financial fraud campaigns targeting enterprise organizations. Between August 3-5, over one million phishing emails were distributed through third-party infrastructure, primarily targeting US-based organizations (87.7%). The attacks employed sophisticated executive impersonation, specifically CEOs and CFOs, combined with fabricated ServiceNow invoices requesting ACH transfers of approximately $50,000. The campaign demonstrated multiple AI-assisted indicators including extensive HTML comments, structured section labeling, and uniform template construction. Attackers registered lookalike domains and created elaborate forwarded email threads between spoofed executives to establish legitimacy. The fraudulent invoices contained detailed branding, personalized recipient information, and specific payment instructions to attacker-controlled bank accounts. Multiple layered social engineering techniques were deployed to reduce recipient skepticism and convince acc... Join the discussion | AlienVault OTX General | 09/10/2026, 22:24:24 UTC Added: 09/11/2026, 14:47:25 UTC |
A China-linked cyber espionage infrastructure provider operates a multi-component 'quartermaster' system that offers reconnaissance, proxy orchestration, and traffic routing services to Chinese state-sponsored actors. The infrastructure includes QScan for reconnaissance, Fast Labyrinth for encrypted relay networks using commercial proxy services, QTRouter for proxy access management, and QTProxy for operational node control. It targets research universities, defense networks, government agencies, and critical infrastructure worldwide, with notable focus on the U.S., U.K., and Asia-Pacific regions. The operation leverages commercial proxy services designed to bypass China's Great Firewall, enabling multiple threat actors to maintain anonymity and coordinate operations via shared infrastructure. This represents an advanced evolution in state-enabled cyber espionage capabilities. Join the discussion | AlienVault OTX General | 08/26/2026, 22:00:43 UTC Added: 08/27/2026, 22:07:26 UTC |
This analysis details infrastructure used by multiple Russian cyber espionage clusters targeting academia, think tanks, and organizations in Europe and the United States. The clusters UNC6293, UNC7005, and UNC5976 employ OAuth phishing, Microsoft device code phishing, and WhatsApp targeting techniques. UNC6293 uses sophisticated lure domains impersonating reputable organizations with possible Evilginx configurations. UNC7005 shows lower operational security with simpler phishing domains. UNC5976 uses Google Drive impersonation for OAuth phishing. The investigation uses DNS data, CSS hashes, favicon analysis, registration patterns, and certificate info to track and identify related malicious infrastructure. Join the discussion | AlienVault OTX General | 08/26/2026, 21:58:59 UTC Added: 08/27/2026, 22:07:26 UTC |
RecruitTrap is a sophisticated phishing campaign targeting enterprise credentials by impersonating HR personnel from well-known companies. It uses Browser-in-the-Browser techniques on desktop and full-screen fake login pages on mobile without visible URL indicators. The campaign actively screens victims to focus on corporate accounts, rejecting personal emails. Attackers impersonate multiple global brands and use persistent hosting on Amazon and SEDO networks. Detection of malicious domains is significantly delayed by traditional threat feeds. The campaign facilitates credential harvesting, OAuth token theft, and lateral movement within organizations. Join the discussion | AlienVault OTX General | 08/25/2026, 02:55:59 UTC Added: 08/25/2026, 10:52:01 UTC |
Educational institutions continue to be the most targeted sector globally, experiencing an average of 4,696 weekly cyberattacks per organization between January and July 2026, representing an 8% increase year-over-year and more than double the cross-industry average. The back-to-school period sees intensified malicious activity, with July 2026 recording 4,848 weekly attacks. Threat actors are registering thousands of education-themed domains, with one in every 226 newly registered domains being malicious. APAC leads with 7,452 weekly attacks, while Europe and Latin America show the fastest growth at 18% and 42% respectively. Attackers deploy phishing campaigns impersonating retailers, schools, and Microsoft 365 to steal credentials and financial information from students, educators, and families during peak enrollment periods. Join the discussion | AlienVault OTX General | 08/20/2026, 11:45:48 UTC Added: 08/20/2026, 23:07:12 UTC |
During Q2 2026, Microsoft detected approximately 7.6 billion email-based phishing threats, with monthly volumes declining from 2.7 billion in April to 2.4 billion in June. The quarter was significantly shaped by the downstream effects of Microsoft's Digital Crimes Unit disruption of the Tycoon2FA phishing-as-a-service platform in March, resulting in a 92% decline in associated phishing volume. QR code phishing attacks peaked at 18.7 monthly attacks in March before declining 48% by June, while CAPTCHA-gated phishing fell 81% from its March high. Credential phishing remained the dominant objective, accounting for 94-96% of all payload-based attacks. Business email compromise activity returned to historical norms after an anomalous April surge. Microsoft Teams-based threats grew substantially, with weekly malicious call attempts reaching nearly ten times the mid-2025 baseline by quarter end. Join the discussion | AlienVault OTX General | 07/23/2026, 16:30:34 UTC Added: 07/23/2026, 23:37:06 UTC |
Kratos is a mature Phishing-as-a-Service operation targeting Microsoft 365 users across the United States, Europe, and other regions. The platform enables attackers to steal credentials through trusted platforms, anti-bot verification, and convincing login pages. Researchers traced three generations of the kit and uncovered 1,484 previously unattributed detonations. The operation targets organizations across more than 20 countries with particularly strong concentration in the US, Spain, and Southern Europe. Kratos includes an operator panel allowing deployment of phishing domains, configurable Telegram or email delivery, geographic restrictions, and multiple anti-bot systems. The kit has evolved through three page generations (V0, V1, V2) with different exfiltration code. Activity has been visible since January 2026, with the operator panel active since September 2025. Join the discussion | AlienVault OTX General | 07/14/2026, 16:36:39 UTC Added: 07/16/2026, 10:17:37 UTC |
Tomorrowland Belgium 2026, spanning two weekends in July at De Schorre in Boom, sold out rapidly, creating opportunities for cybercriminals. Investigation uncovered approximately a dozen fraudulent websites impersonating the festival brand to target ticket seekers and travellers. These scams include fake ticket shops mimicking official sales with countdown timers and fraudulent biometric checks, travel sites offering bogus accommodation and transport packages, and affiliate schemes. The operations harvest complete identity data, payment credentials, and personal information through sophisticated social engineering. Victims lose money with no recourse, face identity theft risks, and ultimately receive invalid or non-existent tickets. The scammers exploit high demand, tight supply, and rushed purchasing decisions, with sites registered weeks in advance and pushed hardest when official tickets are sold out. Join the discussion | AlienVault OTX General | 07/14/2026, 07:19:34 UTC Added: 07/14/2026, 09:47:42 UTC |
Showing 1 to 10 of 56 results