Skip to main content

Threats Tagged 't1614'

View all threats tagged with 't1614'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: t1614

Threats Tagged 't1614'

Click on any threat for detailed analysis and mitigation recommendations

A new JavaScript infostealer dubbed WeaselBiscuit has been discovered hidden in 11 malicious npm packages. This lean malware shares operational similarities with DPRK-linked BeaverTail and OtterCookie families but features a stripped-down architecture. WeaselBiscuit deploys through npm imports, executes a detached Node process, retrieves its payload from Npoint URLs, and communicates with a C2 server at 103.170.217.184:8787. The malware profiles infected hosts, steals Chrome extension storage containing wallet signing states, captures clipboard contents, and logs Windows keystrokes when commanded. Unlike its predecessors, it lacks wallet-draining code, browser password decryption, Python second stages, screenshots, and remote shell capabilities. The operation uses numeric campaign identifiers embedded in package names for tracking. While technical overlap suggests DPRK attribution, particularly through Npoint dead-drop patterns and nested IP geolocation lookups, definitive attribution requires additional c...

Join the discussion

In August 2026, a Casbaneiro campaign targeted Latin American users through phishing emails and PDFs themed as fake invoices and legal notices. The multi-stage infection chain includes HTA downloaders and AutoIt loaders, employing geofencing to filter victims by IP address location. The malware exhibits sophisticated evasion techniques, including distributed data-receiving servers, deliberate HTTP 403 responses, and activation only when victims access targeted banking websites. Casbaneiro steals email data, performs clipboard injection, and creates fake windows for fraudulent activities. The campaign specifically targets Argentina, Peru, Colombia, and Mexico while avoiding German, French, and English language systems. The malware splits stolen data across multiple servers and uses malformed HTTP packets to complicate detection and analysis efforts.

Join the discussion

Grandoreiro, a notorious banking trojan active since 2016 across Latin America, continues operations despite major law enforcement disruption in 2024. Recent campaigns leverage DLL sideloading techniques, abusing the legitimate Duplicate Files Finder application to execute malicious code. The loader incorporates extensive anti-analysis mechanisms including sandbox detection, virtual machine artifact checks, process blacklisting, and environment profiling to evade automated analysis systems. These defensive checks occur before C2 contact, indicating high priority on avoiding detection. Telemetry from June 2026 shows activity concentrated in Latin America, primarily Mexico, with limited presence in Europe and North America. The malware uses custom string obfuscation combining proprietary decryption with Base64 encoding, and communicates with C2 infrastructure over TCP port 6432 using encrypted requests containing host-specific information.

Join the discussion

A new ClickFix campaign targets Windows users with a NodeJS-based infostealer delivered via malicious MSI installers. This highly adaptable remote access Trojan minimizes forensic footprints through dynamic capability loading, with core stealing modules and communication protocols delivered in-memory only after C2 connection. The malware routes gRPC streaming traffic over Tor network for persistent, masked bidirectional channels. An operational security failure exposed server-side admin panel protocol definitions, revealing a malware-as-a-service backend designed to manage multiple operators and automate cryptocurrency asset tracking. The modular architecture delivers malicious logic dynamically as strings executed in-memory, bypassing static signature detection while supporting full RAT functionality including shell command execution and wallet tracking.

Join the discussion

Eleven malicious NuGet packages masquerade as game cheat tools for popular games, acting as first-stage downloaders that evade detection using DNS-over-HTTPS and request UAC elevation. They fetch a second-stage PyInstaller payload named pepesoft.exe from GitHub and Hugging Face, which binds to hardware fingerprints, enforces licensing via Google Sheets telemetry, and supports remote ban-lists. Some variants enable remote control and screenshot capture through Telegram bot commands. These packages share AWS credentials and mutex identifiers, linking them to a single Russian-speaking operator marketing a commercial game-automation service.

Join the discussion

Group-IB analyzes Millenium RAT version 4.*, a remote access trojan that has undergone significant architectural changes from .NET to native C++, while continuing to leverage Telegram Bot API for command and control without requiring dedicated server infrastructure. The malware is distributed as Malware-as-a-Service by developer 'ShinyEnigma' for $50-90 USD. Active exploitation campaigns are conducted by threat actor cluster 'Y2K Operators' using social engineering tactics including fraudulent utilities, hacking toolkits, software cracks, gaming lures, and trojanized cybercrime tools. The trojan enables exfiltration of sensitive browser and system data, screenshot and audio capture, keylogging, and arbitrary executable downloads. Over 62,000 compromised endpoints across more than 160 countries have been identified, with 39,730 infections occurring in Q1 2026 alone, demonstrating accelerating infection rates.

Join the discussion

A sophisticated infostealer operation was discovered masquerading as a cryptocurrency trading application called Tralert FX. The malicious MSI installer achieved only 3/52 AV detections by using a valid EV code signing certificate from a likely front company, AgilusTech LLC. The campaign has been active since June 2025, utilizing a three-module malware kit that includes system reconnaissance, keylogging, and browser credential theft capabilities. Stolen data is exfiltrated through five GitLab repositories via automated git commits on 30-minute cycles. Hardcoded credentials exposed the entire backend infrastructure, revealing over 4,100 commits, 90+ compromised hosts, and ongoing victim compromise. The operation demonstrates clear financial motivation with focus on cryptocurrency traders for account takeover. Three ProtonMail-linked GitLab accounts operate the infrastructure, assessed as a single operator or small team. The final payload is MoonPeak, a custom variant of XenoRAT.

Join the discussion

Vect ransomware emerged in January 2026 as a new threat actor operating a Ransomware-as-a-Service program with strategic partnerships that significantly expand its reach. The group has partnered with TeamPCP, known for supply chain attacks compromising security tools like Trivy, KICS, and LiteLLM, and BreachForums, distributing affiliate keys to forum members. With 25 published victims primarily targeting the United States and Technology sector, Vect maintains an open affiliate program requiring only a $250 invite code. The operation offers multi-platform ransomware payloads for Windows, Linux, and ESXi with sophisticated lateral movement capabilities and tiered commission structures reaching 89% for top affiliates. Analysis reveals connections to the defunct Devman ransomware through shared code strings and ransom note similarities, suggesting possible rebranding or code reuse.

Join the discussion

A detailed technical analysis confirms that Kyber ransomware implements genuine hybrid post-quantum cryptography rather than mere branding. The Rust-based Windows variant encrypts files using AES-256-CTR with Kyber1024 and X25519 for key protection, appending a fixed 0x744-byte trailer containing encrypted metadata. Instrumented analysis validated the cryptographic implementation through fixture decryption but found no practical recovery path from the sample alone. The encryptor targets multiple file types, deploys standard recovery-inhibition techniques, and marks encrypted files with a .#~~~ extension. A separate ESXi variant was found to use different cryptography despite similar branding. As of April 2026, one victim was publicly listed: a large American defense contractor and IT services provider.

Join the discussion

A sophisticated phishing campaign impersonating Tesseract OCR was discovered, utilizing typosquatting and ClickFix techniques. The attack chain, named OCRFix, employed multi-stage malware deployments with heavy obfuscation and defense evasion techniques, including EtherHiding. The campaign used BNB Smart Chain TestNet to hide C2 domains through smart contracts. The malware delivery process involved three stages: a loader, a secondary loader for persistence, and a bot listener. The final payload connected to a bot control panel, allowing attackers to manage infected hosts and deploy additional malware. The campaign demonstrated a combination of simple initial access methods with complex delivery chains, highlighting the ongoing effectiveness of techniques like ClickFix and the importance of robust phishing defenses.

Join the discussion

Showing 1 to 10 of 19 results

Filters:Tag: t1614
Page 1 of 2
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses