Threats Tagged 'trojans'
View all threats tagged with 'trojans'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'trojans'
Click on any threat for detailed analysis and mitigation recommendations
In October 2025, phishing emails predominantly delivered Trojan malware via attachments, accounting for 47% of cases. These attachments included scripts, documents, and compressed files, notably RAR archives containing JavaScript files. The phishing campaigns also involved distribution of Remcos RAT malware and used document attachments to download additional payloads. Korean phishing emails were specifically analyzed, revealing targeted case names, subjects, and attachment filenames. The report highlights evolving tactics such as increased use of compressed JS files and exploitation of OLE objects within documents. The threat leverages multiple MITRE ATT&CK techniques including persistence, command execution, and credential access. This medium-severity campaign poses significant risks through social engineering and malware delivery via email attachments, requiring focused defensive measures. No known exploits in the wild are reported, but the widespread use of common file formats and compression methods increases the attack surface. European organizations should be vigilant against these evolving phishing tactics and malware payloads. Join the discussion | AlienVault OTX General | 11/20/2025, 14:45:53 UTC Added: 11/20/2025, 22:13:41 UTC |
A financially motivated cybercrime operation has been identified, targeting users with over 80 spoofed domain names and lure websites. The campaign, which began in September 2024, focuses on government tax sites, consumer banking, age 18+ social media content, and Windows assistant applications. The actors use these domains to deliver Android and Windows trojans, likely for credential theft. The operation employs common techniques such as spoofed domains and lure websites, prioritizing scale and conversion rates over technical sophistication. The most common lures exploit curiosity and desire, making victims less likely to report infections. Users are advised to be cautious when encountering unfamiliar links or download prompts. Join the discussion | AlienVault OTX General | 10/06/2025, 11:06:11 UTC Added: 10/06/2025, 11:28:20 UTC |
Showing 1 to 2 of 2 results