Threats Tagged 'underground'
View all threats tagged with 'underground'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'underground'
Click on any threat for detailed analysis and mitigation recommendations
A cryptocurrency-stealing operation utilizing an Aotera/Tedy loader injects a Vidar-class stealer into Windows processes, launching Chrome or Edge to inject malicious scripts into victim sessions. The malware builder, dubbed Underground, has been active since October 2023. The operation employs seven gate domains and has drained approximately $100,000 across 80+ destination addresses on 23 blockchain networks from 350-430 victims. The infection begins with lure archives containing trojanized files, deploying a loader that implements anti-analysis checks against 67 monitoring tools. Once injected, the stealer automatically drains cryptocurrency exchange accounts through fake security overlays, converts holdings to Bitcoin, and modifies withdrawal confirmation emails. A clipboard clipper targeting two dozen cryptocurrencies replaces copied wallet addresses with operator-controlled addresses. The operation rotates Cloudflare-fronted domains faster than reputation-based detection can respond. Join the discussion | AlienVault OTX General | 10/02/2026, 07:13:34 UTC Added: 10/02/2026, 07:46:12 UTC |
Showing 1 to 1 of 1 result