Campaign Threats
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Filtered Threats
Click on any threat for detailed analysis and mitigation recommendations
Fake Reservation Links Prey on Weary Travelers 0 The TA558 threat group has increased campaigns targeting the travel and hospitality industries with fake reservation emails containing malicious links or attachments. These campaigns deliver malware payloads such as remote access trojans (RATs) via ISO and RAR file attachments, which victims must decompress and execute. The group has evolved tactics from using Office document exploits to container files due to changes in Microsoft Office macro policies. TA558 is financially motivated, aiming to steal data and money from organizations and customers in the travel sector. HighCampaign Join the discussion | Threatpost | 08/22/2022, 13:59:06 UTC Added: 08/04/2026, 12:41:23 UTC |
WhatsApp account takeover scam asks you to "vote for my friend" 0 A sophisticated scam is spreading through WhatsApp that exploits the platform's legitimate 'Linked devices' feature to take over user accounts. Attackers compromise existing accounts and send messages to contacts asking them to vote for a friend or relative in various online contests. When victims click the provided link, they are redirected through pages appearing to be WhatsApp-related, often using the legitimate wa.me domain. The attack tricks users into authorizing a new linked session, granting attackers full access to read messages, send messages as the victim, and access contacts. The scam is particularly effective because it comes from known contacts and relies on trust and quick reactions. Once compromised, attackers can continue the scam by messaging the victim's contacts, creating a chain of account takeovers without triggering traditional security alerts. Join the discussion | AlienVault OTX General | 08/04/2026, 07:17:39 UTC Added: 08/04/2026, 08:18:17 UTC |
8 countries. 8 critical sectors. One APT🔥 0 This report highlights a cyber espionage campaign attributed to the Iranian APT group Charming Kitten, targeting eight countries and eight critical sectors simultaneously. The campaign, dubbed Operation Olalampo, affects Egypt, Saudi Arabia, UAE, Turkey, Hungary, Turkmenistan, Israel, and South America, focusing on government, healthcare, financial services, energy, education, telecommunications, defense, and industrial sectors. The information is sourced from a Reddit post linking to a GitHub repository simulating adversary tactics. No specific vulnerabilities or exploits are detailed, and no affected software versions are identified. CriticalCampaign Join the discussion | Reddit BlueTeam | 08/03/2026, 07:07:43 UTC Added: 08/03/2026, 19:33:10 UTC |
Tax Season, Open Season: Phishing and Malware Campaigns Targeting Indian Taxpayers 0 A sophisticated malware campaign is targeting Indian taxpayers during filing season by impersonating the Income Tax Department. Attackers distribute fake penalty notices via WhatsApp from unknown or compromised accounts, using forged Office Memorandums citing legitimate tax law sections and creating 72-hour deadlines to induce panic. The campaign delivers ITD.zip files containing malicious Android APKs and Windows executables that harvest OTPs, banking credentials, and enable remote access. The infrastructure relies on disposable domains using cheap TLDs and Alibaba Cloud storage for payload delivery. This activity is part of a broader ecosystem including refund SMS fraud, cloned e-Filing portals, and fake e-PAN emails. The operation demonstrates resource and planning through bilingual content, payload rotation to evade detection, and abuse of legitimate code-signing certificates. Join the discussion | AlienVault OTX General | 07/30/2026, 10:18:37 UTC Added: 07/31/2026, 11:22:21 UTC |
Operation Endgame disrupted hundreds of systems — a StealC backend I reported still exposes its known routes 0 Operation Endgame disrupted hundreds of systems — a StealC backend I reported still exposes its known routes Source: https://blog.technopathy.club/operation-endgame-stealc-backend-still-responds Join the discussion | Reddit Malware | 07/31/2026, 05:15:17 UTC Added: 07/31/2026, 07:52:02 UTC |
CISA Urges Water Sector to Protect OT After Coordinated Attacks on PLCs 0 CISA is urging water and wastewater utilities to lock down internet-exposed controllers, days after intrusions hit dozens of Minnesota systems. The post CISA Urges Water Sector to Protect OT After Coordinated Attacks on PLCs appeared first on SecurityWeek . MediumCampaign Join the discussion | SecurityWeek | 07/30/2026, 22:18:36 UTC Added: 07/30/2026, 22:22:06 UTC |
ClickFix Keeps Evolving: Rundll32 Ordinal Execution over WebDAV 0 A sophisticated ClickFix campaign variant uses social engineering to trick victims into executing commands via the Windows Run dialog. The technique leverages rundll32.exe to load remote non-DLL payloads by ordinal export #1 over WebDAV connections tunneled through HTTPS port 443. Multiple incidents at a single organization show evolving obfuscation methods including WMI process spawning, caret insertion, and runtime string assembly to evade detection. The attack chain utilizes trusted Windows binaries like pcalua.exe to break process lineage tracking. No files are dropped to disk, and payloads are invoked by ordinal rather than named functions. Successful attacks exfiltrated browser credentials and sensitive documents totaling 13MB. The most obfuscated variant evaded automated EDR detection entirely, being discovered only through proactive threat hunting focused on ordinal execution patterns rather than keyword detection. Join the discussion | AlienVault OTX General | 07/29/2026, 02:59:33 UTC Added: 07/29/2026, 12:07:07 UTC |
Shai-Hulud-Style npm Worm Hits 0 Multiple npm packages across @tanstack, @mistralai, @uipath, @squawk, and safe-action namespaces were compromised in a worm-like attack affecting over 50 packages. The malicious code executes during installation, downloading the Bun runtime and running a payload that harvests GitHub credentials and cloud secrets. The attack specifically targets AWS environments by querying the IMDS and attempting privilege escalation through STS and SSM endpoints across multiple regions. Stolen credentials are automatically used to publish additional malicious package versions across different maintainer accounts, creating a self-propagating infection chain. The attack patterns mirror previous Shai-Hulud compromises, using a drop-and-execute technique and command-and-control infrastructure at git-tanstack.com, a domain designed to mimic legitimate tanstack.com traffic. Organizations should rotate GitHub credentials, audit AWS credentials, and check for suspicious activity. Join the discussion | AlienVault OTX General | 07/29/2026, 08:57:13 UTC Added: 07/29/2026, 11:52:25 UTC |
AI-Native security platform 0 Between May and July 2026, security researchers deployed an unauthenticated Model Context Protocol (MCP) honeypot server to observe how threat actors exploit AI agent infrastructure. Of approximately 1,000 sources that reached the decoy, 596 spoke the protocol and 24 proceeded to actively exploit it. These operators executed 628 shell commands, 255 file reads, and 248 secrets-store lookups, with 19 hunting credentials and 4 attempting container escapes. Activity escalated from 39 tool calls in May to 877 by mid-July. Three stolen credentials were subsequently used against a live AWS account, with two cases involving Bedrock model invocation for LLMjacking. The attacks demonstrated automated reconnaissance, credential harvesting, container escape attempts, backdoor account creation, and Kubernetes enumeration, revealing that exposed MCP servers represent a growing attack surface as AI agent infrastructure proliferates. Join the discussion | AlienVault OTX General | 07/27/2026, 16:59:18 UTC Added: 07/28/2026, 10:22:27 UTC |
[email protected] Harvesting Github Credentials 0 The Intercom TypeScript Library version 7.0.4 has been compromised with malicious code that harvests GitHub credentials. Upon installation, the package executes a preinstall hook that downloads the Bun runtime, then runs a payload to extract GitHub credentials using the gh auth token command. The attack employs sophisticated C2 communication by querying GitHub's commit search API for specific strings embedded in public repositories, effectively using legitimate services to evade detection. The attack patterns mirror previous Shai-Hulud compromises, which exhibit worm-like behavior by automatically using stolen credentials to infect additional npm packages. With 361,510 weekly downloads, this compromise poses significant risk for a widespread infection wave similar to November 2025 when over 1,000 packages were affected. Join the discussion | AlienVault OTX General | 07/24/2026, 01:19:11 UTC Added: 07/24/2026, 10:37:10 UTC |
Showing 1 to 10 of 41 results