Threat Intelligence — Page 12

Threat Intelligence

Mini Shai-Hulud Worm Jumps to Go, Hits LeoPlatform and RStreams npm Packages

The self-propagating supply chain campaign tied to Miasma and Hades has spread again — abusing GitHub Actions workflows and now reaching Go modules.

2 min read
Threat Intelligence

Hotel Front Desks Hit by Photo-ZIP Phishing Dropping Node.js Implant

Microsoft flags an unattributed campaign active since April 2026 against hospitality targets in Europe and Asia.

3 min read
Threat Intelligence

Turla's STOCKSTAY: A Fresh .NET Backdoor Aimed at Kyiv and Rome

Google's threat hunters tie the Russian FSB-linked crew to a previously undocumented Windows implant hitting Ukrainian military targets and Italy-focused diplomatic entities.

2 min read
Threat Intelligence

Featured Chrome Ad Blocker with 10M+ Installs Carries Dormant JS Injection Capability

Researchers flagged a Featured-badge extension that can pull and execute remote JavaScript — a capability common to supply-chain abuse clusters tracked across the Chrome Web Store.

2 min read
Threat Intelligence

The Week in Cheap Crime: Stale Creds, Trusted Apps, and Phishing Through the Front Door

Not elite. Not cinematic. Just effective — and that's the problem.

2 min read
Threat Intelligence

Iranian Group Handala Claimed It Could Poison California's Water. Forensics Say Otherwise.

California Water Service brought in Mandiant after Handala threatened disruption. Investigators found no evidence the group ever touched operational technology.

2 min read
Threat Intelligence

Mistic Backdoor Shows Up in IAB-Brokered Intrusions Across Four Verticals

A quiet new implant tied to the KongTuke access broker is landing on insurance, education, IT, and professional services networks — and it's not riding a CVE to get there.

3 min read
Threat Intelligence

Mistic Backdoor Ties to IAB Selling Enterprise Footholds to Ransomware Gangs

A new in-memory backdoor named Mistic has been active since April, and the threat actor behind it has reportedly funneled access to Qilin, Akira, Black Basta, and others.

2 min read
Threat Intelligence

Operation Endgame Hits Amadey and StealC, Pulls 27M Credentials From Loader Infrastructure

Europol-led takedown dismantled command servers behind two of the most prolific malware-as-a-service loaders, with Microsoft, ESET, Bitdefender, and Bitsight providing technical support.

3 min read
Threat Intelligence

Law Enforcement and Microsoft Tear Down Command Infrastructure Behind Amadey and StealC

Hundreds of C2 servers went dark in a coordinated takedown targeting the shared hosting backbone used by two prolific infostealer families.

2 min read
Threat Intelligence

FortiBleed: Russian-Speaking Broker Tied to 430K FortiGate Credential Harvest

Researchers attribute the long-running operation to a financially motivated IAB, with credential lists feeding brute-force runs against exposed FortiGate appliances since February.

2 min read
Threat Intelligence

Three npm Packages Squat PostCSS Names to Drop a Windows RAT

Typosquatted utilities pulled roughly a thousand combined downloads before researchers flagged them. The payload targets Windows developer machines, which is exactly where the credentials live.

2 min read
Threat Intelligence

WhatsApp DMs Push VBScript Loaders That Deploy Legitimate RMM Tools

An active campaign abuses WhatsApp Desktop and Web to distribute scripted droppers that install commercial remote-management software across at least ten jurisdictions.

2 min read
Threat Intelligence

ShapedPlugin's Update Channel Hijacked, Pro Plugins Shipped with Backdoor

Attackers slipped malicious code into licensed Pro releases by compromising the vendor's own build pipeline — a clean supply-chain hit on WordPress installs.

2 min read
Threat Intelligence

The 'Search-as-a-Service' Economy Built on Stolen Credentials

Underground brokers now sell targeted lookups against stolen credential corpora, lowering the bar for access brokers and intrusion crews alike.

2 min read
© 2026 Threat Vectr