Threat Intelligence — Page 25

Threat Intelligence

Phantom Squatting: When Attackers Camp on the Domains LLMs Hallucinate

Unit 42 documents a pre-positioning tactic where actors register non-existent domains that chatbots keep suggesting, then wait for the traffic to arrive.

2 min read
Threat Intelligence

ClickFix Grows a Back Office: API-Served Payloads and a New AMSI Bypass

Researchers pulled roughly 3,000 live payloads from ClickFix infrastructure and found a polymorphic delivery pipeline built to defeat Windows script scanning.

2 min read
Threat Intelligence

RustDuck: A Rust-Based DDoS Botnet Quietly Building Out Since February

XLab researchers say the two-stage loader is iterating faster than its install base is growing — and that's the interesting part.

2 min read
Threat Intelligence

Silent Swap: Unsigned Installers Drop Fake Chromium Extensions That Hijack Crypto Transactions

McAfee Labs documents a clipper campaign using .NET and Golang loaders to sideload a malicious browser extension that rewrites wallet addresses at send time.

3 min read
Threat Intelligence

BEC Isn't an Email Problem. It's a Supply Chain.

Underground forums show Business Email Compromise as a multi-stage operation — account access, target research, and mules — not a clever phishing lure.

2 min read
Threat Intelligence

FIFA 2026 Fraud Infrastructure Was Pre-Staged Months Before Kickoff, Researchers Say

A Check Point exposure report documents pre-positioned phishing kits, lookalike domains and multilingual scam pages built well ahead of the June 11 opening match.

2 min read
Threat Intelligence

From Modded Game Controllers to IBM X-Force Red: The Chris Thompson Arc

A teenage hardware tinkerer grows up to run one of the most recognizable offensive-security brands in enterprise tech — then leaves to build something new.

2 min read
Threat Intelligence

Fake Perplexity Extension Siphoned Every Chrome Address Bar Keystroke

Microsoft researchers flagged a counterfeit Perplexity Chrome extension that piped queries and omnibox input to an attacker server before completing the search.

3 min read
Threat Intelligence

Mustang Panda Turns Zoho WorkDrive Into C2 in Twin Campaigns Against Indian Government

The China-aligned crew is running parallel operations against New Delhi ministries and hydropower operators, abusing a legitimate cloud collaboration service to move commands past network defenses.

3 min read
Threat Intelligence

Monday Brief: A DirtyClone Linux Bug, Turla's New Backdoor, and the Infostealer Churn

Old access paths, missed patches, and a fresh kernel flaw kept defenders busy. A roundup of what moved this week in the cybercrime ecosystem.

2 min read
Threat Intelligence

236,000 Sites Run Pig-Butchering Templates Built on DCloud Uni-App

Infoblox researchers tie a sprawling fake-exchange and wallet-drainer ecosystem to a legitimate Chinese cross-platform dev framework.

2 min read
Threat Intelligence

Gamaredon's 2025 Phishing Surge: 35 Campaigns, Fresh Loaders, and Identity Tradecraft

The Russia-aligned group has spent the year refining spear-phishing lures against Ukrainian targets, leaning harder on cloud services and credential theft.

3 min read
Threat Intelligence

Harvest Now, Decrypt Later: Why Credentials Are the First Casualty of Q-Day

Captured ciphertext today becomes plaintext tomorrow. Credentials sit at the top of the target list.

2 min read
Threat Intelligence

Microsoft Pulls 119 Edge Extensions Tied to 'StegoAd' Steganography Campaign

The add-ons concealed payloads in image and font files and activated days after install. Microsoft attributes the activity to a single actor operating since 2021.

2 min read
Threat Intelligence

Supply-Chain Attackers Hide Python Stealer in npm and Go Packages, Sidestep Lifecycle Scripts

JFrog flags two hijacked npm packages and a Go cluster that abuse VS Code tasks to drop a cross-platform infostealer — bypassing the script hooks defenders typically watch.

3 min read
© 2026 Threat Vectr