Threat Intelligence — Page 28

Threat Intelligence

Windows Clipper Worm Phones Home Over Tor, Swaps Crypto Wallets via ActiveX

Microsoft says the campaign, active since February, uses USB-borne LNK files and Windows Script Host to drop a bundled Tor proxy that talks to a .onion C2.

2 min read
Threat Intelligence

ClickFix Campaign Turns Google Ads, GitLab, and Claude Into a Six-Wave Trust Machine

Attackers chained legitimate infrastructure across seven weeks to push malicious PowerShell commands to developers. Session tokens, SSH keys, and cloud credentials were the prize.

3 min read
Threat Intelligence

Fortibleed: How 75,000 FortiGate Firewalls Ended Up on an Attacker's Credential List

Configuration files. Legacy SHA-256 hashes. Automation at scale. The Fortibleed campaign is a slow-burn credential harvest that perimeter defenders are still catching up to.

3 min read
Threat Intelligence

Clipper Crew Buys Sponsored Posts on News Sites to Push Trojanized Crypto Tools

An untracked actor is laundering credibility through paid press placements, a phishing-grade WordPress hub, and seeded GitHub and SourceForge repos to deliver clipboard hijackers.

2 min read
Threat Intelligence

Three New Loaders Ride the ClickFix Wave: BabaDeda, Lorem Ipsum, and Potemkin

Separate research teams have pinned three distinct loader families on the same social-engineering pattern, with education and finance taking the brunt of the April 2026 activity.

3 min read
Threat Intelligence

Rokarolla Android Trojan Hits 217 Banking and Crypto Apps

Researchers at Zimperium's zLabs catalogued 137 remote commands in the new malware, including PIN capture and clipboard hijacking against crypto wallets.

2 min read
Threat Intelligence

UNC6508 Spent a Year Inside US and Canadian Research Networks via Trojanized REDCap

A China-linked espionage group hijacked REDCap's own upgrade process to plant persistent malware across academic, medical, and defense-adjacent research environments.

2 min read
Threat Intelligence

Anonymized Infrastructure Now Touches 94% of Incidents, and Most SOCs Are Still Playing Catch-Up

Survey data points to a persistent gap between IP enrichment volume and the analyst's ability to answer a simple question: who's actually on the other end?

2 min read
Threat Intelligence

SprySOCKS Crosses Over: Windows Variants Surface With Driver-Level Hiding

Two undocumented Windows builds of the China-linked backdoor — tagged WIN_DRV and WIN_PLUS — extend a toolset previously seen only on Linux.

2 min read
Threat Intelligence

ScarCruft Dresses Up NarwhalRAT in a Microsoft Account Security Alert

APT37's spear-phish leans on the oldest trick in the identity playbook: tell the user their account is at risk, then hand them the payload.

2 min read
Threat Intelligence

China-Nexus Crew Burrowed Into REDCap, Turned Google Workspace Rules Into an Exfil Pipe

A 13-plus-month intrusion across medical, academic, and defense research networks abused victim-side mail forwarding instead of dropping noisy C2.

2 min read
Threat Intelligence

Contagious Interview Pivots to Dev-Review Lures in Two Fresh Campaigns

The North Korea-linked cluster is back with phishing pretexts aimed at developers — recruiter pitches and code-review requests that drop malware on engineers' workstations.

3 min read
Threat Intelligence

Trusted Plugin Scripts Weaponized in Admin-Aware WordPress Supply-Chain Hit

Tampered JavaScript served from PushEngage, OptinMonster and TrustPulse fingerprinted logged-in admins before silently provisioning rogue accounts and a stealth plugin.

3 min read
Threat Intelligence

152 Chrome 'Wallpaper' Extensions Quietly Push Adware to 105K Browsers

A 38-account publisher cluster on the Chrome Web Store funnels new-tab traffic through three backends — and it looks a lot less like art and a lot more like an ad-fraud pipeline.

2 min read
Threat Intelligence

Threat Actor 'Misere' Claims Breach of French Government Messaging Platform Tchap

Around 73,000 sovereign-platform accounts may be compromised. Attribution remains unclear, and the actor is not yet tied to a known cluster.

2 min read
© 2026 Threat Vectr