Topic
Reports

CTI Roundup: MuddyWater Deploys BugSleep Malware, New Attack From Void Banshee
MuddyWater deploys BugSleep malware, researchers discover malicious files on the npm registry, and Void Banshee exploits a Microsoft MHTML flaw.

CTI Roundup: Threat Actor Updates. APT40, CloudSorcerer, Eldorado
APT40 rapidly exploits network vulnerabilities, CloudSorcerer APT targets Russian organizations, and Eldorado threatens Windows and Linux systems.

CTI Roundup: Busy Days for Threat Actors ONNX Store, Boolka, & SneakyChef
ONNX Store targets the financial industry, Boolka delivers the BMANAGER trojan via SQLi attacks, and SneakyChef deploys SpiceRAT and SugarGh0st.

CTI Roundup: Vortax Spreads Infostealer Malware, Linux Malware Uses Emojis to Execute Commands
Vortax spreads infostealer malware, new malware campaign distributes fake error messages, and Linux malware uses emojis to execute commands.

CTI Roundup: Windows HTML Malware, Remcos RAT, & Black Basta Ransomware
CTI reports a malware campaign utilizing Windows search in HTML, Remcos RAT via UUE files, and a Black Basta ransomware exploit of a Windows vulnerability.

CTI Roundup: TargetCompany Ransomware, LilacSquid Cyber Espionage, & DarkGate Malware
TargetCompany’s Linux variant threatens ESXi environments, LilacSquid targets multiple sectors, and DarkGate malware switches from Autolt to AutoHotkey.

CTI Roundup: Social Engineering, DNS Tunneling, & Malvertising
Beware of an ongoing campaign targeting enterprises and other current cyber threat news to know.

CTI Roundup: Q1 Exploit Trends, HijackLoader, & the State of Pentesting
Kaspersky reveals the top exploit and vulnerability trends for the first quarter of 2024, HijackLoader evolves with new evasion techniques, and Cobalt releases its 2024 State of Pentesting report.

CTI Roundup: Cuttlefish Malware, Hackers Leverage Docker Hub
Cuttlefish malware targets SOHO routers, nation states and cybercriminals share compromised networks, and threat actors use Docker Hub to spread malware and phishing scams.

CTI Roundup: ToddyCat APT, GuptiMiner Malware, APT28 Exploits a Windows Print Spooler Flaw
ToddyCat deploys advanced tools for industrial scale data theft, hackers use eScan updates to spread GuptiMiner malware, and Russia’s APT28 exploits a Windows Print Spooler flaw.

CTI Roundup: A Malicious Notepad++ Plugin, “Junk Gun” Ransomware, and a Google Malvertising Campaign
Researchers discover modified Notepad++ plug-in, new junk gun ransomware appears on cybercrime forums, and a malvertising campaign targets IT teams.

CTI Roundup: LockBit Update, Earth Freybug Deploys UNAPIMON Malware
Law enforcement’s impact on LockBit, how unpatched vulnerabilities contribute to ransomware attacks, and Earth Freybug deploys UNAPIMON malware.