Skip to main content

Topic

Reports

CTI Roundup: Remcos RAT Phishing Attacks, New Meduza Stealer Found on Dark Web
Jan 10, 2024

CISA adds two bugs to the KEV catalog, UAC-0050 distributes Remcos RAT with phishing tactics, and an updated version of Meduza Stealer launches on the dark web.

CTI Roundup – top 2023 stories: The latest on Chae$ 4, 3AM ransomware, DarkGate, and Andariel
Jan 3, 2024

Tanium’s Cyber Threat Intelligence (CTI) team looks at some of the top cybersecurity developments from 2023 that will continue to pose threats in 2024.

CTI Roundup: TA4557, OAuth Cryptomining, and the China-based KEYPLUG backdoor
Dec 21, 2023

TA4557 targets recruiters via email, threat actors use OAuth apps to automate BEC and cryptomining attacks, and researchers discover Sandman APT’s connection to the China-based KEYPLUG backdoor.

CTI Roundup: Russian threat actor APT28 exploits Outlook vulnerability
Dec 13, 2023

APT28 exploits a critical Outlook vulnerability, QR phishing campaigns grow more complex, and an SQL brute force attack results in BlueSky ransomware.

Tanium–Blog-2.3.22-Naveen Goela’s Mission to Mature Security with Science
Dec 6, 2023

North Korean hackers pose as job seekers and recruiters, the Telekopye Telegram bot enables large-scale phishing scams, and DPRK-aligned threat actors target macOS in two campaigns.

CTI Roundup: AlphaLock, a New Russian Hacking Group is Discovered
Nov 21, 2023

Researchers discover a new Russian hacking group, Rhysida ransomware threatens multiple sectors, and a new campaign targets public Docker Engine APIs.

CTI Roundup: ChatGPT-Powered Infostealer Targets Cloud Platforms
Nov 16, 2023

Google Cloud releases its Q3 Threat Horizons report, BlueNoroff hacks macOS machines with ObjCshellz malware, and a ChatGPT-powered infostealer targets cloud platforms.

CTI Roundup: Hackers Target Crypto Experts with KANDYKORN Malware
Nov 8, 2023

Lazarus Group targets a software vendor, a link shortening service abuses the .US top-level domain, and hackers target crypto experts with KANDYKORN malware.

CTI Roundup: Ransomware Spikes in September, Updates on Octo Tempest & Quasar RAT
Nov 1, 2023

Octo Tempest threatens global organizations, ransomware activity spikes in September, and Quasar RAT evades detection with DLL sideloading.

CTI Roundup: North Korean Lazarus Group Exploits JetBrains TeamCity Flaw
Oct 25, 2023

BlackCat operators introduce Munchkin utility, North Korean threat actors exploit JetBrains TeamCity flaw, and threat actors target macOS with evolving techniques.

Image for MITRE ATT&CK blog post
Oct 18, 2023

Threat actors attempt moving laterally from SQL server to the cloud, ShellBot avoids detection in attacks on Linux SSH servers, and Smart Links attacks target Microsoft accounts.

CTI Roundup: The FBI takes down Qakbot and Bumblebee returns from hiatus
Oct 11, 2023

A look at the FBI’s recent Qakbot takedown, the return of Bumblebee after a two-month hiatus, and other developing cyberthreats from 2023.