Topic
Reports

CTI Roundup: Remcos RAT Phishing Attacks, New Meduza Stealer Found on Dark Web
CISA adds two bugs to the KEV catalog, UAC-0050 distributes Remcos RAT with phishing tactics, and an updated version of Meduza Stealer launches on the dark web.

CTI Roundup – top 2023 stories: The latest on Chae$ 4, 3AM ransomware, DarkGate, and Andariel
Tanium’s Cyber Threat Intelligence (CTI) team looks at some of the top cybersecurity developments from 2023 that will continue to pose threats in 2024.

CTI Roundup: TA4557, OAuth Cryptomining, and the China-based KEYPLUG backdoor
TA4557 targets recruiters via email, threat actors use OAuth apps to automate BEC and cryptomining attacks, and researchers discover Sandman APT’s connection to the China-based KEYPLUG backdoor.

CTI Roundup: Russian threat actor APT28 exploits Outlook vulnerability
APT28 exploits a critical Outlook vulnerability, QR phishing campaigns grow more complex, and an SQL brute force attack results in BlueSky ransomware.

CTI Roundup: Multiple Cyber Threats from North Korean Groups and a Telegram Bot Phishing Scam
North Korean hackers pose as job seekers and recruiters, the Telekopye Telegram bot enables large-scale phishing scams, and DPRK-aligned threat actors target macOS in two campaigns.

CTI Roundup: AlphaLock, a New Russian Hacking Group is Discovered
Researchers discover a new Russian hacking group, Rhysida ransomware threatens multiple sectors, and a new campaign targets public Docker Engine APIs.

CTI Roundup: ChatGPT-Powered Infostealer Targets Cloud Platforms
Google Cloud releases its Q3 Threat Horizons report, BlueNoroff hacks macOS machines with ObjCshellz malware, and a ChatGPT-powered infostealer targets cloud platforms.

CTI Roundup: Hackers Target Crypto Experts with KANDYKORN Malware
Lazarus Group targets a software vendor, a link shortening service abuses the .US top-level domain, and hackers target crypto experts with KANDYKORN malware.

CTI Roundup: Ransomware Spikes in September, Updates on Octo Tempest & Quasar RAT
Octo Tempest threatens global organizations, ransomware activity spikes in September, and Quasar RAT evades detection with DLL sideloading.

CTI Roundup: North Korean Lazarus Group Exploits JetBrains TeamCity Flaw
BlackCat operators introduce Munchkin utility, North Korean threat actors exploit JetBrains TeamCity flaw, and threat actors target macOS with evolving techniques.

CTI Roundup: Smart Links Attacks Target Microsoft Accounts
Threat actors attempt moving laterally from SQL server to the cloud, ShellBot avoids detection in attacks on Linux SSH servers, and Smart Links attacks target Microsoft accounts.

CTI Roundup: The FBI takes down Qakbot and Bumblebee returns from hiatus
A look at the FBI’s recent Qakbot takedown, the return of Bumblebee after a two-month hiatus, and other developing cyberthreats from 2023.