Skip to main content

Topic

Threat Intelligence

CTI Roundup: Attacks Spike in 2023, Ransomware Payments Skyrocket
Jul 19, 2023

USB-based malware attacks spike during the first half of 2023, ransomware payments skyrocket, and Big Head ransomware accelerates.

CTI Roundup: Truebot infects US & Canada networks
Jul 12, 2023

Truebot infects networks throughout the US and Canada, Charming Kitten targets new operating systems, and SmugX targets European government entities.

CTI Roundup: North Korean Andariel Group Strikes With EarlyRat Malware
Jul 6, 2023

8Base ransomware activity spikes, China-linked Volt Typhoon APT uses novel tradecraft to gain initial access to target networks, and North Korean hacker group Andariel strikes with new EarlyRat malware.

CTI Roundup: New DoJ Cyber Unit Pursues State-Sponsored Threats
Jun 27, 2023

The DoJ launches a cyber unit to prosecute nation-state threat actors, cybercriminals use expired AWS S3 buckets to distribute malicious code, and a new exfiltration malware targets RDP workloads.

CTI Roundup: Skuld Malware Steals Discord Data From Windows PCs
Jun 21, 2023

Chinese hackers use DNS-over-HTTPS for Linux malware communication, a new Golang-based Skuld malware strand steals Discord and browser data from Windows PCs, and a massive phishing campaign uses 6,000 sites to impersonate brands.

CTI Roundup: North Korea’s Kimsuky Cyber Spies at it Again
Jun 14, 2023

Washington and Seoul expose North Korea’s Kimsuky cyber spies, the Asylum Ambuscade crimeware group conducts cyberespionage, and the Cyclops ransomware and stealer combo poses a dual threat.

CTI Roundup: Microsoft Finds a macOS Bug That Lets Hackers Bypass SIP Root Restrictions
Jun 7, 2023

Improved BlackCat ransomware variant strikes with lightning speed in stealthier attacks, Microsoft finds a macOS bug that lets hackers bypass SIP root restrictions, and Dark Pink hackers continue to target government and military organizations.

CTI Roundup: Russia, Iran, & North Korea Target Global SMBs
Jun 1, 2023

State-aligned threat actors target global SMBs, new PowerExchange malware backdoors Microsoft Exchange servers, and an IT security employee attempts to impersonate a ransomware gang during an attack on his own company.

CTI Roundup: Hackers target macOS systems with Cobalt Strike
May 24, 2023

Hackers use Golang variant of Cobalt Strike to target macOS systems, Cybercriminals adapt to Microsoft’s macro-blocking feature, and cybercriminals target the Microsoft VSCode Marketplace.

Image for MITRE ATT&CK blog post
May 16, 2023

CISA issues a joint advisory on Russia’s Snake malware operation, hackers use ChatGPT lures to spread malware on Facebook, and a new phishing-as-a-service tool appears in the wild.

CTI Roundup: Google Ads pushes new BumbleBee malware
May 3, 2023

A new SLP bug potentially enables massive DDoS amplification attacks, Google Ads pushes new BumbleBee malware, and Chinese hackers use Linux malware variants for espionage .

CTI Roundup: CCP-Sponsored APT41 Deploys Google GC2 for Attacks
Apr 25, 2023

APT41 leverages Google GC2, ransomware gangs abuse Process Explorer driver to kill security software, and new details regarding 3CX’s software supply chain compromise emerge.