
Category: Threat Intel Reports
-
Investigating Infrastructure and Tactics of PhishingasaService Platform Sniper Dz
Unit42 explores Sniper Dz, a popular phishing-as-a-service (PhaaS) platform targeting social media and online services. Over 140,000 phishing websites associated…
-
ReadText34 Ransomware Incident
A ransomware attack was observed in September 2024, targeting an endpoint with limited visibility. The threat actor used stolen Administrator…
-
How Ransomhub Ransomware Uses EDRKillShifter to Disable EDR and Antivirus Protections
The RansomHub ransomware, attributed to a group tracked as Water Bakunawa, employs sophisticated anti-EDR techniques to evade security solutions. Its…
-
Necro Trojan infiltrates Google Play and Spotify and WhatsApp mods
A new version of the Necro Trojan has infected various popular applications, including game mods and apps on Google Play,…
-
Inside SnipBot: The Latest RomCom Malware Variant
A novel version of the RomCom malware family called SnipBot has been discovered, revealing post-infection activity from attackers on victim…
-
Inside SnipBot: The Latest RomCom Malware Variant
A novel version of the RomCom malware family called SnipBot has been discovered, revealing post-infection activity from attackers on victim…
-
An Offer You Can Refuse: Backdoor Deployment Using Trojanized PDF Reader
UNC2970, a suspected North Korean cyber espionage group, targeted critical infrastructure sectors using job-themed phishing lures. The group employed a…
-
Binary Managed Object File (BMOF) Distributing XMRig CoinMiner
This analysis explores the use of Binary Managed Object Files (BMOFs) in distributing XMRig CoinMiner. BMOFs, compiled versions of Managed…
-
The Nanshou Campaign Hackers Arsenal Grows Stronger
This comprehensive analysis details a sophisticated cyber campaign targeting over 50,000 Windows servers worldwide, primarily in the healthcare, telecommunications, media,…
-
The Nanshou Campaign Hackers Arsenal Grows Stronger
This comprehensive analysis details a sophisticated cyber campaign targeting over 50,000 Windows servers worldwide, primarily in the healthcare, telecommunications, media,…

