TaskJacker: Malicious VS Code Task File Cluster in PolinRider Campaign
A cluster within the PolinRider campaign that drops malicious VS Code task files into GitHub users' repositories. The tasks use 'runOn: folderOpen'…
MITRE ATT&CK groups, threat actors, intrusion sets and activity clusters.
A cluster within the PolinRider campaign that drops malicious VS Code task files into GitHub users' repositories. The tasks use 'runOn: folderOpen'…
North Korean threat actors linked to the Contagious Interview campaign have published 108 unique malicious packages and browser extensions across npm, Packagist,…
Threat actors with ties to North Korea have been linked to a fresh set of malicious npm packages that masquerade as Rollup…
A previously undocumented threat actor, Armored Likho, has been attributed to cyber attacks targeting government agencies and the electric power sector across…
Armored Likho is a previously undocumented threat actor targeting government agencies and electric power sectors in Russia, Brazil, and Kazakhstan. They blend…
Eagle Werewolf is a threat cluster tracked by BI.ZONE, active since May 2023, targeting government and defense organizations, especially those involved in…
ToddyCat is an advanced persistent threat (APT) group active since at least 2020, known for targeting organizations in Europe and Asia. The…
An AI-agent-driven operator first documented by Sysdig. Deployed ENCFORGE ransomware against Langflow servers, using Docker socket for host breakout. Previously used throwaway…
MUT-1244 is a campaign that used fake PoC repositories to steal SSH keys and cloud credentials from red teamers and researchers, similar…
The recently discovered financially-motivated FortiBleed campaign has been attributed to INC and Lynx ransomware operations, indicating that the verified, stolen credentials were…