GrayBravo: Threat Activity Cluster Behind CastleLoader and CastleStealer
GrayBravo is a threat activity cluster attributed to distributing CastleLoader and CastleStealer malware. The group is known for using ClickFix-style lures and…
MITRE ATT&CK groups, threat actors, intrusion sets and activity clusters.
GrayBravo is a threat activity cluster attributed to distributing CastleLoader and CastleStealer malware. The group is known for using ClickFix-style lures and…
PolinRider is a threat cluster assessed to be related to the Contagious Interview campaign, known for using multi-blockchain resolver structures (Tron, Aptos,…
A financially motivated Russian-speaking initial access broker (IAB) is assessed to be behind the FortiBleed campaign, which has targeted over 430,000 FortiGate…
A Russian-speaking account named SantaAd advertised access to thousands of Fortinet devices for a starting price of $30,000, later increased to $60,000.…
A Russian-speaking initial access broker (IAB) has been linked to a large-scale credential-harvesting operation dubbed FortiBleed, targeting over 430,000 FortiGate firewalls globally…
Prince Group is a Cambodia-based conglomerate classified as a Transnational Criminal Organization (TCO) by the U.S. Treasury for its role in operating…
HuiOne Group is a Cambodia-based conglomerate whose subsidiaries operated an illicit Telegram marketplace, HuiOne Guarantee, facilitating money laundering for cryptocurrency investment fraud…
plymouth is the threat actor who sells the StealC information stealer under a malware-as-a-service model, charging $300 per month or $1,000 for…
YouTubeTA is a customer of the StealC MaaS operation who used Google's YouTube platform to distribute the stealer by advertising cracked versions…
InCrease is the threat actor who advertises and sells the Amadey malware loader under a malware-as-a-service model. The actor charges $600 for…