GhostPoster: Browser Extension Malware Campaign
GhostPoster is a browser extension malware campaign associated with DarkSpectre. It uses steganography to hide malicious code in extension icons, similar to…
MITRE ATT&CK groups, threat actors, intrusion sets and activity clusters.
GhostPoster is a browser extension malware campaign associated with DarkSpectre. It uses steganography to hide malicious code in extension icons, similar to…
DarkSpectre is a Chinese threat actor linked by Koi Security to the StegoAd campaign. It has been active since at least 2021,…
A cluster of malicious packages that use fake .woff2 font files to conceal JavaScript payloads. Tactically overlaps with TaskJacker and PolinRider, using…
North Korean threat actors have been linked to the NullReceiver campaign, which uses trojanized npm packages to deploy malware that decodes C2…
The Security Service of Ukraine (SSU), in coordination with the U.S. Federal Bureau of Investigation (FBI), has uncovered a long-running cyber espionage…
Star Blizzard is a Russian threat activity cluster known for phishing campaigns targeting messaging app users, including Signal and WhatsApp, to steal…
UNC1151, also known as Ghostwriter and UAC-0057, is a Belarus-aligned threat actor that conducted spear-phishing campaigns targeting Ukrainian government organizations, delivering the…
Ghostwriter was identified as a relevant cybersecurity entity in recently ingested reporting. This profile is generated so related cyber news, CVEs, malware,…
The FBI and CISA have updated their March warning about Russian intelligence phishing Signal accounts, adding a new tactic where attackers coax…
UNC5792, also tracked as UAC-0195, is a Russian threat cluster involved in credential theft campaigns against messaging platforms, targeting government and military…