HiddenTear: Ransomware Signatures Found in Sable Squirrel Campaigns
HiddenTear is a ransomware family whose signatures have been found in artifacts communicating with Sable Squirrel's infrastructure, indicating potential ransomware activity within…
HiddenTear is a ransomware family whose signatures have been found in artifacts communicating with Sable Squirrel's infrastructure, indicating potential ransomware activity within…
Threat actors are increasingly acquiring expired domains—known as "dropcatch domains"—to inherit their reputation and traffic, redirecting victims to scams and malware. According…
SocGholish is a malware campaign that regained access to thousands of compromised sites by teaming up with Shady Squirrel shortly after its…
NanoCore is a remote access trojan that has been identified in malware samples communicating with Sable Squirrel's infrastructure, highlighting its role in…
njRAT is a remote access trojan that has been detected in malware samples communicating with Sable Squirrel's infrastructure, contributing to the threat…
Nanjing Ranyi Technology Co., Ltd. is a Chinese company whose digital certificate was used to sign the malicious msagent.sys driver. The certificate…
Ransomware is a type of malware deployed by Transnational Criminal Organizations to extort victims. The White House memo highlights ransomware as one…
This week's ThreatsDay Bulletin covers a wide range of cybersecurity developments, including new attack techniques, data breaches, and product updates. Key highlights…
SHEETCREEP is a malware family that uses Google Sheets for C2 communications. It is referenced as a predecessor to SHEETCORD, which combines…
HACKERAI C2 is an AI-assisted malware project that overlaps with PATCHCORD and SHEETCORD but uses GitHub Gists for C2. It implements dedicated…