Cybersecurity researchers have uncovered a new Python-based implant framework called TWINLOOT that abuses trusted Microsoft services for command-and-control (C2) operations. The malware,…
Backdoor.TurnBroadcomC2 infrastructureCarbon Black
Cybersecurity researchers have uncovered new components in the Cavern (aka Cav3rn) command-and-control (C2) framework, used by Iranian nation-state hackers in attacks targeting…
The China-linked threat actor known as Jewelbug has been observed conducting cyber espionage against governments and militaries while simultaneously running a cryptocurrency…
Cybersecurity researchers at Arctic Wolf Labs have uncovered a widespread email-driven phishing campaign that uses adversary-in-the-middle (AitM) techniques to compromise Microsoft 365…
AitM phishingArctic Wolf Labsbusiness email compromisecredential theft
The commercial phishing-as-a-service (PhaaS) toolkit known as Greatness has expanded its capabilities to include device code phishing, a technique that abuses the…
Iranian state-backed hacking group Nimbus Manticore (also known as GalaxyGato, Mirage Kitten, Smoke Sandstorm, Subtle Snail, and UNC1549) has been linked to…
Group-IB has discovered a new espionage implant named HollowGraph that hijacks Microsoft 365 calendars for command-and-control (C2) and data exfiltration. The malware,…