New PATCHCORD Backdoor Targets Afghan Telecom and Indian Critical Infrastructure
Afghan telecom providers and South Asian critical infrastructure organizations are the targets of a new campaign delivering a previously undocumented backdoor called…
Afghan telecom providers and South Asian critical infrastructure organizations are the targets of a new campaign delivering a previously undocumented backdoor called…
The Computer Emergency Response Team of Ukraine (CERT-UA) has disclosed a new social engineering campaign attributed to UAC-0145, a subgroup of the…
Cybersecurity researchers have uncovered an active, multi-wave campaign that uses social engineering lures themed around Adobe and Zoom updates, business document reviews,…
In-memory PowerShell stealer that collects Microsoft 365 and Azure AD tokens from the Token Broker cache, enabling session replay.
The North Korean threat actors behind the ClickFix-style campaigns that employ typosquatted Zoom and Microsoft Teams domains have been found to operate…
SCOUTCURL is a PowerShell script used by UAC-0145 to perform basic reconnaissance by harvesting details about infected machines.
TookPS is a PowerShell downloader used as the initial payload for OkoBot. It has been active since March 2025, delivered via fake…
Cybersecurity researchers at Huntress have identified an intrusion where an unknown threat actor used a suspected AI-generated PowerShell script to enumerate Active…
A new banking fraud operation tracked as REF6045 by Elastic Security Labs is targeting customers of Mexican banks, fintech platforms, payment processors,…
A previously undocumented threat actor, Armored Likho, has been attributed to cyber attacks targeting government agencies and the electric power sector across…