ZoomEye Used in Reconnaissance for PLC Exploitation
ZoomEye, a cyberspace mapping service, is used by threat actors to find poorly protected PLCs exposed to the internet. This aids in…
ZoomEye, a cyberspace mapping service, is used by threat actors to find poorly protected PLCs exposed to the internet. This aids in…
SoftPerfect Network Scanner is a network scanning tool used by Ransom Busters for internal reconnaissance during intrusions.
Matryoshka is a Rust-based backdoor family deployed in attacks on law firms. It comes in two variants: one uses HTTP-based communication for…
BINDCLOAK is a 64-bit C++ implant that contacts an external server for command-and-control. It is the final payload in the attack chain,…
LogMeIn is a remote access and support software. Qilin ransomware affiliates used LogMeIn for reconnaissance and remote access during post-exploitation activities after…
SCOUTCURL is a PowerShell script used by UAC-0145 to perform basic reconnaissance by harvesting details about infected machines.
SharpShares is a C#-based utility for enumerating network shares. It was used by the attacker to find user-accessible data repositories.
Cybersecurity researchers at Huntress have identified an intrusion where an unknown threat actor used a suspected AI-generated PowerShell script to enumerate Active…
Datadog Security Labs has uncovered several overlapping campaigns that leverage dormant GitHub accounts—some created two to five years ago—to systematically enumerate corporate…
Iranian state-sponsored hackers affiliated with the Ministry of Intelligence and Security (MOIS) have been using a previously undocumented modular command-and-control (C2) framework…