Stealthy Attributes of APT Lazarus: Evading Detection with Extended Attributes

CategoryDetailsThreat ActorsAPT LazarusCampaign OverviewNew technique for code smuggling using custom extended attributes (EAs) in macOS…

Threat Hunting Case Study: Uncovering Turla

CategoryDetailsThreat ActorsTurla (FSB's Center 16), Russia's state-sponsored cyber espionage groupCampaign OverviewFocused on cyber espionage, targeting…

A Look at Trending Chinese APT Techniques

CategoryDetailsChina's Global AmbitionsMilitary, technological, and economic powers driving its challenge to the global order, with…

APT trends Report Q3 2024

Category Details Threat Actor/Family Unknown, possibly linked to OceanLotus (APT32) but not conclusively attributed. Framework…

T-Mobile rebuffed breach attempts by hackers likely connected to China’s Salt Typhoon

Category Details Threat Actors Salt Typhoon (China-linked hacking campaign). Campaign Overview Attempted infiltration of T-Mobile…

RomCom Backdoor Attacks Use Zero-Day Exploits in Mozilla and Windows (CVE-2024-9680 & CVE-2024-49039)

AspectDetailsThreat ActorsRomCom, suspected ties to Russia, also known as Tropical Scorpius, Storm-0978, or UNC2596.Campaign OverviewExploited…

Perfctl Campaign Exploits Millions of Linux Servers for Crypto Mining and Proxyjacking

CategoryDetailsThreat ActorsPerfctl (undisclosed group behind the malware campaign targeting Linux servers).Campaign OverviewCampaign targeting Linux servers…

China’s Salt Typhoon hackers target telecom firms in Southeast Asia with new malware

Category Details Threat Actors Salt Typhoon (also referred to as Earth Estrie by Trend Micro).…

South Asian hackers target Pakistani entities in new espionage campaign

Category Details Threat Actors Mysterious Elephant (also tracked as APT-K-47), likely originating from South Asia.…

Perfctl Campaign Exploits Millions of Linux Servers for Crypto Mining and Proxyjacking

CategoryDetailsThreat ActorsPerfctl campaign (attributed to an unknown threat actor targeting Linux servers).Campaign OverviewExploits Linux servers…