#cryptocti — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #cryptocti, aggregated by home.social.
-
Windows AFD.sys Zero-Day Exploited by Lazarus Hackers to Gain SYSTEM Access
Pulse ID: 6a7e137d417182865191ce16
Pulse Link: https://otx.alienvault.com/pulse/6a7e137d417182865191ce16
Pulse Author: cryptocti
Created: 2026-08-13 18:57:01Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #InfoSec #Lazarus #OTX #OpenThreatExchange #Windows #ZeroDay #bot #cryptocti
-
Windows AFD.sys Zero-Day Exploited by Lazarus Hackers to Gain SYSTEM Access
Pulse ID: 6a7e137d417182865191ce16
Pulse Link: https://otx.alienvault.com/pulse/6a7e137d417182865191ce16
Pulse Author: cryptocti
Created: 2026-08-13 18:57:01Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #InfoSec #Lazarus #OTX #OpenThreatExchange #Windows #ZeroDay #bot #cryptocti
-
Unpatched Fortinet Devices Being Actively Exploited by Gunra Ransomware
Pulse ID: 6a7bad263a07942cb9b80c6a
Pulse Link: https://otx.alienvault.com/pulse/6a7bad263a07942cb9b80c6a
Pulse Author: cryptocti
Created: 2026-08-11 23:15:50Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #InfoSec #OTX #OpenThreatExchange #RansomWare #bot #cryptocti
-
Unpatched Fortinet Devices Being Actively Exploited by Gunra Ransomware
Pulse ID: 6a7bad263a07942cb9b80c6a
Pulse Link: https://otx.alienvault.com/pulse/6a7bad263a07942cb9b80c6a
Pulse Author: cryptocti
Created: 2026-08-11 23:15:50Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #InfoSec #OTX #OpenThreatExchange #RansomWare #bot #cryptocti
-
Fake Google Translate Chrome Extension Steals Browser Data and Enables Remote Control
-Fake Google Translate Chrome extension campaign targets browser users by stealing sensitive data and enabling remote control of Chrome sessions.
Pulse ID: 6a7b4100873ebae65e20a65c
Pulse Link: https://otx.alienvault.com/pulse/6a7b4100873ebae65e20a65c
Pulse Author: cryptocti
Created: 2026-08-11 15:34:24Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Browser #Chrome #ChromeExtension #CyberSecurity #Google #InfoSec #OTX #OpenThreatExchange #bot #cryptocti
-
Fake Google Translate Chrome Extension Steals Browser Data and Enables Remote Control
-Fake Google Translate Chrome extension campaign targets browser users by stealing sensitive data and enabling remote control of Chrome sessions.
Pulse ID: 6a7b4100873ebae65e20a65c
Pulse Link: https://otx.alienvault.com/pulse/6a7b4100873ebae65e20a65c
Pulse Author: cryptocti
Created: 2026-08-11 15:34:24Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Browser #Chrome #ChromeExtension #CyberSecurity #Google #InfoSec #OTX #OpenThreatExchange #bot #cryptocti
-
Gunra Ransomware Exploits Fortinet VPN Vulnerabilities to Gain Network Access and Bypass MFA
Gunra ransomware exploits known Fortinet VPN vulnerabilities to gain unauthorized access to enterprise networks and bypass multi-factor authentication.
Pulse ID: 6a7b418c9c13f8e6bf2c89c7
Pulse Link: https://otx.alienvault.com/pulse/6a7b418c9c13f8e6bf2c89c7
Pulse Author: cryptocti
Created: 2026-08-11 15:36:44Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #InfoSec #MFA #OTX #OpenThreatExchange #RansomWare #VPN #bot #cryptocti
-
Gunra Ransomware Exploits Fortinet VPN Vulnerabilities to Gain Network Access and Bypass MFA
Gunra ransomware exploits known Fortinet VPN vulnerabilities to gain unauthorized access to enterprise networks and bypass multi-factor authentication.
Pulse ID: 6a7b418c9c13f8e6bf2c89c7
Pulse Link: https://otx.alienvault.com/pulse/6a7b418c9c13f8e6bf2c89c7
Pulse Author: cryptocti
Created: 2026-08-11 15:36:44Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #InfoSec #MFA #OTX #OpenThreatExchange #RansomWare #VPN #bot #cryptocti
-
Interlock Ransomware Abuses Forensic Tools for Credential Theft
Interlock ransomware uses ClickFix social engineering and legitimate
forensic tools to compromise networks. Attackers abuse Volatility3 and
WinPmem for credential theft perform Kerberoasting, establish
persistence, move laterally, exfiltrate data and deploy ransomware for
double extortion.Pulse ID: 6a79c66917a813aade9856bf
Pulse Link: https://otx.alienvault.com/pulse/6a79c66917a813aade9856bf
Pulse Author: cryptocti
Created: 2026-08-10 12:39:05Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #Extortion #InfoSec #NPM #OTX #OpenThreatExchange #RAT #RansomWare #SocialEngineering #bot #cryptocti
-
Interlock Ransomware Abuses Forensic Tools for Credential Theft
Interlock ransomware uses ClickFix social engineering and legitimate
forensic tools to compromise networks. Attackers abuse Volatility3 and
WinPmem for credential theft perform Kerberoasting, establish
persistence, move laterally, exfiltrate data and deploy ransomware for
double extortion.Pulse ID: 6a79c66917a813aade9856bf
Pulse Link: https://otx.alienvault.com/pulse/6a79c66917a813aade9856bf
Pulse Author: cryptocti
Created: 2026-08-10 12:39:05Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #Extortion #InfoSec #NPM #OTX #OpenThreatExchange #RAT #RansomWare #SocialEngineering #bot #cryptocti
-
Greatness PhaaS Steals Microsoft 365 Tokens Despite MFA
The Greatness Phishing-as-a-Service platform uses Adversary-in-the-Middle
and device-code phishing to steal Microsoft 365 authentication tokens and
bypass MFA. Active campaigns exploit trusted sender configurations and
phishing lures to compromise accounts. Stolen tokens enable attackers to
access Outlook, Teams, SharePoint and OneDrive while evading
conventional authentication-based security controls.Pulse ID: 6a79bef48cee5cb15fd34fd2
Pulse Link: https://otx.alienvault.com/pulse/6a79bef48cee5cb15fd34fd2
Pulse Author: cryptocti
Created: 2026-08-10 12:07:16Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#AdversaryInTheMiddle #CyberSecurity #EDR #InfoSec #MFA #Microsoft #OTX #OpenThreatExchange #Outlook #Phishing #RAT #Rust #bot #cryptocti
-
Greatness PhaaS Steals Microsoft 365 Tokens Despite MFA
The Greatness Phishing-as-a-Service platform uses Adversary-in-the-Middle
and device-code phishing to steal Microsoft 365 authentication tokens and
bypass MFA. Active campaigns exploit trusted sender configurations and
phishing lures to compromise accounts. Stolen tokens enable attackers to
access Outlook, Teams, SharePoint and OneDrive while evading
conventional authentication-based security controls.Pulse ID: 6a79bef48cee5cb15fd34fd2
Pulse Link: https://otx.alienvault.com/pulse/6a79bef48cee5cb15fd34fd2
Pulse Author: cryptocti
Created: 2026-08-10 12:07:16Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#AdversaryInTheMiddle #CyberSecurity #EDR #InfoSec #MFA #Microsoft #OTX #OpenThreatExchange #Outlook #Phishing #RAT #Rust #bot #cryptocti
-
BdThemes Supply Chain Attack Compromises WordPress via Poisoned API
Pulse ID: 6a785c94a880b6c45e4905cd
Pulse Link: https://otx.alienvault.com/pulse/6a785c94a880b6c45e4905cd
Pulse Author: cryptocti
Created: 2026-08-09 10:55:16Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #InfoSec #OTX #OpenThreatExchange #RDP #SupplyChain #Word #Wordpress #bot #cryptocti
-
BdThemes Supply Chain Attack Compromises WordPress via Poisoned API
Pulse ID: 6a785c94a880b6c45e4905cd
Pulse Link: https://otx.alienvault.com/pulse/6a785c94a880b6c45e4905cd
Pulse Author: cryptocti
Created: 2026-08-09 10:55:16Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #InfoSec #OTX #OpenThreatExchange #RDP #SupplyChain #Word #Wordpress #bot #cryptocti
-
ClickFix macOS Campaign Evolves Into Crypto-Draining Attack
A ClickFix-based macOS malware campaign targets users by tricking them
into executing malicious Terminal commands that deploy a Go-based
stealer. The malware steals browser credentials, Apple Keychain data and
cryptocurrency assets by exfiltrating sensitive information and draining
targeted wallets.Pulse ID: 6a7711519a15c9288e8ef74c
Pulse Link: https://otx.alienvault.com/pulse/6a7711519a15c9288e8ef74c
Pulse Author: cryptocti
Created: 2026-08-08 11:21:53Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Browser #CyberSecurity #InfoSec #Mac #MacOS #Malware #OTX #OpenThreatExchange #RAT #bot #cryptocurrency #cryptocti
-
ClickFix macOS Campaign Evolves Into Crypto-Draining Attack
A ClickFix-based macOS malware campaign targets users by tricking them
into executing malicious Terminal commands that deploy a Go-based
stealer. The malware steals browser credentials, Apple Keychain data and
cryptocurrency assets by exfiltrating sensitive information and draining
targeted wallets.Pulse ID: 6a7711519a15c9288e8ef74c
Pulse Link: https://otx.alienvault.com/pulse/6a7711519a15c9288e8ef74c
Pulse Author: cryptocti
Created: 2026-08-08 11:21:53Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Browser #CyberSecurity #InfoSec #Mac #MacOS #Malware #OTX #OpenThreatExchange #RAT #bot #cryptocurrency #cryptocti
-
ClickFix macOS Campaign Evolves Into Crypto-Draining Attack
A ClickFix-based macOS malware campaign targets users by tricking them
into executing malicious Terminal commands that deploy a Go-based
stealer. The malware steals browser credentials, Apple Keychain data and
cryptocurrency assets by exfiltrating sensitive information and draining
targeted wallets.Pulse ID: 6a7711a399480a065d07328a
Pulse Link: https://otx.alienvault.com/pulse/6a7711a399480a065d07328a
Pulse Author: cryptocti
Created: 2026-08-08 11:23:15Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Browser #CyberSecurity #InfoSec #Mac #MacOS #Malware #OTX #OpenThreatExchange #RAT #bot #cryptocurrency #cryptocti
-
ClickFix macOS Campaign Evolves Into Crypto-Draining Attack
A ClickFix-based macOS malware campaign targets users by tricking them
into executing malicious Terminal commands that deploy a Go-based
stealer. The malware steals browser credentials, Apple Keychain data and
cryptocurrency assets by exfiltrating sensitive information and draining
targeted wallets.Pulse ID: 6a7711a399480a065d07328a
Pulse Link: https://otx.alienvault.com/pulse/6a7711a399480a065d07328a
Pulse Author: cryptocti
Created: 2026-08-08 11:23:15Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Browser #CyberSecurity #InfoSec #Mac #MacOS #Malware #OTX #OpenThreatExchange #RAT #bot #cryptocurrency #cryptocti
-
ClickFix macOS Campaign Evolves Into Crypto-Draining Attack
A ClickFix-based macOS malware campaign targets users by tricking them
into executing malicious Terminal commands that deploy a Go-based
stealer. The malware steals browser credentials, Apple Keychain data and
cryptocurrency assets by exfiltrating sensitive information and draining
targeted wallets.Pulse ID: 6a7711d2858b75d5a5d2a891
Pulse Link: https://otx.alienvault.com/pulse/6a7711d2858b75d5a5d2a891
Pulse Author: cryptocti
Created: 2026-08-08 11:24:02Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Browser #CyberSecurity #InfoSec #Mac #MacOS #Malware #OTX #OpenThreatExchange #RAT #bot #cryptocurrency #cryptocti
-
ClickFix macOS Campaign Evolves Into Crypto-Draining Attack
A ClickFix-based macOS malware campaign targets users by tricking them
into executing malicious Terminal commands that deploy a Go-based
stealer. The malware steals browser credentials, Apple Keychain data and
cryptocurrency assets by exfiltrating sensitive information and draining
targeted wallets.Pulse ID: 6a7711d2858b75d5a5d2a891
Pulse Link: https://otx.alienvault.com/pulse/6a7711d2858b75d5a5d2a891
Pulse Author: cryptocti
Created: 2026-08-08 11:24:02Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Browser #CyberSecurity #InfoSec #Mac #MacOS #Malware #OTX #OpenThreatExchange #RAT #bot #cryptocurrency #cryptocti
-
ChainDrop npm Supply Chain Worm Attack Target Developers and CI/CD Environments
Pulse ID: 6a76817228e67b24b4fb3e61
Pulse Link: https://otx.alienvault.com/pulse/6a76817228e67b24b4fb3e61
Pulse Author: cryptocti
Created: 2026-08-08 01:08:02Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #InfoSec #NPM #OTX #OpenThreatExchange #SupplyChain #Worm #bot #developers #cryptocti
-
ChainDrop npm Supply Chain Worm Attack Target Developers and CI/CD Environments
Pulse ID: 6a76817228e67b24b4fb3e61
Pulse Link: https://otx.alienvault.com/pulse/6a76817228e67b24b4fb3e61
Pulse Author: cryptocti
Created: 2026-08-08 01:08:02Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #InfoSec #NPM #OTX #OpenThreatExchange #SupplyChain #Worm #bot #developers #cryptocti
-
August 07th, 2026 - CryptoGen Cyber Threat Intelligence Advisory #10315 - Threat Actors Abuse ScreenConnect RMM Through Fake Update Lures
Pulse ID: 6a75cfdd295a0a6f2abf9827
Pulse Link: https://otx.alienvault.com/pulse/6a75cfdd295a0a6f2abf9827
Pulse Author: cryptocti
Created: 2026-08-07 12:30:21Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CryptoGen #CyberSecurity #InfoSec #OTX #OpenThreatExchange #ScreenConnect #bot #cryptocti
-
August 07th, 2026 - CryptoGen Cyber Threat Intelligence Advisory #10315 - Threat Actors Abuse ScreenConnect RMM Through Fake Update Lures
Pulse ID: 6a75cfdd295a0a6f2abf9827
Pulse Link: https://otx.alienvault.com/pulse/6a75cfdd295a0a6f2abf9827
Pulse Author: cryptocti
Created: 2026-08-07 12:30:21Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CryptoGen #CyberSecurity #InfoSec #OTX #OpenThreatExchange #ScreenConnect #bot #cryptocti
-
Python Based Malware Vanta Stealer Targeting Credentials, Wallets and Digital Assets
Pulse ID: 6a74e24eaa6d5add8f8db213
Pulse Link: https://otx.alienvault.com/pulse/6a74e24eaa6d5add8f8db213
Pulse Author: cryptocti
Created: 2026-08-06 19:36:46Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #InfoSec #Malware #OTX #OpenThreatExchange #Python #bot #cryptocti
-
Python Based Malware Vanta Stealer Targeting Credentials, Wallets and Digital Assets
Pulse ID: 6a74e24eaa6d5add8f8db213
Pulse Link: https://otx.alienvault.com/pulse/6a74e24eaa6d5add8f8db213
Pulse Author: cryptocti
Created: 2026-08-06 19:36:46Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #InfoSec #Malware #OTX #OpenThreatExchange #Python #bot #cryptocti
-
ClickFix Campaign Targets macOS Users with Atomic Stealer Malware
A macOS ClickFix campaign spanning over 250 domains now uses browser fingerprinting to hide its fake "Download for macOS" lure from crawlers and researchers, while still serving it to genuine Mac users who are tricked into running a Terminal command that deploys the AMOS infostealer.
Pulse ID: 6a74853991cc8881d222ead0
Pulse Link: https://otx.alienvault.com/pulse/6a74853991cc8881d222ead0
Pulse Author: cryptocti
Created: 2026-08-06 12:59:37Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#AMOS #Atomic #AtomicStealer #Browser #CyberSecurity #InfoSec #InfoStealer #Mac #MacOS #Malware #OTX #OpenThreatExchange #bot #cryptocti
-
ClickFix Campaign Targets macOS Users with Atomic Stealer Malware
A macOS ClickFix campaign spanning over 250 domains now uses browser fingerprinting to hide its fake "Download for macOS" lure from crawlers and researchers, while still serving it to genuine Mac users who are tricked into running a Terminal command that deploys the AMOS infostealer.
Pulse ID: 6a74853991cc8881d222ead0
Pulse Link: https://otx.alienvault.com/pulse/6a74853991cc8881d222ead0
Pulse Author: cryptocti
Created: 2026-08-06 12:59:37Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#AMOS #Atomic #AtomicStealer #Browser #CyberSecurity #InfoSec #InfoStealer #Mac #MacOS #Malware #OTX #OpenThreatExchange #bot #cryptocti
-
Fake Roblox Xeno Script Launcher Delivers Infostealer and RAT Malware
Pulse ID: 6a7128ea99c82f99828f4a7b
Pulse Link: https://otx.alienvault.com/pulse/6a7128ea99c82f99828f4a7b
Pulse Author: cryptocti
Created: 2026-08-03 23:48:58Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #InfoSec #InfoStealer #Malware #OTX #OpenThreatExchange #RAT #bot #cryptocti
-
Fake Roblox Xeno Script Launcher Delivers Infostealer and RAT Malware
Pulse ID: 6a7128ea99c82f99828f4a7b
Pulse Link: https://otx.alienvault.com/pulse/6a7128ea99c82f99828f4a7b
Pulse Author: cryptocti
Created: 2026-08-03 23:48:58Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #InfoSec #InfoStealer #Malware #OTX #OpenThreatExchange #RAT #bot #cryptocti
-
Android RAT Uses Fake Government Alert App to Steal Victim Data
Pulse ID: 6a70eeef45a56554c8996059
Pulse Link: https://otx.alienvault.com/pulse/6a70eeef45a56554c8996059
Pulse Author: cryptocti
Created: 2026-08-03 19:41:35Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Android #CyberSecurity #Government #InfoSec #OTX #OpenThreatExchange #RAT #bot #cryptocti
-
Android RAT Uses Fake Government Alert App to Steal Victim Data
Pulse ID: 6a70eeef45a56554c8996059
Pulse Link: https://otx.alienvault.com/pulse/6a70eeef45a56554c8996059
Pulse Author: cryptocti
Created: 2026-08-03 19:41:35Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Android #CyberSecurity #Government #InfoSec #OTX #OpenThreatExchange #RAT #bot #cryptocti
-
MacSync RAT Targets macOS Credentials and Cryptocurrency Wallets
MacSync is a macOS information stealer and a Remote Access Trojan distributed through malicious Google Ads and Claude AI shared conversations. Victims are tricked into executing Terminal commands that deploy malware to steals credentials, cryptocurrency wallets and establish persistent remote access.
Pulse ID: 6a708422cc9833fb7a2ec3f9
Pulse Link: https://otx.alienvault.com/pulse/6a708422cc9833fb7a2ec3f9
Pulse Author: cryptocti
Created: 2026-08-03 12:05:54Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #Google #GoogleAds #InfoSec #Mac #MacOS #Malware #OTX #OpenThreatExchange #RAT #RemoteAccessTrojan #Trojan #bot #cryptocurrency #cryptocti
-
MacSync RAT Targets macOS Credentials and Cryptocurrency Wallets
MacSync is a macOS information stealer and a Remote Access Trojan distributed through malicious Google Ads and Claude AI shared conversations. Victims are tricked into executing Terminal commands that deploy malware to steals credentials, cryptocurrency wallets and establish persistent remote access.
Pulse ID: 6a708422cc9833fb7a2ec3f9
Pulse Link: https://otx.alienvault.com/pulse/6a708422cc9833fb7a2ec3f9
Pulse Author: cryptocti
Created: 2026-08-03 12:05:54Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #Google #GoogleAds #InfoSec #Mac #MacOS #Malware #OTX #OpenThreatExchange #RAT #RemoteAccessTrojan #Trojan #bot #cryptocurrency #cryptocti
-
BlackTech BlueShell Backdoor Campaign Targeting Linux Servers
A BlackTech APT campaign has been observed targeting Japanese organizations by deploying the BlueShell Linux backdoor, allowing attackers to maintain remote access, execute commands, transfer files and perform stealthy post-compromise activities within compromised networks.
Pulse ID: 6a6f9dbbb32232ff774c69fa
Pulse Link: https://otx.alienvault.com/pulse/6a6f9dbbb32232ff774c69fa
Pulse Author: cryptocti
Created: 2026-08-02 19:42:51Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#BackDoor #CyberSecurity #InfoSec #Japan #Linux #OTX #OpenThreatExchange #bot #cryptocti
-
BlackTech BlueShell Backdoor Campaign Targeting Linux Servers
A BlackTech APT campaign has been observed targeting Japanese organizations by deploying the BlueShell Linux backdoor, allowing attackers to maintain remote access, execute commands, transfer files and perform stealthy post-compromise activities within compromised networks.
Pulse ID: 6a6f9dbbb32232ff774c69fa
Pulse Link: https://otx.alienvault.com/pulse/6a6f9dbbb32232ff774c69fa
Pulse Author: cryptocti
Created: 2026-08-02 19:42:51Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#BackDoor #CyberSecurity #InfoSec #Japan #Linux #OTX #OpenThreatExchange #bot #cryptocti
-
Microsoft Teams Vishing Campaign Leads to Chaos Ransomware Deployment
STAC4749 is a financially motivated Teams-based vishing campaign in which attackers impersonate IT support to gain remote access through Quick Assist or RemSupp. They then deploy malware, establish persistence, move laterally, and ultimately deploy Chaos ransomware.
Pulse ID: 6a6ca07a1a3d8bfabd6d9941
Pulse Link: https://otx.alienvault.com/pulse/6a6ca07a1a3d8bfabd6d9941
Pulse Author: cryptocti
Created: 2026-07-31 13:17:46Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #InfoSec #Malware #Microsoft #MicrosoftTeams #OTX #OpenThreatExchange #RansomWare #bot #cryptocti
-
Microsoft Teams Vishing Campaign Leads to Chaos Ransomware Deployment
STAC4749 is a financially motivated Teams-based vishing campaign in which attackers impersonate IT support to gain remote access through Quick Assist or RemSupp. They then deploy malware, establish persistence, move laterally, and ultimately deploy Chaos ransomware.
Pulse ID: 6a6ca07a1a3d8bfabd6d9941
Pulse Link: https://otx.alienvault.com/pulse/6a6ca07a1a3d8bfabd6d9941
Pulse Author: cryptocti
Created: 2026-07-31 13:17:46Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #InfoSec #Malware #Microsoft #MicrosoftTeams #OTX #OpenThreatExchange #RansomWare #bot #cryptocti
-
OWAReaper Malware Campaign Targeting Exchange OWA
Pulse ID: 6a6b9284e0ed69a14c94a57c
Pulse Link: https://otx.alienvault.com/pulse/6a6b9284e0ed69a14c94a57c
Pulse Author: cryptocti
Created: 2026-07-30 18:05:56Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #InfoSec #Malware #OTX #OpenThreatExchange #bot #cryptocti
-
OWAReaper Malware Campaign Targeting Exchange OWA
Pulse ID: 6a6b9284e0ed69a14c94a57c
Pulse Link: https://otx.alienvault.com/pulse/6a6b9284e0ed69a14c94a57c
Pulse Author: cryptocti
Created: 2026-07-30 18:05:56Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #InfoSec #Malware #OTX #OpenThreatExchange #bot #cryptocti
-
Microsoft Teams Vishing Campaign Abuses Quick Assist to Deploy GoGRPC Backdoor
Microsoft Teams vishing campaign targeting enterprises between January and June 2026. Attackers use email bombing, Teams impersonation and Quick Assist to deploy the GoGRPC backdoor, enabling ersistent access, reconnaissance and potential ransomware or extortion through compromised enterprise networks.
Pulse ID: 6a693ba0eaf729fe7f4805da
Pulse Link: https://otx.alienvault.com/pulse/6a693ba0eaf729fe7f4805da
Pulse Author: cryptocti
Created: 2026-07-28 23:30:40Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#BackDoor #CyberSecurity #Email #Extortion #InfoSec #Microsoft #MicrosoftTeams #OTX #OpenThreatExchange #RPC #RansomWare #bot #cryptocti
-
Microsoft Teams Vishing Campaign Abuses Quick Assist to Deploy GoGRPC Backdoor
Microsoft Teams vishing campaign targeting enterprises between January and June 2026. Attackers use email bombing, Teams impersonation and Quick Assist to deploy the GoGRPC backdoor, enabling ersistent access, reconnaissance and potential ransomware or extortion through compromised enterprise networks.
Pulse ID: 6a693ba0eaf729fe7f4805da
Pulse Link: https://otx.alienvault.com/pulse/6a693ba0eaf729fe7f4805da
Pulse Author: cryptocti
Created: 2026-07-28 23:30:40Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#BackDoor #CyberSecurity #Email #Extortion #InfoSec #Microsoft #MicrosoftTeams #OTX #OpenThreatExchange #RPC #RansomWare #bot #cryptocti
-
NadMesh Botnet Targets AI and Cloud Infrastructure
Pulse ID: 6a64a9954c20b3eb7ba237be
Pulse Link: https://otx.alienvault.com/pulse/6a64a9954c20b3eb7ba237be
Pulse Author: cryptocti
Created: 2026-07-25 12:18:29Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Cloud #CyberSecurity #InfoSec #OTX #OpenThreatExchange #bot #botnet #cryptocti
-
NadMesh Botnet Targets AI and Cloud Infrastructure
Pulse ID: 6a64a9954c20b3eb7ba237be
Pulse Link: https://otx.alienvault.com/pulse/6a64a9954c20b3eb7ba237be
Pulse Author: cryptocti
Created: 2026-07-25 12:18:29Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Cloud #CyberSecurity #InfoSec #OTX #OpenThreatExchange #bot #botnet #cryptocti
-
ChonkyChicken Steals Browser Credentials and Conducts Victim Surveillance
ChonkyChicken is a modular Windows remote access trojan built for credential theft and long term surveillance. It can hijack active browser sessions and explore internal networks.
Pulse ID: 6a63fbea209182be9a2d07d8
Pulse Link: https://otx.alienvault.com/pulse/6a63fbea209182be9a2d07d8
Pulse Author: cryptocti
Created: 2026-07-24 23:57:30Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Browser #CyberSecurity #InfoSec #OTX #OpenThreatExchange #RemoteAccessTrojan #Trojan #Windows #bot #cryptocti
-
ChonkyChicken Steals Browser Credentials and Conducts Victim Surveillance
ChonkyChicken is a modular Windows remote access trojan built for credential theft and long term surveillance. It can hijack active browser sessions and explore internal networks.
Pulse ID: 6a63fbea209182be9a2d07d8
Pulse Link: https://otx.alienvault.com/pulse/6a63fbea209182be9a2d07d8
Pulse Author: cryptocti
Created: 2026-07-24 23:57:30Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Browser #CyberSecurity #InfoSec #OTX #OpenThreatExchange #RemoteAccessTrojan #Trojan #Windows #bot #cryptocti
-
msaRAT Ransomware Routes C2 Traffics Through Headless Browsers
Chaos ransomware group uses the Rust-based msaRAT implant to conceal C2
communications through headless Chrome or Edge browsers, Chrome
DevTools Protocol, Cloudflare Workers and WebRTC.Pulse ID: 6a636223b470c7200c1cfac1
Pulse Link: https://otx.alienvault.com/pulse/6a636223b470c7200c1cfac1
Pulse Author: cryptocti
Created: 2026-07-24 13:01:23Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Browser #Chrome #Cloud #CyberSecurity #Edge #ICS #InfoSec #OTX #OpenThreatExchange #RAT #RansomWare #Rust #bot #cryptocti
-
msaRAT Ransomware Routes C2 Traffics Through Headless Browsers
Chaos ransomware group uses the Rust-based msaRAT implant to conceal C2
communications through headless Chrome or Edge browsers, Chrome
DevTools Protocol, Cloudflare Workers and WebRTC.Pulse ID: 6a636223b470c7200c1cfac1
Pulse Link: https://otx.alienvault.com/pulse/6a636223b470c7200c1cfac1
Pulse Author: cryptocti
Created: 2026-07-24 13:01:23Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Browser #Chrome #Cloud #CyberSecurity #Edge #ICS #InfoSec #OTX #OpenThreatExchange #RAT #RansomWare #Rust #bot #cryptocti
-
Email Theft Campaign Exploits Zimbra Zero-Click Flaw
Pulse ID: 6a630d8195ebe8af82f8ade3
Pulse Link: https://otx.alienvault.com/pulse/6a630d8195ebe8af82f8ade3
Pulse Author: cryptocti
Created: 2026-07-24 07:00:17Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #Email #InfoSec #OTX #OpenThreatExchange #Zimbra #bot #cryptocti
-
Email Theft Campaign Exploits Zimbra Zero-Click Flaw
Pulse ID: 6a630d8195ebe8af82f8ade3
Pulse Link: https://otx.alienvault.com/pulse/6a630d8195ebe8af82f8ade3
Pulse Author: cryptocti
Created: 2026-07-24 07:00:17Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #Email #InfoSec #OTX #OpenThreatExchange #Zimbra #bot #cryptocti
-
Distributed cPanel and WHM Exploitation Campaign
Pulse ID: 6a62800a266612e507dd042e
Pulse Link: https://otx.alienvault.com/pulse/6a62800a266612e507dd042e
Pulse Author: cryptocti
Created: 2026-07-23 20:56:42Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #InfoSec #OTX #OpenThreatExchange #bot #cryptocti
-
Distributed cPanel and WHM Exploitation Campaign
Pulse ID: 6a62800a266612e507dd042e
Pulse Link: https://otx.alienvault.com/pulse/6a62800a266612e507dd042e
Pulse Author: cryptocti
Created: 2026-07-23 20:56:42Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #InfoSec #OTX #OpenThreatExchange #bot #cryptocti
-
Fake Game Campaign Spreads Amatera Stealer Through Malicious RenPy Installers
Pulse ID: 6a60bf172ede7825ba7a6f5f
Pulse Link: https://otx.alienvault.com/pulse/6a60bf172ede7825ba7a6f5f
Pulse Author: cryptocti
Created: 2026-07-22 13:01:11Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #InfoSec #OTX #OpenThreatExchange #bot #cryptocti
-
Fake Game Campaign Spreads Amatera Stealer Through Malicious RenPy Installers
Pulse ID: 6a60bf172ede7825ba7a6f5f
Pulse Link: https://otx.alienvault.com/pulse/6a60bf172ede7825ba7a6f5f
Pulse Author: cryptocti
Created: 2026-07-22 13:01:11Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #InfoSec #OTX #OpenThreatExchange #bot #cryptocti
-
FakeGit Campaign Spreads SmartLoader Through Malicious GitHub Repositories
The FakeGit campaign uses fake GitHub repositories to distribute
SmartLoader malware.Pulse ID: 6a5f68a45f22eb75b3c0f6f3
Pulse Link: https://otx.alienvault.com/pulse/6a5f68a45f22eb75b3c0f6f3
Pulse Author: cryptocti
Created: 2026-07-21 12:40:04Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #GitHub #InfoSec #Malware #OTX #OpenThreatExchange #bot #cryptocti
-
FakeGit Campaign Spreads SmartLoader Through Malicious GitHub Repositories
The FakeGit campaign uses fake GitHub repositories to distribute
SmartLoader malware.Pulse ID: 6a5f68a45f22eb75b3c0f6f3
Pulse Link: https://otx.alienvault.com/pulse/6a5f68a45f22eb75b3c0f6f3
Pulse Author: cryptocti
Created: 2026-07-21 12:40:04Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #GitHub #InfoSec #Malware #OTX #OpenThreatExchange #bot #cryptocti
-
HollowGraph Malware Hides C2 Traffic in Microsoft 365 Calendar
HOLLOWGRAPH malware hides command-and-control and stolen data
inside Microsoft 365 calendar events dated 2050 that using legitimate
Graph API traffic to evade detection. It also uses DNS tunneling to refresh
stolen Entra ID credentials.Pulse ID: 6a5f68e3afd0e1db35d5a244
Pulse Link: https://otx.alienvault.com/pulse/6a5f68e3afd0e1db35d5a244
Pulse Author: cryptocti
Created: 2026-07-21 12:41:07Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #DNS #InfoSec #Malware #Microsoft #OTX #OpenThreatExchange #bot #cryptocti
-
HollowGraph Malware Hides C2 Traffic in Microsoft 365 Calendar
HOLLOWGRAPH malware hides command-and-control and stolen data
inside Microsoft 365 calendar events dated 2050 that using legitimate
Graph API traffic to evade detection. It also uses DNS tunneling to refresh
stolen Entra ID credentials.Pulse ID: 6a5f68e3afd0e1db35d5a244
Pulse Link: https://otx.alienvault.com/pulse/6a5f68e3afd0e1db35d5a244
Pulse Author: cryptocti
Created: 2026-07-21 12:41:07Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #DNS #InfoSec #Malware #Microsoft #OTX #OpenThreatExchange #bot #cryptocti
-
ClickFix Fake CAPTCHAs to Infect Devices with Malware
Pulse ID: 6a5e10f2c39aa45f2dec8da1
Pulse Link: https://otx.alienvault.com/pulse/6a5e10f2c39aa45f2dec8da1
Pulse Author: cryptocti
Created: 2026-07-20 12:13:38Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CAPTCHA #CyberSecurity #InfoSec #Malware #OTX #OpenThreatExchange #bot #cryptocti
-
ClickFix Fake CAPTCHAs to Infect Devices with Malware
Pulse ID: 6a5e10f2c39aa45f2dec8da1
Pulse Link: https://otx.alienvault.com/pulse/6a5e10f2c39aa45f2dec8da1
Pulse Author: cryptocti
Created: 2026-07-20 12:13:38Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CAPTCHA #CyberSecurity #InfoSec #Malware #OTX #OpenThreatExchange #bot #cryptocti