Topic
Threat Intelligence

CTI Roundup: Google AMP & Salesforce Exploited for Phishing Attacks
Threat actors abuse Google AMP for evasive phishing attacks, hackers exploit Salesforce’s email services in targeted Facebook phishing campaign, and Russian actor BlueCharlie alters infrastructure in response to disclosures.

CTI Roundup: Realst Malware targets MacOS, Infostealer Malware Sees Exponential Growth
Realst malware targets macOS Sonoma ahead of public release, infostealer malware sees exponential growth, and new Nitrogen malware spreads via Google Ads for ransomware attacks.

CTI Roundup: Ransomware Impersonates Cybersecurity Firm, Espionage Tactics Evolve in China
Ransomware impersonates Sophos, FIN8 group uses modified backdoor to deliver BlackCat ransomware, and Chinese espionage actors continue to evolve.

CTI Roundup: Attacks Spike in 2023, Ransomware Payments Skyrocket
USB-based malware attacks spike during the first half of 2023, ransomware payments skyrocket, and Big Head ransomware accelerates.

CTI Roundup: Truebot infects US & Canada networks
Truebot infects networks throughout the US and Canada, Charming Kitten targets new operating systems, and SmugX targets European government entities.

CTI Roundup: North Korean Andariel Group Strikes With EarlyRat Malware
8Base ransomware activity spikes, China-linked Volt Typhoon APT uses novel tradecraft to gain initial access to target networks, and North Korean hacker group Andariel strikes with new EarlyRat malware.

CTI Roundup: New DoJ Cyber Unit Pursues State-Sponsored Threats
The DoJ launches a cyber unit to prosecute nation-state threat actors, cybercriminals use expired AWS S3 buckets to distribute malicious code, and a new exfiltration malware targets RDP workloads.

CTI Roundup: Skuld Malware Steals Discord Data From Windows PCs
Chinese hackers use DNS-over-HTTPS for Linux malware communication, a new Golang-based Skuld malware strand steals Discord and browser data from Windows PCs, and a massive phishing campaign uses 6,000 sites to impersonate brands.

CTI Roundup: North Korea’s Kimsuky Cyber Spies at it Again
Washington and Seoul expose North Korea’s Kimsuky cyber spies, the Asylum Ambuscade crimeware group conducts cyberespionage, and the Cyclops ransomware and stealer combo poses a dual threat.

CTI Roundup: Microsoft Finds a macOS Bug That Lets Hackers Bypass SIP Root Restrictions
Improved BlackCat ransomware variant strikes with lightning speed in stealthier attacks, Microsoft finds a macOS bug that lets hackers bypass SIP root restrictions, and Dark Pink hackers continue to target government and military organizations.

CTI Roundup: Russia, Iran, & North Korea Target Global SMBs
State-aligned threat actors target global SMBs, new PowerExchange malware backdoors Microsoft Exchange servers, and an IT security employee attempts to impersonate a ransomware gang during an attack on his own company.

CTI Roundup: Hackers target macOS systems with Cobalt Strike
Hackers use Golang variant of Cobalt Strike to target macOS systems, Cybercriminals adapt to Microsoft’s macro-blocking feature, and cybercriminals target the Microsoft VSCode Marketplace.