Nimbus Manticore uses trojanized coding challenges to deploy NodeRabbit and PollCat RATs across Windows, Linux, and macOS.
WordlistLoader delivers Amatera via ClearFake ClickFix attacks, while SynkLoader uses Teams phishing to steal Windows login ...
Microsoft Threat Intelligence observed a human-operated intrusion campaign that abuses Microsoft Teams external collaboration to impersonate IT support, gain remote access, and deploy a Node.js-based ...
Threat actors are increasingly turning legitimate software into part of their attack chains. Instead of deploying an obviously malicious executable, attackers can abuse trusted tools that already have ...
Mirage2FA uses AiTM phishing to steal Microsoft 365 credentials and authenticated sessions, bypassing conventional MFA and ...
Russia GRU espionage campaign targeting NATO defense and diplomatic networks in Romania, Spain, and Turkey deployed the ...
Iran-linked operators are using a trusted developer tool to conceal a backdoor called Dindoor inside Windows environments. The malware uses the Deno JavaScript and TypeScript runtime to execute ...
MuddyWater-linked threat actors are using a backdoor named Dindoor that abuses the legitimate Deno runtime to execute ...
HexMage Magecart attacks 40+ online stores, using blockchain infrastructure to steal shoppers’ card details through malicious ...
Cybercriminals have found an unsettlingly clever use for blockchain’s most celebrated feature: immutability. A malware campaign identified by Microsoft Threat Intelligence is using smart contracts on ...
For most defenders, a phishing alert ends with a forced password change. Mirage2FA is built to make that response useless.
Some results have been hidden because they may be inaccessible to you
Show inaccessible results