2024-11-21 09:33 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Following the arrest in May 2024 of more than 20 individuals behind Facebook infostealers campaigns in Vietnam, we have compared the tactics of operators behind VietCredCare and DuckTail stealers. These 2 malware families have been active before the arrest in Vietnam and are believed to be controlled by Vietnamese threat actors. Based on the research, we decided that the groups operate in a different way and the arrest probably affected the VietCredCare operators.
P0
2024-10-17 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Rhetoric within the cybersecurity community has leaned heavily towards threat actor use of LOLBins as a means of “hiding amongst the noise” of normal, administrative and operational activity. However, as Huntress SOC analysts can attest, this is often far from the case.
P0
2024-10-03 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Join Huntress Threat Hunters as they unpack the password-spraying techniques of threat actors, exposing how they target everything from small businesses to giants like Microsoft.
P0
2024-09-20 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Tracking various indicators associated with different attacks, Huntress analysts have been able to identify specific indicators (threat actor workstation names, passwords associated with new user account creation or current account modification, CloudFlare tunnel tokens) that are associated with Akira ransomware infections. By detecting these indicators much earlier in the attack chain, organizations can inhibit or even obviate file encryption malware deployment.
P15
2024-09-17 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Threat actors have been successful in gaining entry using accounting software commonly used by construction companies.
P0
2024-08-28 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Huntress identified an intrusion against a non-profit supporting Vietnamese human rights that’s likely spanned years. Jump in as we provide a thorough analysis of this malicious threat actor.
P0
2024-07-25 05:58 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Specializing in AI-powered phishing-as-a-service and Android malware capable of intercepting OTP codes, the GXC Team targets Spanish bank users and 30 institutions worldwide
P0
2024-06-21 05:25 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Uncovering the operations of threat actor Boolka, driven by the creation of malicious scripts, malware trojans, sophisticated malware delivery platforms, and more.
P0
2024-05-30 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
In the cybersecurity community, we may hear analysts say, “Oh, threat actors change their tactics…”, and at times, they may include the word “always” as part of that statement. However, the question at hand is, “Does the data really show that to be the case?” What are we truly seeing in real-world incidents?
P0
2024-05-01 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Huntress has observed INC ransomware deployed in the past but recent activity indicates a possible continued shift in/or improvement of tactics employed by these threat actors.
P15
2024-04-01 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Threat actors have been using malicious versions of Advanced IP Scanner to compromise their targets via malvertising campaigns. Let’s analyze one.
P0
2024-03-28 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Huntress continues to see MSSQL server systems being attacked, and in recent incidents have seen overlap with previous incidents, not only in the use of LOLBins, but also in IP addresses used by the threat actor.
P0
2024-03-20 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Huntress recently detected interesting activity on an endpoint; a threat actor was attempting to establish a foothold on an endpoint by using commands issued via MSSQL to upload a reverse shell accessible from the web server. All attempts were obviated by MAV and process detections, but boy-howdy, did they try!
P0
2024-03-13 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
“Double extortion” attacks, often perpetrated by ransomware threat actors, include data exfiltration prior to file encryption. Huntress analysts have observed various means of data exfiltration, but recently observed the use of a legitimate backup application seen by others to be associated with a Noberus/ALPHV ransomware affiliate.
P15
2024-03-04 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Over the past year, the Huntress team has posted a number of blog posts related to remote monitoring and management (RMM) tools being installed or abused by threat actors.
P0
2024-02-08 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
In addition to social engineering attacks, threat actors target organizations' attack surface, looking for exposed services and applications to gain access into an infrastructure. Microsoft SQL database servers have long been a target for attackers.
P0
2023-12-14 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Huntress analysts recently observed a novel set of tactics, techniques, and procedures used by a threat actor for data collection and exfiltration.
P0
2023-11-28 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Threat actors frequently make use of native utilities during incidents. However, this blog post discusses a rarely-observed means of data exfiltration.
P0
2023-11-09 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Huntress has uncovered a series of unauthorized access, revealing a threat actor using ScreenConnect to infiltrate multiple healthcare organizations.
P0
2023-11-08 07:59 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Take a deep dive into the operations of one of the most active players in the Ransomware-as-a-Service market.
P15
2023-11-02 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
Amazon Managed Workflows for Apache Airflow (MWAA) and the Task instance details page in the Google Composer UI were not patched against CVE-2023-29247 (Stored XSS). This meant that post-authentication, a threat actor could have exploited this to store their JavaScript payload in the victim's managed Apache Airflow instance and run JavaScript on behalf of the victim (who could be an admin or another user with higher permissions than the threat actor, thereby leading to privilege escalation). Wi…
P15
2023-08-17 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Get an inside look at how threat actors use phishing and social engineering tactics to target users and infiltrate organizations.
P0
2023-08-11 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
The Huntress team investigated a ransomware attack of a new INC Ransom threat actor group. Here is the activity we observed.
P15
2023-08-03 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Dive into how Huntress caught a threat actor adding several legitimate email apps to maintain persistent access to a compromised Microsoft 365 environment.
P0
2023-06-08 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Explore the recent disclosures concerning Volt Typhoon, a threat actor engaged in the widespread exploitation of external-facing services and network appliances.
P0
2023-05-18 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
Threat actors in possession of IAM active credentials that had the power to update S3 bucket policies could have bypassed GuardDuty’s S3 detections and silently updated permissions for S3 resources, resulting in a bucket configuration that allowed anonymous data access. This gap in GuardDuty’s alert coverage occurred only when S3’s Block Public Access was not enabled on the account or the bucket, and when KMS-based server-side bucket encryption was not in use. In order to trigger on opening pub…
P0
2023-04-21 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
Google users can find and install third-party OAuth applications from Google Marketplace that are integrated with Google Workspace. Each OAuth application client in Google is associated with a GCP project. A bug in the way a GCP project enters a "pending deletion" state when deleted, could have allowed threat actors to make a malicious application invisible and unremovable from the user's account. If an attacker had managed to install an application in an account (e.g., through a phishing attac…
P0
2022-08-16 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
We unravel an investigation that details one way threat actors are able to gather cleartext passwords via NPPSPY.
P0
2021-10-22 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Huntress discovered threat actors abusing a blind SQL injection vulnerability in BillQuick Web Suite. Follow our analysis and latest findings in this blog.
P0
2021-04-05 08:45 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
The analysis of phishing campaigns carried out by a new threat actor
P0