Skip to main content
FreeIntelHub
Feed Threat Feed Search Trending
Intelligence CVE Priority Vulnerability IOC Lookup IOC Feed YARA Rules Phishing Lookup Exploit Lookup Pastes Dark Web
Adversaries Threat Groups Software Campaigns
Explore Dashboard Geo Map Heatmap MITRE ATT&CK
Browse Sources Vendors Categories Sectors
RSS API
FreeIntelHub
/
Sign In

TTPs

20 articles

Help Net Security TTPs 2d ago

Websites can spy on user activity by analyzing SSD behavior

Websites have spent years collecting information about visitors through browser fingerprinting, tracking scripts, and other techniques designed to identify d...

T1592

Help Net Security →

CSO Online TTPs 2d ago

Cybersecurity trends in SEC filings

In 2023, the Securities and Exchange Commission (SEC) required public companies to include a new section in their 10-K annual filings that is devoted to cybe...

CSO Online →

The Hacker News TTPs Cisco 2d ago

Kimsuky Deploys HTTPSpy, Expands Arsenal with HelloDoor and VS Code Tunnels

The North Korean state-sponsored threat actor known as Kimsuky (aka Velvet Chollima) has been attributed to a fresh set of cyber attacks targeting South Kore...

T1204

The Hacker News →

GBHackers TTPs Microsoft VMware 2d ago

Malicious RVTools Installer Uses Sectigo Cert to Evade SmartScreen

A malicious fake RVTools installer is abusing a legitimately issued Sectigo code‑signing certificate to slip past Microsoft Defender SmartScreen and many end...

T1592

GBHackers →

GBHackers TTPs 3d ago

ClearFake Abuses BSC Testnet Contracts for Resilient C2 Operations

Threat actors behind the ClearFake campaign have adopted a novel and highly resilient command-and-control (C2) architecture by leveraging BNB Smart Chain (BS...

GBHackers →

The Hacker News TTPs Apple 3d ago

JINX-0164 Targets Cryptocurrency Firms with Fake Recruiter Lures and macOS Malware

A new campaign orchestrated by a previously undocumented threat actor has targeted cryptocurrency organizations with an aim to facilitate digital asset theft...

T1204

The Hacker News →

Help Net Security TTPs Intel 3d ago

XM Cyber enhances identity risk visibility with continuous exposure management capabilities

XM Cyber has announced platform enhancements aimed at helping organizations reduce identity risk, compounded by AI-enabled attackers. According to Gartner, “...

T1021

Help Net Security →

GBHackers TTPs 3d ago

New PureLogs Variant Abuses MSBuild to Evade Detection

A new phishing-driven malware campaign distributing a stealthy PureLogs variant that leverages advanced evasion techniques, including process hollowing via M...

T1566 T1027

GBHackers →

Help Net Security TTPs 3d ago

Hackers are knocking on office doors pretending to be IT staff

The Silent Ransom Group (SRG) is targeting law firms using social engineering techniques and an unusual tactic for cybercriminals: showing up at victims’ off...

T1204

Help Net Security →

BleepingComputer TTPs 3d ago

Glassworm botnet disrupted after resilient C2 infrastructure takedown

The Glassworm botnet targeting developers in software supply-chain attacks has been disrupted after researchers took down its resilient command-and-control i...

T1583

BleepingComputer →

The Hacker News TTPs Google CrowdStrike 4d ago

GlassWorm Malware Takedown Disrupts Developer Supply Chain Attack Infrastructure

CrowdStrike, in partnership with Google and the Shadowserver Foundation, has announced the simultaneous disruption of all command-and-control (C2) channels a...

T1195

The Hacker News →

Security Affairs TTPs Google CrowdStrike 4d ago

How cybersecurity firms took down Glassworm botnet in one shot

Glassworm infected developers through poisoned tools and packages until a coordinated takedown killed all four of its C2 channels at once. On May 26, 2026, a...

Security Affairs →

GBHackers TTPs Microsoft Linux 5d ago

Quasar RAT Hits Developers With Fileless Linux Attacks

Quasar Linux (QLNX) is a new, stealthy Linux Remote Access Trojan that quietly turns developer and DevOps workstations into high‑value beachheads for softwar...

GBHackers →

GBHackers TTPs 5d ago

Hackers Use SEO Poisoning to Fake Gemini CLI and Claude Code Installers

Hackers are increasingly abusing search engine optimization (SEO) techniques to distribute malware by impersonating popular AI developer tools, including Gem...

GBHackers →

Information Security Buzz TTPs Intel 5d ago

Major US telecom providers debut C2 ISAC to counter AI-driven threats

Eight of the leading communications companies in the United States have created a new cybersecurity alliance that aims to improve threat intelligence sharing...

Information Security Buzz →

GBHackers TTPs 6d ago

InvisibleFerret Malware Uses .pyd and .so Files to Evade Script Detection

A North Korea-linked threat group, Void Dokkaebi, also known as Famous Chollima, has significantly upgraded its malware delivery techniques by converting its...

GBHackers →

GBHackers TTPs 6d ago

Iranian APT Uses SEO Poisoning to Spread Fake SQL Developer Malware

A newly observed cyber campaign linked to the Iranian IRGC-affiliated threat group Nimbus Manticore (also tracked as UNC1549) highlights an evolution in both...

GBHackers →

GBHackers TTPs Microsoft 6d ago

MiniUpdate RAT Abuses Azure C2 for Targeted Espionage

A sophisticated espionage campaign by the Iran-nexus advanced persistent threat group known as Screening Serpens also tracked as UNC1549 and Smoke Sandstorm ...

GBHackers →

SANS ISC TTPs Microsoft May 23

An Example of Stack String in High Level Language, (Sat, May 23rd)

This week, I'm attending the SEC670[1] training (“Red Teaming Tools - Developing Windows Implants, Shellcode, Command and Control”). From my point of vie...

T1071 T1598

SANS ISC →

SC Media TTPs May 22

Middle East malicious infrastructure report highlights concentration of C2 servers

The Hunt.io report identified over 1,350 C2 servers across 98 providers in 14 Middle Eastern countries.

T1071 1 IOC

SC Media →

1 2 3 ... 5 Next page»
FreeIntelHub · Open-source CTI platform

All articles belong to their respective owners. FreeIntelHub aggregates publicly available RSS feeds for informational purposes only. DMCA