Skip to main content
FreeIntelHub
Feed Threat Feed Search Trending
Intelligence CVE Priority Vulnerability IOC Lookup IOC Feed YARA Rules Phishing Lookup Exploit Lookup Pastes Dark Web
Adversaries Threat Groups Software Campaigns
Explore Dashboard Geo Map Heatmap MITRE ATT&CK
Browse Sources Vendors Categories Sectors
RSS API
FreeIntelHub
/
Sign In

TTPs

20 articles

Microsoft Security Blog TTPs Microsoft Atlassian F5 Linux May 22

From edge appliance to enterprise compromise: Multi-stage Linux intrusion via F5 and Confluence

A multi-stage attack on Linux devices began with an exposed F5 BIG-IP edge appliance and pivoted to an internal Confluence server for credential theft and id...

T1078 T1021

Microsoft Security Blog →

Unit 42 TTPs May 22

Paved With Intent: ROADtools and Nation-State Tactics in the Cloud

Open-source framework ROADtools is being misused by threat actors for cloud intrusions. Learn how to identify its malicious use.

Unit 42 →

Kaspersky Securelist TTPs May 22

Cloud Atlas activity in the second half of 2025 and early 2026: new tools and a new payload

The experienced Cloud Atlas group remains active, continuing to target government sectors and diplomatic entities in Russia and Belarus, employing both new a...

Kaspersky Securelist →

Security Affairs TTPs Intel May 22

One Telecom Provider Hosted Most of the Middle East ’s Active C2 Infrastructure

Hunt.io mapped 1,350+ C2 servers across the Middle East, revealing how a small group of providers quietly supports major malware activity.

T1566 T1071 T1583 1 IOC

Security Affairs →

GBHackers TTPs May 22

Operation Dragon Whistle Targets Changzhou University with Malicious LNK Files

A recent phishing campaign dubbed “Operation Dragon Whistle” highlights an evolving trend in cyberattacks: threat actors abusing legitimate developer tools a...

T1566

GBHackers →

GBHackers TTPs Apple May 22

Hackers Hide Malware in Nested macOS-Style Folders to Evade Scans

Hackers are increasingly adopting stealthy delivery techniques, and a newly uncovered spear-phishing campaign shows how nested macOS-like folder structures c...

T1566 T1204

GBHackers →

GBHackers TTPs Microsoft May 21

Fake Microsoft Teams Downloads Spread ValleyRAT Malware

Hackers are actively distributing a sophisticated ValleyRAT malware variant through fake Microsoft Teams download pages, leveraging social engineering and mu...

T1204

GBHackers →

Help Net Security TTPs Microsoft NVIDIA May 21

AI red teaming agents change how LLMs get tested

Adversarial probing of LLMs has piled up a sprawling toolkit over the past three years. Attack techniques with names like Tree of Attacks with Pruning, Cresc...

Help Net Security →

SC Media TTPs May 20

APIs under pressure: How AI is rewriting the rules of enterprise security

The rapid growth of AI has created an explosion of APIs that will require new techniques to manage.

SC Media →

SC Media TTPs Microsoft May 20

Storm-2949 actor targets Microsoft 365 and Azure environments

Storm-2949 initiates attacks by targeting users with privileged roles, such as IT personnel or senior leadership, using social engineering tactics to obtain ...

T1204

SC Media →

SC Media TTPs May 20

Major U.S. telecom companies form new cybersecurity information sharing group

The C2 ISAC, founded by AT&T, Charter, Comcast, Cox, Lumen, T-Mobile, Verizon, and Zayo, aims to foster more candid information exchange than previously ...

SC Media →

SC Media TTPs May 20

Poland directs officials to cease Signal use amid cyberattack concerns

The cyberattacks did not compromise Signal's encryption but instead relied on social engineering and account takeover tactics.

T1204

SC Media →

The Hacker News TTPs Microsoft Broadcom May 20

Webworm Deploys EchoCreep and GraphWorm Backdoors Using Discord and MS Graph API

Cybersecurity researchers have flagged fresh activity from a China-aligned threat actor known as Webworm in 2025, deploying custom backdoors that employ Disc...

The Hacker News →

GBHackers TTPs May 20

Gremlin Stealer Hides C2 and Exfiltration Paths in Encrypted Resources

A newly identified variant of the Gremlin stealer malware is leveraging advanced obfuscation techniques to conceal its command-and-control (C2) infrastructur...

T1027 T1041

GBHackers →

GBHackers TTPs Microsoft May 20

GraphWorm Malware Abuses Microsoft OneDrive for Stealthy C2 Operations

A new activity from Webworm, a China-aligned advanced persistent threat (APT) group, revealing a significant evolution in its cyber espionage toolkit during ...

GBHackers →

Infosecurity Magazine TTPs May 20

China-Linked Webworm APT Evolves Tactics, Expands to European Targets

China-linked Webworm APT expands beyond Asia, targeting European government organizations and refining its cyber espionage tactics, according to ESET research

Infosecurity Magazine →

ESET Research TTPs May 20

Webworm: New burrowing techniques

ESET researchers describe new tools and techniques that the Webworm APT group recently added to its arsenal

ESET Research →

GBHackers TTPs May 20

Void Botnet Leverages Ethereum for Resilient C2

A newly identified botnet, named Void, is leveraging Ethereum smart contracts to build a resilient, hard-to-disrupt command-and-control (C2) infrastructure, ...

GBHackers →

GBHackers TTPs Google May 20

Trapdoor Android Ad Fraud Ring Abuses 455 Apps for Fake Clicks

A large-scale Android ad fraud campaign named “Trapdoor,” exposing a sophisticated ecosystem built on 455 malicious apps and 183 command-and-control (C2) dom...

T1189

GBHackers →

GBHackers TTPs May 20

Mini Shai-Hulud Attack Hits npm Ecosystem, Compromising Over 600 Packages

A large-scale supply chain attack targeting the npm ecosystem has resurfaced with a new variant of the Mini Shai-Hulud malware, compromising more than 600 pa...

T1195

GBHackers →

«Previous page 1 2 3 4 5 Next page»
FreeIntelHub · Open-source CTI platform

All articles belong to their respective owners. FreeIntelHub aggregates publicly available RSS feeds for informational purposes only. DMCA