250+ Fake Download Domains Target Mac Users With AMOS and MacSync Infostealers
Attackers are using more than 250 fake “download” domains to selectively target Mac users with AMOS and MacSync infostealers, hiding their ClickFix lures beh...
Articles mapped to MITRE ATT&CK techniques. Select a technique to view matching articles.
56 articles found
Attackers are using more than 250 fake “download” domains to selectively target Mac users with AMOS and MacSync infostealers, hiding their ClickFix lures beh...
A macOS ClickFix operation spanning more than 250 front-end domains now fingerprints visitors before deciding whether to show them a malware lure, a change M...
A macOS ClickFix campaign shifted tactics from openly serving infostealer lures to hiding them behind a browser-fingerprinting gate. The change makes malicio...
OpenAI has shut down a coordinated network of ChatGPT accounts that powered a Cambodia-based scam factory running multi-vector fraud and trafficking-linked o...
Recon-only activity on SSH is not harmless background noise. A recent honeypot session shows an automated Go-based bot logging in as root, exhaustively gradi...
[This is a Guest Diary by Adam Cann, an ISC intern as part of the SANS.
With AI compressing reconnaissance and exploit development from weeks to hours, security vendors are racing to help enterprises identify exposures long befor...
Key Takeaways Two real-world cloud attacks reached meaningful impact in less than ten minutes despite pursuing entirely different objectives. Both attackers ...
Hunt.io uncovered a cyber-espionage attack on Thailand’s Finance Ministry using Hermes AI agent and Hades malware for reconnaissance and persistence.
Cobalt has introduced Cobalt Autonomous Pentest, a new offering that enables continuous offensive security across an organization’s application portfolio by ...
The ransomware landscape is reconsolidating around major players, with Qilin emerging as the leading RaaS operation, researchers say
Threat actors are integrating AI into their exploit chains, accelerating reconnaissance, automating vulnerability discovery, and scaling social engineering i...
Azure AD Graph Activity Logs land in Elastic with full ECS parsing. Detect ROADrecon and AADInternals enumeration with ready-to-use detection rules.
Azure AD Graph Activity Logs land in Elastic with full ECS parsing. Detect ROADrecon and AADInternals enumeration with ready-to-use detection rules.
Explore JOKERSPY, a recently discovered campaign that targets financial institutions with Python backdoors. This article covers reconnaissance, attack patter...
Researchers uncover a watering hole attack likely carried out by APT TA423, which attempts to plant the ScanBox JavaScript-based reconnaissance tool.