Warlock Exploits SharePoint Flaws to Disable Security Tools and Deploy Ransomware
The suspected China-linked threat actor known as Warlock is still continuing to weaponize Microsoft SharePoint vulnerabilities, likely both old and new, in a...
Articles mapped to MITRE ATT&CK techniques. Select a technique to view matching articles.
14 articles found
The suspected China-linked threat actor known as Warlock is still continuing to weaponize Microsoft SharePoint vulnerabilities, likely both old and new, in a...
The Psychedelic Stealer malware distributed via compromised Ukrainian websites using ClickFix-style Cloudflare verification checks is part of a wider malware...
The technique, termed "process parameter poisoning," allows attackers to hide malicious code within the legitimate startup parameters of a Windows process.
The campaign, uncovered by LastPass and Delphos Labs, impersonates LastPass and at least 39 other companies.
A newly documented ransomware intrusion attributed to The Gentlemen shows how attackers can convert a foothold in a Windows environment into domain-wide cont...
The campaign utilizes a "bring your own vulnerable driver" (BYOVD) technique, leveraging a legitimate but vulnerable driver (ardrv.sys) associated with OPSWA...
Individuals and organizations in Cambodia have emerged as the target of a new campaign that delivers an open-source remote access trojan (RAT) called Spark R...
Cybersecurity researchers have disclosed details of a Chinese-speaking cybercrime group dubbed UAT-10147 that's targeting Windows and Linux web servers globa...
BeyondTrust has revealed two high-severity vulnerabilities in its Endpoint Privilege Management (EPM) Windows Deployment product, which could lead to local p...
A growing underground market is turning mature malware-evasion techniques into subscription products. An analysis of 24 active crypting-service vendors shows...
Huntress documents how a ransomware affiliate sabotaged its own attack with an anti-EDR effort
Attackers are adapting established techniques to AI platforms, emerging technologies, and changing user behavior. ESET's new threat report examines the rise ...
A threat actor used AI coding tools to build and test EDR evasion malware, Sophos finds
This research focuses on the importance of native audit logs in secure-by-design software, emphasizing the need for kernel-level ETW logging over user-mode h...