Skip to main content

Tag: credential harvesting

87 articles

Dragon Breath Exclusive: Critical RONINGLOADER Gh0st RAT

Dragon Breath Exclusive: Critical RONINGLOADER Gh0st RAT

Think twice before clicking Next — researchers warn Dragon Breath is hiding a multi‑stage RONINGLOADER inside trojanized NSIS installers (masquerading as Chrome or Teams) to install a modified Gh0st RAT that gives attackers stealthy, persistent remote access for credential theft, lateral movement and data exfiltration.

Analyst 207
GootLoader WordPress: Exclusive Font Trick Is Dangerous

GootLoader WordPress: Exclusive Font Trick Is Dangerous

Think an exclusive font is harmless? Think again — GootLoader is hiding malicious JavaScript in fonts and other benign WordPress assets, letting tiny site tweaks become a fast route to full-network takeovers.

Analyst 207
Quantum Route Redirect Phishing Kit: Stunningly Dangerous

Quantum Route Redirect Phishing Kit: Stunningly Dangerous

The Quantum Route Redirect phishing kit quietly hijacks web traffic, rerouting victims to eerily convincing fake sites. Learn how this route redirect phishing attack works and what you can do to stay one step ahead.

Analyst 207
China-Aligned UTA0388 Exclusive: Dangerous AI Phishing

China-Aligned UTA0388 Exclusive: Dangerous AI Phishing

Imagine your inbox posing as a trusted colleague—researchers say UTA0388, a China‑aligned cluster, now uses AI to craft eerily personalized, time‑sensitive spear‑phishing that steals credentials and plants stealthy, long‑term access.

Analyst 207
Russian spies Exclusive: Dangerous VM malware on Windows

Russian spies Exclusive: Dangerous VM malware on Windows

Meet Curly COMrades — a spy group that runs a tiny Alpine Linux “shadow OS” inside a hidden Hyper‑V VM on compromised Windows hosts, letting them slip past endpoint tools and quietly harvest data, credentials and long‑term access.

Analyst 207
Invisible npm malware: Exclusive, Dangerous Token Theft

Invisible npm malware: Exclusive, Dangerous Token Theft

PhantomRaven quietly slipped into the npm registry, turning routine installs into token theft by harvesting credentials during install and letting attackers publish malicious updates without touching your code. One stolen token can cascade through thousands of projects—here’s why supply‑chain hygiene and MFA matter now.

Analyst 207
New Atroposia RAT Exclusive: Dangerous Dark Web Threat

New Atroposia RAT Exclusive: Dangerous Dark Web Threat

Meet Atroposia RAT: a modular, encrypted remote-access trojan on the dark web that grants attackers a stealthy, persistent foothold to harvest credentials and siphon crypto wallets. Defenders need to move beyond static hashes and rely on behavioral analytics, EDR, and tuned network telemetry to spot its evasive moves.

Analyst 207
GhostCall Exclusive: Critical BlueNoroff Malware Reveal

GhostCall Exclusive: Critical BlueNoroff Malware Reveal

Meet GhostCall — a stealthy campaign tied to BlueNoroff that weaponizes low‑profile backdoors and traffic‑manipulation to quietly harvest credentials and hijack Web3 sessions. As blockchain projects scale, GhostCall and its sibling GhostHire show how openness can be turned into an espionage-and-theft platform that technologists, policy makers and users can’t afford to ignore.

Analyst 207
Iran’s MuddyWater: Stunning, damaging 100+ network breach

Iran’s MuddyWater: Stunning, damaging 100+ network breach

A single hijacked government mailbox became MuddyWater’s battering ram, letting Tehran-linked operators quietly harvest credentials and pivot into 100+ networks across the Middle East and North Africa. It’s a stark reminder that low-cost social engineering and trusted infrastructure can give attackers exponential reach without a single zero-day.

Analyst 207
Dark landscape with cracked dam, lone figure amidst shattered screens and wires.

Iran’s MuddyWater Exclusive: Damaging 100+ Gov Hacks

MuddyWater turned one trusted inbox and a rented VPN into a battering ram against more than 100 government networks—proving social engineering beats flashy malware every time. Group‑IB’s forensic breakdown shows how stealthy credential theft and patient lateral movement bought months of access to critical diplomatic and government secrets.

Analyst 207
MuddyWater Exclusive: Devastating 100+ Government Breach

MuddyWater Exclusive: Devastating 100+ Government Breach

A single compromised mailbox and an attacker-controlled VPN quietly became the battering ram for a MuddyWater espionage campaign that infiltrated more than 100 government networks across the Middle East and North Africa. Group‑IB’s analysis shows the actors used trusted email, credential harvesting, and stealthy lateral movement to maintain months-long access and siphon sensitive diplomatic and personnel data.

Analyst 207
MuddyWater Stunning Breach Hits 100+ Government Networks

MuddyWater Stunning Breach Hits 100+ Government Networks

The MuddyWater campaign turned a single compromised mailbox and an attacker-controlled VPN into a battering ram, phishing its way into 100+ government networks across the Middle East and North Africa and proving that access and trust beat flashy exploits every time.

Analyst 207
Pakistani-Linked Hacker Group Exclusive: Major India Breach

Pakistani-Linked Hacker Group Exclusive: Major India Breach

A Pakistan-linked group called TransparentTribe quietly deployed the DeskRAT trojan to infiltrate Indian government networks, harvesting credentials and sensitive documents over months. The patient, espionage-focused campaign raises urgent questions about when cyber intrusions become acts of war.

Analyst 207
Hooded figure in shadows stands before dimly lit European map, laptop screen glowing with cryptic image amidst broken…

Lazarus Group Exclusive: Stunning Threat to EU Defense

Europe’s drone industry is being stalked by North Korea’s Lazarus Group, which used fake recruitment DreamJob lures to slip malware into engineers’ inboxes and siphon designs, test data and R&D secrets. The campaign shows how porous modern research networks are—and how cyber espionage can become a direct, strategic threat to EU defence and supply‑chain security.

Analyst 207
Dark laptop screen with distorted CAPTCHA, Ukraine map, cracked glass, and ominous glowing eyes in shadows.

PhantomCaptcha Campaign: Stunning Threat to Ukraine Aid

What if the message promising help handed attackers the keys? The PhantomCaptcha campaign did exactly that — a surgical phishing blitz using believable impersonation and innocuous-looking attachments to steal credentials and threaten Ukraine relief efforts.

Analyst 207
MuddyWater Exclusive: Dangerous Global Phishing Campaign

MuddyWater Exclusive: Dangerous Global Phishing Campaign

Get an exclusive look at the dangerous global MuddyWater phishing campaign—how it operates, who it targets, and simple, practical steps you can take today to stay protected.

Analyst 207
Smishing Triad Exclusive: Dangerous 194K Domains Revealed

Smishing Triad Exclusive: Dangerous 194K Domains Revealed

Think a text cant hurt you? Researchers say a single smishing campaign has spawned over 194,000 malicious domains, turning routine SMS alerts into localized lookalike sites and clever redirect chains that steal credentials or deliver malware worldwide.

Analyst 207
APT36 Exclusive: Critical Golang DeskRAT Threat Hits India

APT36 Exclusive: Critical Golang DeskRAT Threat Hits India

Think a phishing email cant threaten national security? In summer 2025, tailored spear-phishing delivered Golang DeskRAT into Indian government networks — a stealthy APT36 tool that turns a single click into a strategic risk.

Analyst 207
BeaverTail and OtterCookie: Stunning Critical Threat

BeaverTail and OtterCookie: Stunning Critical Threat

Cisco Talos warns a North Korean group is fusing BeaverTail’s credential-theft with OtterCookie’s browser persistence into single, stealthier JavaScript malware that’s harder to spot — defenders should start hunting for blended behaviors and tighten basics like MFA, patching, and anomaly detection now.

Analyst 207
NoRobot malware: Exclusive Dangerous Threat

NoRobot malware: Exclusive Dangerous Threat

When LostKeys was exposed this spring, Coldriver didn’t fold — they reinvented, rolling out a lean, modular strain called NoRobot that sneaks past signatures, steals credentials, and blends into normal traffic. Defenders now need behavior-based detection, stronger identity controls like MFA, and faster threat-sharing to keep up with this smarter, stealthier pivot.

Analyst 207
Fortress-like cityscape at dusk with laptop and shield emblem, surrounded by ominous code-like tendrils and a cracked…

RMM software Must-Have Protections: Best Defenses

Remote monitoring tools like ScreenConnect make IT life easier—but when attackers hijack them through phishing or stolen credentials, that convenience becomes a powerful way to spread ransomware and steal data. Protect your RMM consoles with strong authentication, network segmentation, and vigilant monitoring before a single click turns into a network-wide crisis.

Analyst 207
Payroll Pirate Crew: Exclusive Risky Threat to Campuses

Payroll Pirate Crew: Exclusive Risky Threat to Campuses

Microsoft warns a cybercriminal group dubbed the Payroll Pirate Crew is targeting U.S. universities with phishing attacks that hijack HR systems to quietly reroute paychecks, leaving staff suddenly unpaid and campuses scrambling. Universities should tighten MFA, limit admin privileges, and require out‑of‑band verification for bank‑detail changes to protect employees and reputations.

Analyst 207
malicious npm packages: Stunning Critical Threat Revealed

malicious npm packages: Stunning Critical Threat Revealed

Researchers uncovered Beamglea — 175 malicious npm packages downloaded about 26,000 times — that quietly hosted credential‑harvesting phishing campaigns against 135+ organizations, a stark reminder that the convenience of open-source packages can become a gateway for large‑scale theft.

Analyst 207
PHP web shells: Exclusive Alert – Dangerous Campaign

PHP web shells: Exclusive Alert – Dangerous Campaign

A new campaign is exploiting unpatched PHP web apps to plant web shells and deploy Nezha and Ghost RAT for fast, persistent access — a clear reminder to patch, harden, and monitor your web-facing systems now.

Analyst 207