Skip to main content

Tag: unit 42

43 articles

Concerned individuals walk down a modern office corridor lined with server racks and filing cabinets, with a focused laptop…

Cyber Extortion Economy Shifts Away From Ransomware Encryption

The cyber extortion landscape is undergoing a seismic shift, with threat actors ditching ransomware encryption in favor of data-only extortion - and they're moving at lightning speed, with one case seeing data exfiltration in just 39 seconds. This trend is driven by improved backup and recovery methods, leaving attackers to focus on stealing sensitive data.

Analyst 207
Devices and equipment in a brightly-lit tech facility with a laptop screen displaying blurred code.

Malvertisers Exploit Code Signing in TamperedChef Malware Campaigns

Meet the sneaky malware campaign that's been flying under the radar, leveraging polished marketing tactics and code signing to spread its malicious reach - with over 4,000 samples and 100 unique variants uncovered across three distinct clusters of activity.

Analyst 207
Dimly lit server room with rows of rack-mounted equipment and cables.

Gremlin Stealer Evolves With Advanced Obfuscation Tactics

Meet the new and improved Gremlin Stealer, which has upgraded its hiding game by cleverly concealing its payloads in .NET resource blobs and only revealing them at runtime, making it a stealthier threat than ever. This latest variant uses single-byte XOR encoding to mask its malicious code, evading detection by signature and heuristic scanners.

Analyst 207
Network device in a brightly-lit tech environment with blurred background infrastructure.

Palo Alto Networks Discloses Active Exploitation of PAN-OS Flaw Enabling Espionage

Palo Alto Networks has uncovered active exploitation of a high-severity flaw in PAN-OS software, allowing attackers to execute arbitrary code with root privileges and inject shellcode into vulnerable systems. This critical vulnerability, tracked as CVE-2026-0300, enables unauthenticated remote code execution, putting affected appliances at risk of espionage.

Analyst 207
Brightly-lit network operations center with multiple workstations and natural light from floor-to-ceiling windows.

Threat Actors Exploit Blind Spots Beyond Endpoint Defenses

Attackers are now moving at an alarming pace, taking data four times faster than in 2025, and exploiting the blind spots that an over-reliance on endpoint defenses creates. They're striking across multiple surfaces, from cloud services to remote users, to evade detection and get in and out quickly.

Analyst 207
Person working at desk with laptop in a well-lit office setting.

Malicious AI Browser Extensions Exfiltrate User Data

Beware of AI browser extensions that promise to boost productivity but secretly steal your data. Researchers uncovered 18 malicious extensions that masquerade as helpful tools but deliver spyware, Trojans, and other threats that can hijack your online activity.

Analyst 207
Brightly-lit retail setting with a point-of-sale terminal in the foreground, hinting at unease.

BlackFile Targets Retail, Hospitality with Extortion Attacks

Meet BlackFile, a notorious extortion group wreaking havoc on the retail and hospitality sectors with high-stakes attacks, demanding seven-figure ransoms from its victims. With a modus operandi that includes impersonation and voice-phishing, this threat actor is using pressure tactics to get what they want.

Analyst 207
Busy airport terminal in Central or South America with laptop on luggage cart.

TGR-STA-1030 Intensifies Espionage Push in Central, South America

The threat group TGR-STA-1030 is ramping up its espionage efforts in Central and South America, with sustained and widespread activity observed across multiple countries since February. This persistent campaign has recently intensified, with a heavy focus on regions within Central and South America.

Analyst 207
Person hunched over laptop with eerie glow, surrounded by shattered shield and robotic arm, with cityscape in background.

AI Models Turbocharge Vulnerability Discovery

Imagine a world where AI models don't just help find software bugs, but actually behave like expert security researchers - that's the reality we're facing, and it's changing the vulnerability discovery game. Frontier AI models are now capable of autonomously discovering zero-day vulnerabilities and speeding up patching processes.

Analyst 207
Person in hoodie sits before laptop with eerie glow, surrounded by cables, with cityscape and Iranian flag in background.

Iran's Cyber Threat Landscape Intensifies

Iran's cyber threat landscape is escalating, with phishing, hacktivist operations, and criminal activity converging to create a complex risk picture. A recent Unit 42 threat brief offers valuable insights and practical guidance to help defenders stay ahead of these emerging threats.

Analyst 207
Shadowy figure in a hoodie amidst industrial complex with glowing laptop screens and cables.

TeamPCP Infiltrates Security Infrastructure with Multi-Stage Supply Chain Attack

When security tools meant to safeguard networks become the entry point for attacks, trust is shattered - and that's exactly what's happening with TeamPCP's multi-stage supply chain attacks on security infrastructure. This sinister tactic lets threat actors turn protectors into launchpads for wider compromise.

Analyst 207
Tangled web of interconnected chains and gears with a broken link highlighted, set against a cityscape at dusk.

Unit 42 Uncovers Axios Supply Chain Attack's Far-Reaching Consequences

When a trusted software pathway is compromised, the consequences can be far-reaching - as Unit 42's recent analysis of the Axios supply chain attack starkly reveals, threatening digital trust and resilience. The team's detailed examination exposes the attack's full chain, from initial dropper to forensic cleanup.

Analyst 207
Large ominous robot with cracked facade surrounded by swarming autonomous agents.

Unit 42 Research Exposes Risks in Amazon Bedrock's Multi-Agent AI Systems

Unit 42's latest research reveals a hidden threat: multi-agent AI systems on Amazon Bedrock can be vulnerable to new and alarming risks, including prompt injection attacks that practitioners can't afford to ignore. Learn how to safeguard your AI applications from these emerging threats.

Analyst 207
Cracked sandbox with miniature cityscape and exposed glowing wires amidst shattered glass and broken screens.

Vulnerabilities Exposed in Amazon Bedrock AgentCore Sandbox

Security researchers at Unit 42 have uncovered critical vulnerabilities in Amazon Bedrock AgentCore's sandbox, revealing that a protective layer meant to separate code and services can be breached using DNS tunneling, exposing sensitive credentials in the process. This alarming discovery highlights the potential risks of slipping through the cracks of a supposedly secure system.

Analyst 207
Kubernetes Environments Under Siege as Attacks Escalate

Kubernetes Environments Under Siege as Attacks Escalate

Kubernetes environments are under attack like never before, with threat actors exploiting identities and critical vulnerabilities to compromise cloud infrastructure - so what can organizations do to protect themselves? The warning signs are clear: it's time to take action against escalating Kubernetes attacks.

Analyst 207
TGR-STA-1030 Exclusive: Severe Breach Hits 70 Sites

TGR-STA-1030 Exclusive: Severe Breach Hits 70 Sites

Meet TGR-STA-1030: a stealthy Asia-based espionage crew that’s quietly breached at least 70 government and critical‑infrastructure networks across 37 countries, using bespoke tools, credential harvesting and meticulous reconnaissance to keep long‑term, hard-to-detect access to telecom and communications systems.

Analyst 207
Nation-State Hackers Deploy Dire Exclusive Airstalk Malware

Nation-State Hackers Deploy Dire Exclusive Airstalk Malware

Think your MDM keeps devices safe? Think again — a suspected nation-state is using the AirWatch API to deploy Airstalk malware, hijacking trusted management channels to stealthily compromise fleets of phones.

Analyst 207
Jingle Thief Exclusive: Costly Cloud Hack Steals Millions

Jingle Thief Exclusive: Costly Cloud Hack Steals Millions

Imagine criminals turning your retailer’s cloud into a holiday ATM—Unit 42 warns the Jingle Thief gang uses phishing and smishing to steal credentials and exploit misconfigured cloud systems to issue and redeem millions in gift cards. Stronger identity controls, logging and vendor oversight are urgent fixes before consumers and merchants are left cleaning up the mess.

Analyst 207
NET malware Dangerous: Exclusive Phantom Taurus Threat

NET malware Dangerous: Exclusive Phantom Taurus Threat

A Beijing-linked group dubbed Phantom Taurus is quietly using custom .NET malware to hunt credentials and siphon sensitive files from government web servers across Asia, Africa and the Middle East — a sharp reminder that everyday frameworks can hide serious threats. Defenders should harden .NET apps, tighten logging and MFA, and share indicators fast to turn the tables before secrets slip away.

Analyst 207