Security Insights
Latest threat analysis, industry news, and security best practices from our expert team.
Y2K Operators: Millenium RAT v4 (C++) Telegram C2 Campaign — OTX Pulse Analysis
Threat Summary Analysis of OTX Pulse data reveals the Y2K Operators threat group actively utilizing Millenium RAT v4, a Remote Access Trojan...
Cisco SD-WAN Zero-Day & GitHub Actions Abuse: Supply Chain Credential Theft
Intelligence Briefing: Multi-Vector Supply Chain & Credential Theft Campaign Threat Summary Recent OTX pulses indicate a coordinated surge i...
DEADLOCK Ransomware: Global Manufacturing & Gov Sector Assault — IOCs & Detection Engineering
Threat Actor Profile — DEADLOCK Aliases: None confirmed (Single operation under DEADLOCK brand). Operational Model: RaaS (Ransomware-as-a-Se...
Prinz Eugen Ransomware: ROOTBOY APT Campaign & Go-based Encryptor — OTX Pulse Analysis
Threat Summary Recent intelligence from the AlienVault OTX community has uncovered a new ransomware family, Prinz Eugen, attributed to the e...
Prinz Eugen Ransomware & GitHub Actions Abuse: OTX Pulse Analysis — Enterprise Detection Pack
Threat Summary Recent OTX pulses indicate a surge in multi-vector threat activity targeting enterprise infrastructure and data integrity. Th...
MONEYMESSAGE Gang: US Transportation & Energy Under Siege — Critical Firewall & Remote Access Exploitation
Threat Actor Profile — MONEYMESSAGE Aliases & Affiliation: MONEYMESSAGE is a relatively new but aggressive player in the ransomware-as-a-ser...
wp2shell RCE Chain & CMSmap Webshell Deployment: OTX Pulse Analysis — Enterprise Detection Pack
Threat Summary Recent OTX pulse data indicates the active exploitation of a critical vulnerability chain dubbed "wp2shell" affecting WordPre...
LokiBot Resurgence & GitHub Actions Supply Chain Attacks: OTX Pulse Analysis
Threat Summary Recent OTX pulses indicate a convergence of legacy malware persistence and modern infrastructure abuse. A mature LokiBot info...
KILLSEC Gang: 3 New US/IN Victims — Financial & Healthcare Targeting & Detection Rules
Threat Actor Profile — KILLSEC Aliases & Operations: KILLSEC (also tracked as Kill Security) operates as a aggressive Ransomware-as-a-Servic...