Security Insights
Latest threat analysis, industry news, and security best practices from our expert team.
ValleyRAT Resurgence: SilverFox Fake Installer Campaigns & BYOVD Techniques
Threat Summary Recent OTX pulse data indicates a significant resurgence in SilverFox activity, utilizing the ValleyRAT malware family. Detec...
Supply Chain Attack: lib-mtop & aone-cli RAT Cluster — OTX Pulse Analysis
Threat Summary A sophisticated supply chain attack has been detected targeting the software development ecosystem, specifically focusing on ...
GoGRPC Backdoor & Teams Vishing Campaign: Helpdesk Hijacker IAB Tactics — OTX Pulse Analysis
Threat Summary The latest OTX pulse highlights an active Initial Access Broker (IAB) campaign, tracked since January 2026, that employs a so...
BabaDeda Loader + ClickFix Social Engineering: OTX Pulse Analysis — Enterprise Detection Pack
Threat Summary Based on the OTX pulse data, the BabaDeda loader family represents an evolving malware framework discovered in April 2026 tha...
AsyncRAT & Remcos RATs + BabaDeda Loader: Multi-Stage Phishing & ClickFix Campaigns — Enterprise Detection Pack
Threat Summary Recent intelligence from the AlienVault OTX community highlights two active and sophisticated malware distribution campaigns ...
TonRAT, AsyncRAT & BabaDeda Campaigns: OTX Pulse Analysis — Enterprise Detection Pack
TonRAT, AsyncRAT & BabaDeda Campaigns: OTX Pulse Analysis — Enterprise Detection Pack Active campaigns delivering TonRAT, AsyncRAT, and Baba...
wp2shell RCE Chain & CMSmap Webshell Deployment: OTX Pulse Analysis — Enterprise Detection Pack
Threat Summary Recent OTX pulse data indicates the active exploitation of a critical vulnerability chain dubbed "wp2shell" affecting WordPre...
ZimReaper, wp2shell, and IOCONTROL: OTX Pulse Analysis — Critical Infrastructure Threat Pack
ZimReaper, wp2shell, and IOCONTROL: OTX Pulse Analysis — Critical Infrastructure Threat Pack Excerpt Active exploitation of Zimbra (CVE-2025...
TrickBot DNS Tunneling Variant: C2 Infrastructure & Persistence Analysis
TrickBot DNS Tunneling Variant: C2 Infrastructure & Persistence Analysis Threat Summary A distinct variant of the TrickBot banking trojan (S...