Malware & Criminal Tooling Intelligence
New malware families, crimeware updates, loader/dropper campaigns, C2 infrastructure, and initial access broker tooling emerging from criminal underground channels.
Malware & Criminal Tooling — Archive & Latest
GoGRPC Backdoor & Teams Vishing Campaign: Helpdesk Hijacker IAB Tactics — OTX Pulse Analysis
Active IAB campaign abusing Microsoft Teams vishing and Quick Assist to deploy GoGRPC backdoor. Critical urgency.
BabaDeda Loader + ClickFix Social Engineering: OTX Pulse Analysis — Enterprise Detection Pack
Advanced BabaDeda loader using ClickFix social engineering targeting enterprise networks. High urgency - widespread detection recommended.
AsyncRAT & Remcos RATs + BabaDeda Loader: Multi-Stage Phishing & ClickFix Campaigns — Enterprise Detection Pack
Active phishing campaigns delivering AsyncRAT/Remcos via steganography and the BabaDeda ClickFix loader. Urgent blocking required.
TonRAT, AsyncRAT & BabaDeda Campaigns: OTX Pulse Analysis — Enterprise Detection Pack
Active campaigns delivering TonRAT, AsyncRAT, and BabaDeda via ZIPs, phishing, and ClickFix. High urgency for hospitality.
wp2shell RCE Chain & CMSmap Webshell Deployment: OTX Pulse Analysis — Enterprise Detection Pack
Active exploitation of CVE-2026-63030/CVE-2026-60137 'wp2shell' chain drops CMSmap webshells on default WordPress installs. Urgent.
ZimReaper, wp2shell, and IOCONTROL: OTX Pulse Analysis — Critical Infrastructure Threat Pack
Active exploitation of Zimbra (CVE-2025-66376) by TA488, widespread wp2shell RCE on WordPress, and Cyber Av3ngers targeting US ICS via IOCONTROL.
TrickBot DNS Tunneling Variant: C2 Infrastructure & Persistence Analysis
Active TrickBot variant detected using DNS tunneling for C2. High urgency due to evasion techniques.
ValleyRAT & Lampion Campaigns: Multi-Vector VBS/HTML Threats Targeting Finance & Global WhatsApp Users
OTX pulses reveal active VBS-distributing WhatsApp campaign (ValleyRAT/gh0st RAT) and Portugal-targeted banking trojan (Lampion) via obfuscated HTML.
TELESHIM, MIXEDKEY, BINDCLOAK: Targeted Middle East Government Attack — OTX Pulse Analysis
Active East Asia-linked campaign uses TELESHIM (Telegram C2) and MIXEDKEY to target Middle East gov entities. High urgency.
Popa Android Proxyware SDK: Residential Proxy Network Abuse — OTX Pulse Analysis
Android proxyware 'Popa' and variants infect consumer devices via IPTV apps for commercial proxy networks. Urgent block required.
NetSupport RMM via Python Side-Loading: MediaFire ZIP Attack Chain Analysis
Urgent: Active NetSupport RMM campaign using MediaFire ZIPs, Python DLL side-loading, and dllhost.exe injection.
HelloNet APT & Daxin Rootkit Resurgence: OTX Pulse Analysis — Enterprise Detection Pack
Active APT campaigns HelloNet (Russia) and Daxin (Taiwan) exploit software updates and Winlogon via DLL sideloading. High urgency.
TencShell, Lucide Proxy & BadIIS: OTX Pulse Analysis — AI-Powered Intrusions & DDoS Botnets
Active AI-powered espionage (TencShell), npm-based DDoS bots (Lucide), and SQLi-to-crypto persistence (BadIIS) detected. High urgency.
Vercel-Hosted Phishing Campaign Distributing LogMeIn RAT: OTX Pulse Analysis
Cybercriminals abuse Vercel to deliver LogMeIn RAT via fake PDF viewers. High urgency.
RedHook RAT & Clubfoot Wolf OTX Pulse Analysis — Cloud Abuse & Remote Access Trojan Surge
Active RAT campaigns (RedHook, NetSupport, LogMeIn) targeting finance/manufacturing via phishing, Vercel abuse, and mobile ADB exploits. High urgency.
BabaDeda Loader: ClickFix Malware Campaign Analysis — Enterprise Detection Pack
Evolving BabaDeda loader using ClickFix technique for payload delivery. Urgent: block identified C2 IPs and hunt for installer-based infections.
Nezha Web Shell Campaign & BabaDeda ClickFix Loader: OTX Pulse Analysis — Enterprise Detection Pack
OTX pulses reveal active abuse of Nezha monitoring tool via phpMyAdmin log poisoning and the evolution of the BabaDeda ClickFix loader.
AsyncRAT & Remcos Steganography Campaign: OTX Pulse Analysis — Enterprise Detection Pack
Active global phishing campaign using Excel macros and steganography to deliver AsyncRAT/Remcos. High urgency.
CastleRAT, AsyncRAT & Havoc Framework: Multi-Vector Malware Campaign Analysis — Detection Pack
Active campaigns utilizing ClickFix, steganography, and tax lures delivering CastleRAT, AsyncRAT, and Havoc. High urgency.
RustDuck Botnet, AsyncRAT Sideloading & Gamaredon GammaWorm: OTX Pulse Analysis — Enterprise Detection Pack
Critical surge in threats: RustDuck IoT DDoS botnet, AsyncRAT via typosquatting, and Gamaredon espionage targeting Ukraine.
Gamaredon APT, BTMOB Android RAT & Malicious VPN Extensions: OTX Pulse Analysis
FSB-linked Gamaredon targeting Ukraine, Android RAT surge in LatAm, and clipper malware distributed via trojanized VPN extensions.
GHOST STADIUM, Millenium RAT, and LokiBot: OTX Pulse Analysis — Phishing, MaaS, and Infostealer Campaigns
Active campaigns detected: FIFA World Cup phishing (Vidar/Lumma), Millenium RAT MaaS, and LokiBot infostealer. High urgency for credential protection.
FortiBleed Harvesters & Ghost Stadium Phish: OTX Pulse Analysis — Steganography & Credential Theft
Three active threats: FortiBleed FortiGate harvester, multi-stage stego loaders (Remcos/Agent Tesla), and Ghost Stadium FIFA fraud.
StrikeShark Campaign & macOS.Gaslight Backdoor: OTX Pulse Analysis — Multi-Vector Threat Briefing
Active StrikeShark exploitation, DPRK macOS.Gaslight backdoor, and PostCSS supply chain RAT detected. High urgency for gov/tech sectors.
Lazarus Supply Chain & Cloud Atlas APT: OTX Pulse Analysis — Multi-Vector Malware Detection Pack
Urgent: Lazarus 3CX supply chain attack and Cloud Atlas APT campaigns targeting Gov/Healthcare. IOCs and detection rules inside.
Lazarus Supply Chain & Cloud Atlas RATs: OTX Pulse Analysis — Global Threat Briefing
Lazarus targets finance/energy via trojanized 3CX; Cloud Atlas and unknown actors hit gov/healthcare with stealers and RATs. Urgency: High.
Shai-Hulud npm Worm, Cloud Atlas APT, & Gentlemen RaaS: OTX Pulse Analysis — Enterprise Detection Pack
OTX pulses reveal active supply-chain attacks via npm, Cloud Atlas APT targeting government, and Gentlemen ransomware defense evasion tactics.
Shai-Hulud Supply Chain Attack, Cloud Atlas APT Recon, and The Gentlemen RaaS Evasion: OTX Pulse Analysis
Critical threats: Shai-Hulud npm worm, Cloud Atlas phishing new payloads, and The Gentlemen ransomware clearing logs.
Shai-Hulud NPM Worm, The Gentlemen RaaS, & ClickFix Polymorphism: OTX Pulse Analysis
Active npm supply-chain attacks, evasive ransomware TTPs, and polymorphic ClickFix campaigns detected. High urgency for credential theft.
Operation Endgame Aftermath: SocGholish, NPM Shai-Hulud Worm, and ClickFix Fileless Attacks
Briefing on SocGholish infrastructure disruption, npm Shai-Hulud worms, and ClickFix fileless attacks. Critical detection guidance included.
Operation Endgame Disruption & Shai-Hulud Supply Chain: TA569, GoldFactory, and NPM Threats
TA569 infrastructure disrupted; Shai-Hulud worm hits npm; GoldFactory tax fraud active. Block IOCs immediately.
Shai-Hulud, ShinyHunters (CVE-2026-35273), & Potemkin Loader: OTX Pulse Analysis — Enterprise Detection Pack
Active NPM supply chain attack, Oracle PeopleSoft zero-day exploitation, and Potemkin ClickFix loader campaign detected. High urgency.
Potemkin Loader, AsyncRAT AI Lures & APT37 NarwhalRAT: OTX Pulse Analysis — Enterprise Detection Pack
Urgent OTX pulses reveal ClickFix attacks delivering Potemkin/RMMProject, AI-themed AsyncRAT campaigns, and APT37 NarwhalRAT spear-phishing.
ShinyHunters, Potemkin & AsyncRAT Campaigns: OTX Pulse Analysis — Enterprise Detection Pack
Active campaigns: UNC6240 targeting Education via Oracle RCE, and widespread Potemkin/AsyncRAT distribution via ClickFix & AI lures.
AsyncRAT, APT37 NarwhalRAT & OnyxC2: OTX Pulse Analysis of Active RAT & Stealer Campaigns
Active campaigns delivering AsyncRAT via AI lures, APT37's NarwhalRAT, and OnyxC2 MaaS. High urgency due to credential theft.
4BID Hacktivist Ops, Needle Crypto-Stealer, & The Gentlemen Ransomware: OTX Pulse Analysis
OTX pulses reveal active 4BID hacktivism via ProxyShell, Needle MaaS crypto-theft, and The Gentlemen ransomware targeting critical sectors.
The Gentlemen RaaS & AI Supply Chain Poisoning: SystemBC, AMOS Stealer, and CVE-2024-55591 Exploitation
Active RaaS operation Storm-2697 exploits CVE-2024-55591 while threat actors poison AI supply chains with AMOS Stealer. Urgent patching required.
The Gentlemen RaaS (Storm-2697) & AI Supply Chain (AMOS Stealer): OTX Pulse Analysis
Alert: The Gentlemen ransomware exploiting CVE-2024-55591 and AI supply chain trojans dropping AMOS stealer. High urgency.
OTX Pulse Analysis: 4BID Hacktivist Operations & PAN-OS Zero-Day Exploitation (CL-STA-1132)
4BID group leverages ProxyShell/Sliver to target Gov/Healthcare; CL-STA-1132 exploits PAN-OS zero-day; GriefLure hits Vietnam/Philippines.
ClickFix RATs & CL-STA-1132 PAN-OS Exploitation: OTX Pulse Analysis — Enterprise Detection Pack
Active campaigns targeting macOS/Windows with ClickFix (CastleLoader/AMOS) and critical PAN-OS zero-day exploitation by CL-STA-1132.
ClickFix Campaigns & PAN-OS Exploitation: OTX Pulse Analysis — CastleLoader, macOS Infostealers, and EarthWorm
Active ClickFix campaigns delivering CastleLoader/macOS infostealers plus CL-STA-1132 exploiting PAN-OS zero-days for tunneling.
Remus Stealer, Gamaredon GammaSteel, and macOS ClickFix Campaigns: OTX Pulse Analysis — Enterprise Detection Pack
Active detection guidance for Remus/Lumma evolution, macOS ClickFix infostealers, and Gamaredon's GammaSteel targeting Ukraine.
ClickFix macOS Campaigns, Remus Browser Bypass, and Gamaredon GammaSteel Espionage: OTX Pulse Intelligence
Active macOS ClickFix infostealers, Remus browser encryption bypass, and Gamaredon GammaSteel targeting Ukraine analyzed via OTX pulses.
ClickFix & Gamaredon Operations: MacOS Stealers and GammaSteel Espionage — OTX Pulse Analysis
Active ClickFix macOS campaigns delivering AMOS/Shub stealer alongside Gamaredon's GammaSteel targeting Ukraine. Critical IOCs and detection engineering included.
Remus Stealer, Gamaredon GammaSteel, and CloudZ Pheno: OTX Pulse Analysis — Enterprise Detection Pack
Active info-stealers and espionage tooling targeting credentials and OTPs via Phone Link and browser bypasses. Urgent patching required.
Remus Stealer, Gamaredon GammaSteel & CloudZ RAT: OTX Pulse Analysis — Enterprise Detection Pack
Active campaigns featuring Remus ABE bypass, Gamaredon's GammaSteel registry persistence, and CloudZ OTP theft via Phone Link. Urgency: High.
CloudZ OTP Theft, UAT-8302 APT Intrusions, and DesckVB RAT: OTX Pulse Analysis — Enterprise Detection Pack
Active campaigns feature CloudZ OTP theft via Microsoft Phone Link, UAT-8302 exploiting CVE-2025-0994, and DesckVB malspam. High urgency.
DesckVB RAT, Kali365 PhaaS, and Gamaredon GammaWorm: OTX Pulse Analysis — Multi-Vector Threat Landscape
Live OTX intel: Active campaigns involving DesckVB RAT malspam, Kali365 OAuth token theft, and Gamaredon espionage tools detected. Urgency: High.
Gamaredon GammaWorm, SideCopy XenoRAT, and BTMOB MaaS Campaigns: OTX Pulse Analysis & Enterprise Detection Pack
Active espionage and malware campaigns targeting Ukraine, Afghanistan, and LATAM. Gamaredon, SideCopy, and BTMOB using HTA persistence, RAR exploits, and Android RATs. High Urgency.
XenoRAT, BTMOB, and The Gentlemen: OTX Pulse Analysis — Enterprise Detection Pack
Active OTX pulses reveal SideCopy targeting Afghanistan with XenoRAT, BTMOB Android RAT in LatAm, and The Gentlemen RaaS ransomware.
Showing 50 of 99 reports. Archive expands automatically as new intel is generated.
Every Malware & Criminal ToolingReport Includes SIGMA & KQL Detection Rules
Every intelligence briefing on this page includes at least one Sigma rule, a Microsoft Sentinel KQL hunt query, and an IOC check script — ready to drop into your SIEM. No paywall. No registration.