Topic: remote access tools
-
Akira hackers use Safe Mode to bypass EDR, steal data, skip encryption
An Akira ransomware affiliate bypassed a victim's EDR by exploiting a SonicWall VPN without MFA, gaining access, mapping Active Directory, and exfiltrating data via S3 and AnyDesk within about two hours. The attacker forced the host into Safe Mode with Networking, disabling the EDR and Microsoft ...
Read More » -
Former Medusa Affiliate Deploys New StormEncryptor Ransomware
Microsoft's threat intelligence unit tracks Storm-1175, a China-based actor previously linked to Medusa ransomware, which has now deployed a new custom C++ locker called StormEncryptor that appends ".encrypted" to files and demands payment within 72 hours. The group's recent intrusions likely exp...
Read More » -
Bank of America Phishing Scam Deploys Remote Access Malware
Phishing emails posing as Bank of America lure victims to fake login pages that steal credentials and trigger a malicious script installing ScreenConnect, a legitimate remote access tool abused for unauthorized control and persistence. The attack grants attackers full remote control, enabling dat...
Read More » -
Microsoft Teams vishing leads to Chaos ransomware attacks
Cybercriminals posing as IT support staff over Microsoft Teams calls have targeted North American businesses, with 95% of attacks hitting Canadian (50%) and U.S. (45%) entities across services, manufacturing, energy, and construction sectors. The scheme uses external Teams accounts and IT-themed ...
Read More » -
Scattered Spider Operates as a Cybercrime Collective
Security researchers redefined Scattered Spider as a decentralized cybercrime collective of independent clusters sharing tactics but no central hierarchy, rather than a single unified group. The collective is linked by common techniques like social engineering, phishing, and targeting technology ...
Read More » -
Silent Ransom Group targets law firms via fake IT support calls
The Silent Ransom Group is aggressively targeting U.S. law firms and professional services through sophisticated social engineering, beginning with invoice-themed phishing emails followed by callback phishing where attackers impersonate IT help desk staff to gain remote access. Once inside, the g...
Read More » -
FBI and Google warn of ransomware gangs posing as IT workers
The Silent Ransom Group has escalated attacks on law firms by dispatching fake IT workers in person to victims' offices to steal data using USB drives or remote access tools. The gang uses social engineering and phishing to gain remote access, but also employs physical intrusions to bypass securi...
Read More » -
MuddyWater uses Chaos ransomware as decoy in attacks
Iranian state-sponsored MuddyWater hackers posed as a Chaos ransomware operation, using Microsoft Teams social engineering to steal credentials and access systems, with the ransomware component likely a decoy for cyber-espionage rather than financial gain. Researchers at Rapid7 attribute the atta...
Read More » -
Iran-Linked Hackers Posed as Ransomware Group in Spy Campaign
Iranian state-linked group MuddyWater used the Chaos ransomware brand as cover for espionage, infiltrating an organization via Microsoft Teams screen sharing and harvesting credentials before exfiltrating data, but never deploying actual ransomware. Key red flags indicating state sponsorship incl...
Read More » -
Microsoft Teams Used to Deliver New Snow Malware
A threat group called UNC6692 uses social engineering via email bombing and Microsoft Teams to trick victims into installing the "Snow" malware suite, which includes a malicious Chrome extension (SnowBelt), a tunneler (SnowGlaze), and a backdoor (SnowBasin). The malware enables credential theft a...
Read More » -
Report: Chinese hackers exploited VPN flaws to breach Ivanti customers
State-linked Chinese hackers exploited a hidden backdoor in Ivanti's Pulse Secure VPN in February 2021, compromising 119 organizations including government agencies and military contractors. The breach is linked to corporate restructuring after Ivanti's 2017 acquisition, where cost-cutting and la...
Read More » -
Operation DoppelBrand: How Hackers Hijack Trusted Brands to Steal Your Data
A sophisticated phishing campaign dubbed Operation DoppelBrand, linked to threat actor GS7, is using highly convincing fake websites to impersonate major financial and tech brands and steal user credentials. The operation uses extensive automated infrastructure, including over 150 identified doma...
Read More » -
Active Attacks Target Unpatched SolarWinds WHD Systems
Attackers are exploiting unpatched SolarWinds Web Help Desk systems to gain network access, using "living-off-the-land" techniques like legitimate remote access tools to avoid detection. Once inside, they deploy a weaponized version of the Velociraptor forensics tool for command-and-control, enab...
Read More » -
AI Fuels 100% Surge in Phishing Attacks
AI has fueled a 100% surge in phishing attack rates, with security systems now intercepting one malicious email every nineteen seconds, doubling the previous year's frequency. Cybercriminals use AI to create polymorphic, multi-channel campaigns that constantly adapt their appearance and personali...
Read More » -
DeadLock Ransomware Evades Security with BYOVD Attack
The DeadLock ransomware campaign uses a BYOVD technique, exploiting a known vulnerability (CVE-2024-51324) in a Baidu Antivirus driver to disable security software and delete recovery options before deploying its payload. The ransomware itself, written in C++, uses process hollowing and a custom ...
Read More » -
New Gladinet Triofox Flaw Exploited by Attackers (CVE-2025-12480)
A critical security flaw (CVE-2025-12480) in Gladinet Triofox allows unauthenticated attackers to bypass access controls and gain administrative privileges, which has been exploited by the threat group UNC6485 since late August 2025. Attackers used an HTTP Host header attack to access the configu...
Read More » -
Legit Tools Turned Malicious: Velociraptor and Nezha Weaponized
Legitimate open-source tools Velociraptor and Nezha are being weaponized by threat actors to maintain access, evade detection, and deploy ransomware or malware on enterprise systems. A China-linked ransomware group exploited an outdated Velociraptor version with a privilege escalation flaw to dep...
Read More » -
MonsterRAT: Stealthy Malware Threatens Windows Systems
A sophisticated phishing campaign distributes the previously undocumented MonsterRAT malware, which targets Windows systems and grants attackers full administrative control through a multi-stage infection process. The attack uses phishing emails disguised as business correspondence to deliver the...
Read More » -
New Phishing Attack Deploys RATs Using UpCrypter Evasion
A global phishing campaign uses personalized emails and fake websites to distribute malicious downloads, employing the UpCrypter loader to deploy remote access trojans for prolonged unauthorized access. The attack involves HTML attachments redirecting to deceptive sites, with variations like voic...
Read More »