Product
high
threat
Toy Ghouls Deploying Custom GenieLocker Ransomware
1 rule 4 TTPs 1 IOCThe Toy Ghouls threat actor is deploying a custom ransomware family called GenieLocker against manufacturing organizations, utilizing compromised VPN credentials and legitimate system tools for lateral movement and encryption.
Windows +6
Toy Ghouls
ransomware
extortion
manufacturing
toy-ghouls
1r
4t
1i
high
advisory
OpenVPN: Multiple Vulnerabilities
3 TTPsA local attacker can exploit multiple vulnerabilities in OpenVPN to achieve arbitrary code execution, manipulate data, or cause a denial of service.
OpenVPN
vulnerability
rce
dos
3t
medium
advisory
BadIIS Malware-as-a-Service Ecosystem Targeting IIS Servers
2 rules 1 TTP 6 IOCsA commodity BadIIS malware variant is fueling a thriving malware-as-a-service (MaaS) ecosystem for Chinese-speaking cybercrime groups, allowing them to execute malicious SEO fraud, hijack server content, and redirect traffic to illicit sites.
Photoshop +3
iis
malware
maas
seo fraud
2r
1t
6i