Severity
HEAVYGRAM Telegram-based Surveillance Backdoor
1 TTPHEAVYGRAM is a Windows-based surveillance backdoor used by Handala Hack that utilizes the Telegram API for command-and-control communication to facilitate remote information theft and system monitoring.
SparroWock Backdoor Analysis
2 TTPsSparroWock is a backdoor malware that utilizes custom command-and-control communication mechanisms to execute arbitrary commands on compromised Windows systems, establishing persistence to maintain long-term access.
SilkParasite Campaign Infrastructure Analysis
1 TTPAnalysis of the SilkParasite campaign reveals a 13-server command-and-control cluster facilitating the deployment of SpiceRAT against targets in Central Asia.
Linux Local Privilege Escalation Detection Framework
1 TTPThis brief summarizes a detection engineering framework from Elastic Security Labs for identifying post-exploitation activity and system misconfigurations associated with Linux local privilege escalation.
Monitoring Malicious Use of SCCM Application Execution
1 TTPThis brief documents the execution mechanics of Microsoft System Center Configuration Manager (SCCM), identifying risks where adversary-controlled software or scripts are deployed through the SCCM client infrastructure.
Abuse of Faronics Deploy for Remote Execution and Persistence
1 rule 1 TTPThreat actors are exploiting compromised Faronics Deploy management consoles to push malicious scripts and binaries, enabling unauthorized remote code execution and persistence across managed enterprise endpoints.
NachoMDM Vulnerability in Windows MDM Enrollment
2 TTPsNachoMDM is a vulnerability within the Windows Mobile Device Management (MDM) enrollment process that allows an attacker to achieve UAC bypass and execute arbitrary code with SYSTEM privileges.
Infrastructure Tracking of Chinese Malware Delivery Operations
1 TTPThis report catalogs domain infrastructure identified in ongoing malware delivery and command-and-control operations linked to Chinese-based threat actors, facilitating improved network-level detection and defensive blocking.
Lightweight Backdoor Uses desktop.ini Whitespace for C2 Configuration
1 TTPA 12 KB Windows backdoor evades traditional detection by storing its command-and-control infrastructure within hidden whitespace characters inside standard desktop.ini configuration files.