Skip to content
Threat Feed

Tag

Cross-Platform

8 briefs RSS
medium advisory

Detection of Unauthorized Hosts File Modifications

Adversaries manipulate endpoint hosts files to intercept network traffic, enabling malicious infrastructure redirection or the disruption of security services such as MFA.

impact persistence cross-platform
1r 1t updated
medium advisory

Detection of Web Server Access Log Deletion

Adversaries often delete web server access logs to destroy forensic evidence and evade detection after unauthorized activity, a behavior monitorable through file deletion events on common web server log paths.

HTTP Server +1 defense-evasion file-integrity logs cross-platform
1r 1t updated
medium advisory

Detection of Anomalous SOCKS Proxy Traffic via FortiGate Integration

This detection leverages cross-platform correlation between FortiGate network application logs and endpoint telemetry to identify processes acting as SOCKS proxies for potential command and control obfuscation.

FortiGate command-and-control proxy network-security cross-platform
1t updated
medium advisory

Correlation of Palo Alto Networks C2 Alerts with Endpoint Process Activity

This detection capability correlates Palo Alto Networks (PANW) firewall command and control alerts with Elastic Defend endpoint events to identify the specific process responsible for network traffic flagged as malicious.

PAN-OS +1 command-and-control detection-engineering network-security cross-platform
1t
high threat

Nimbus Manticore Targets Developers with Node.js-based Cross-Platform RATs

The Iranian threat actor Nimbus Manticore is distributing NodeRabbit and PollCat cross-platform RATs via trojanized coding challenges on LinkedIn to compromise developer systems.

VS Code +1 Nimbus Manticore espionage rat phishing recruitment cross-platform
1r 3t 3i
high threat

UAT-10147 Deploys SPECTRE Cross-Platform Backdoor

The threat actor UAT-10147 is deploying a sophisticated cross-platform backdoor named SPECTRE, featuring kernel-level rootkits, BYOVD defense evasion, and AI-assisted development artifacts to target IIS and Linux infrastructure.

Internet Information Services UAT-10147 backdoor cross-platform rootkit byovd e-commerce-fraud cybercrime agentic-ai web-exploitation +1
2r 6t 2i updated
high advisory

Emerging Threat: QuimaRAT, a Cross-Platform Java-Based Remote Access Trojan

QuimaRAT is a newly identified Java-based Remote Access Trojan (RAT) distributed via a Malware-as-a-Service (MaaS) model, capable of targeting Windows, Linux, and macOS systems with a modular architecture for remote access and dynamic functionality expansion.

RAT MaaS Java cross-platform remote-access
2t
high advisory

Web Server Potential SQL Injection Attempt Detection

This brief details the detection of potential SQL injection (SQLi) attempts against web servers by identifying common SQLi patterns in URLs and query strings, used by threat actors for reconnaissance, data exfiltration, or command execution, aiming for sensitive information disclosure or system compromise.

Apache +5 sql-injection web-attack reconnaissance initial-access data-exfiltration command-execution persistence cross-platform
1r 6t