Skip to content
Threat Feed

Tag

Malware-Delivery

5 briefs RSS
medium advisory

Detection of DLL Downloads via PowerShell Cmdlets

This brief covers the detection of suspicious PowerShell activity involving the use of web download cmdlets to retrieve and save DLL files to the local file system.

windows powershell c2 malware-delivery
1r 2t
rumour rumour

Infrastructure Tracking of Chinese Malware Delivery Operations

This report catalogs domain infrastructure identified in ongoing malware delivery and command-and-control operations linked to Chinese-based threat actors, facilitating improved network-level detection and defensive blocking.

malware-delivery command-and-control threat-intelligence infrastructure-tracking
1t
high threat

Suspicious File Download via Headless Browser

The DUCKTAIL threat actor leverages Chromium-based web browsers (such as Microsoft Edge and Chrome) running in headless mode with the `--dump-dom` argument to stealthily download malicious content from the internet via suspicious file-sharing domains, impacting compromised endpoints.

Brave Browser +4 DUCKTAIL headless-browser file-download data-exfiltration malware-delivery endpoint network
1r 2t 26i
high advisory

Understanding ClickOnce Technology Abuse: Part 1

Threat actors are abusing Microsoft's ClickOnce deployment technology to spread malware, allowing malicious applications to be deployed easily with minimal user interaction and without requiring administrative privileges, ultimately delivering malicious payloads onto user endpoints.

ClickOnce technology +4 clickonce malware-delivery windows endpoint
2t updated
high advisory

Suspicious File Download From File Sharing Domain Via Wget.EXE

This brief details a high-severity threat involving the use of `wget.exe` to download suspicious files from known file-sharing domains, a technique observed in campaigns by threat actors such as FIN7 and Mint Sandstorm, enabling initial malware delivery and subsequent system compromise.

execution malware-delivery command-and-control windows
1r 2t 36i