Tag
SectopRAT Variant Distributed via Tampered Software Installers
3 TTPsThreat actors are distributing a variant of SectopRAT by embedding the malware into legitimate software installers, enabling remote control and credential theft upon execution.
Cross-Platform Malware Campaign via Malicious Google Doc Sidebar
2 TTPsA social engineering campaign delivered via X direct messages leverages a Google Doc sidebar to deliver platform-specific malware, deploying NetSupport Manager on Windows and Atomic macOS Stealer (AMOS) on macOS.
CL-CRI-1171 Pay-Per-Install Infrastructure and Malware Campaign
1 rule 2 TTPs 5 IOCsThe CL-CRI-1171 threat actor operates a large-scale pay-per-install marketplace, leveraging SEO poisoning and YouTube gaming lures to deploy a persistent multi-payload loader used to distribute malware including Insomnia RAT and ARKTunnel.
Zbtlink Router Firmware Contains Embedded ENDLESSDOORS Implant
3 TTPs 1 CVEZbtlink router firmware ships with the ENDLESSDOORS remote-control implant, which runs as root, masquerades as a kernel process, and enables unauthenticated remote command execution.
CastleLoader Malware Loader and ClearFake Activity in July 2026
3 rules 7 TTPs 7 IOCsRed Canary reports heightened activity of the CastleLoader malware loader, which uses paste-and-run techniques and legitimate tools to deliver infostealers and RATs, alongside continued prevalence of the ClearFake activity cluster in June 2026.
Unpacking 'Cruciferra': Analysis of a Sophisticated Crypter Service
1 rule 10 TTPs 11 IOCsCruciferra is a sophisticated crypter-as-a-service, written in Mono, actively developed and sold to multiple cybercriminal threat actors who use it to deliver a wide range of remote access trojans and infostealers, employing extensive defense evasion techniques like BYOVD-based EDR tampering, Process Ghosting, and unique cryptographic obfuscation via email-based phishing campaigns.
Detection of Malicious Remote Access Tools by Antivirus
1 rule 1 TTPThis brief details a Sigma rule designed to detect Antivirus alerts flagging various malicious Remote Access Tools (RATs) such as AgentTesla, AsyncRAT, and NanoCore, highlighting the critical need for investigation into the initial infection vector even when the AV blocks the threat.