Tag
Heap-based Buffer Overflow in FreeRDP Windows Clipboard Client
1 CVEA heap-based buffer overflow in FreeRDP versions 3.29.0 and earlier allows a malicious RDP server to execute an out-of-bounds write in the memory of a paste consumer process when handling clipboard file transfers.
Heap Out-of-Bounds Read in FreeRDP Glyph Caching
1 TTP 1 CVEFreeRDP versions 3.28.0 and earlier are vulnerable to a heap out-of-bounds read during the processing of malicious RDP server glyph fragments, allowing for potential client-side crashes or information disclosure.
Shell Command Execution via Elastic Endpoint Console
1 rule 3 TTPsAttackers who compromise Elastic Endpoint console access can leverage its legitimate remote support feature to execute arbitrary shell commands on Linux endpoints, turning it into a command and control channel for persistence, tool deployment, and data exfiltration.
Accepted Default Telnet Port Connection
1 rule 4 TTPsThis threat brief details how threat actors exploit the insecure Telnet protocol on its default port 23 for initial access, lateral movement, and command and control, leveraging its unencrypted nature to compromise systems and exfiltrate data, emphasizing the need for robust detection and mitigation strategies.
Multiple Vulnerabilities in Absolute Secure Access
2 TTPsAn attacker can exploit multiple vulnerabilities in Absolute Secure Access to perform a denial of service attack or disclose confidential information.
Emerging Threat: QuimaRAT, a Cross-Platform Java-Based Remote Access Trojan
2 TTPsQuimaRAT is a newly identified Java-based Remote Access Trojan (RAT) distributed via a Malware-as-a-Service (MaaS) model, capable of targeting Windows, Linux, and macOS systems with a modular architecture for remote access and dynamic functionality expansion.
H3C NX15 Weak Password Recovery Vulnerability (CVE-2026-15479)
2 TTPs 1 CVE 5 IOCsA critical vulnerability, CVE-2026-15479, in H3C NX15 V100R017 allows remote attackers to perform weak password recovery by manipulating the 'newPass' argument in the '/api/login/modify' endpoint, leading to unauthorized administrator access.
RustDesk Authorization Bypass via Session Scope Enforcement Failure (CVE-2026-57850)
1 TTP 1 CVEAn authorization vulnerability exists in RustDesk before version 1.4.9 where the server-side fails to properly enforce connection scope for authenticated peers, allowing an attacker, having been granted a limited session type, to inject control messages typically reserved for a full Remote session and gain unauthorized observation and control over the host.
New Abuse of ClickOnce Technology: Stop Threat Actors from Clicking Once and Staying Forever
2 rules 5 TTPsThreat actors are exploiting Microsoft's ClickOnce technology to achieve initial access, execute malicious payloads, and maintain persistence. This abuse leverages ClickOnce's user-friendly deployment, minimal privilege requirements, and built-in update mechanism to bypass traditional security defenses and execute malware stealthily within legitimate Microsoft processes like rundll32.exe. Adversaries achieve persistence by pushing malicious updates, or by placing ClickOnce shortcut files (.appref-ms) in the Windows Startup folder or configuring them as scheduled tasks.
Suspicious DNS Queries to Remote Monitoring and Management Domains from Non-Browser Processes
1 rule 193 IOCsThis brief details the detection of DNS queries targeting commonly abused Remote Monitoring and Management (RMM) or remote access software domains, originating from non-browser processes, which is a common tactic for command and control, persistence, and lateral movement by threat actors.
VNC (Virtual Network Computing) to the Internet
1 rule 2 TTPsThis brief details the risk of VNC (Virtual Network Computing) traffic originating from internal networks and destined for the internet, indicating potential unauthorized access or a backdoor, as VNC is frequently exploited by threat actors when exposed externally via specific TCP ports (5800-5810).
VNC (Virtual Network Computing) from the Internet
1 rule 3 TTPsThis brief detects unauthorized Virtual Network Computing (VNC) traffic originating from the Internet and targeting internal network segments on TCP ports 5800-5810, indicating potential initial access or backdoor exploitation by threat actors leveraging exposed VNC services.
First Time Seen Remote Monitoring and Management Tool Detection
1 rule 3 TTPs 5 IOCsAdversaries are leveraging legitimate Remote Monitoring and Management (RMM) and remote access tools on Windows endpoints for command-and-control, persistence, and execution, with detection focusing on the first observed instance of these tools on a host.
Tiflux RMM Abused in Malspam Campaign
2 rules 1 TTP 2 IOCsA malspam campaign is leveraging the Tiflux RMM to gain remote access and persistence on victim machines, abusing legitimate remote management software for stealthy access and persistence.
Multiple Vulnerabilities in Oracle Java SE
2 rules 1 TTPA remote attacker, either anonymous or authenticated, can exploit multiple vulnerabilities in Oracle Java SE to compromise confidentiality, integrity, and availability.
Vulnerabilities Disclosed in IP KVM Devices from Multiple Vendors
2 rules 2 TTPsResearchers have disclosed unspecified vulnerabilities in IP KVM devices from four manufacturers, potentially allowing attackers to gain unauthorized access to connected systems.
VScode Remote Tunnel Abuse for Command and Control
2 rules 1 TTPAdversaries are leveraging the VScode remote tunnel feature to establish unauthorized access and control over Windows systems, potentially enabling command and control activities via disguised legitimate software.
Detection of Suspicious VScode Remote Tunnel Usage
2 rules 1 TTPThis brief details the detection of potential command and control activity through the suspicious use of the VScode remote tunnel feature, which allows attackers to establish unauthorized remote access to systems.
Remote Management Software Launch After MSI Install
3 rulesAttackers are leveraging MSI installers to deploy remote management software (RMM) such as ScreenConnect, Syncro, and VNC, potentially indicating unauthorized access and control over compromised systems.
First Time Seen Remote Monitoring and Management Tool Execution
3 rulesDetects the execution of previously unseen remote monitoring and management (RMM) tools or remote access software on compromised Windows endpoints, often leveraged for command-and-control, persistence, and execution of malicious commands.
Suspicious Remote File Copy via TeamViewer
2 rules 2 TTPsAttackers may abuse TeamViewer, a legitimate remote access tool, to transfer malware or tools into a compromised environment by creating executable or script files with suspicious extensions.
Remote Management Access Launch After MSI Install
2 rulesDetects a suspicious sequence of an MSI installer execution immediately followed by the execution of commonly abused Remote Management Software, potentially indicating unauthorized remote access.
Newly Observed ScreenConnect Host Server
2 rules 1 TTPDetection of ScreenConnect clients connecting to a newly observed host server outside the official ScreenConnect cloud, potentially indicating command and control activity or compromise.
Suspicious DNS Queries to RMM Domains from Non-Browser Processes
2 rulesDetection of DNS queries to remote monitoring and management (RMM) domains from non-browser processes indicating potential misuse of legitimate remote access tools for command and control.
Detection of Windows RMM Tool Execution
3 rules 1 TTPDetects process creation events indicative of remote management tools, potentially signifying legitimate use or malicious exploitation by threat actors abusing RMM software.
Remote File Copy via TeamViewer
2 rules 2 TTPsAttackers may abuse legitimate utilities such as TeamViewer to deploy malware interactively by remotely copying executable or script files during a TeamViewer session.
Detection of Level RMM Watchdog Task Creation
2 rules 2 TTPsThe creation of the 'Level Watchdog' task, indicative of the Level remote management tool installation, is detected, highlighting the potential abuse of legitimate RMM tools for persistence and execution by threat actors on Windows systems.