Tag
Rogue ScreenConnect Clients Distribute Four-Stage VBScript Malware
1 rule 6 TTPs 4 IOCsThreat actors are using compromised ConnectWise ScreenConnect instances to propagate a worm-like, four-stage VBScript infection chain that enables backdooring, UAC bypass, and cryptojacking on connected hosts.
Worm-like Campaign Leveraging Modified ScreenConnect Clients
1 rule 4 TTPs 1 CVEThreat actors are using social engineering to deploy modified, backdoored ScreenConnect clients that automate multi-stage payload execution and self-propagation across connected remote hosts.
Hard-coded Credentials in SmartIT Desktop Manager
1 TTP 1 CVESmartIT Desktop Manager contains a hard-coded credentials vulnerability that allows unauthenticated remote attackers to retrieve SSH service account credentials for the SmartIT Agent via application source code.
CVE-2026-85440: Heap Overflow in MOOS core-moos
5 TTPs 1 CVEA pre-authentication heap overflow vulnerability in the MOOSCommPkt packet handling of MOOS core-moos versions up to 10.4.0 allows remote unauthenticated attackers to perform arbitrary memory writes via crafted packets.
Detection of TeamViewer Desktop Installation
1 ruleThis brief documents the detection of TeamViewer Desktop installation via file system activity, often associated with Remote Access Software usage.
Detection of GoToAssist Remote Support Temporary Artifacts
1 ruleAdversaries often abuse legitimate remote access software like GoToAssist to establish interactive command-and-control channels, leaving specific temporary artifacts in the user's local profile.
Threat Actors Impersonate IT Support via Microsoft Teams to Deploy Node.js Implants
1 rule 2 TTPsThreat actors impersonate IT helpdesk staff in Microsoft Teams to socially engineer users into granting remote access, subsequently deploying a Node.js-based implant for reconnaissance and lateral movement.
Improper Client-Side Security Enforcement in tsi-dpdp-cms
1 CVEThe tsi-dpdp-cms software contains a vulnerability in versions 0.5.0 and earlier that improperly relies on client-side enforcement for security controls, allowing for remote exploitation via publicly available exploit code.
Abuse of Faronics Deploy for Remote Execution and Persistence
1 rule 1 TTPThreat actors are exploiting compromised Faronics Deploy management consoles to push malicious scripts and binaries, enabling unauthorized remote code execution and persistence across managed enterprise endpoints.
Unauthorized VNC Exposure to the Internet
1 rule 2 TTPsThe exposure of VNC services to the public internet enables unauthorized remote access, providing adversaries a vector for initial access or persistent backdoors.
Multiple Vulnerabilities in TeamViewer Client
1 TTPTeamViewer clients are affected by multiple vulnerabilities that allow an unauthenticated or local attacker to execute arbitrary code with the privileges of the logged-in user.
Veeam ONE Security Bypass Vulnerability
1 TTP 1 CVEA vulnerability in Veeam ONE allows a remote, unauthenticated attacker to bypass security protections, potentially leading to unauthorized access to monitoring functions.
Data Manipulation Vulnerability in Devolutions Remote Desktop Manager
1 CVEA vulnerability in Devolutions Remote Desktop Manager allows a remote, unauthenticated attacker to manipulate data, leading to unauthorized modification risks.
Unauthenticated Access Vulnerability in FitSoft POS System
1 TTP 1 CVEFitSoft POS System contains a missing authentication vulnerability that allows unauthenticated remote attackers to gain unauthorized access and control over the platform.
Flooding Dropper npm Supply Chain Campaign
3 TTPsAn automated supply chain campaign targeting npm, deploying multi-stage loaders across 850+ malicious packages that utilize DNS TXT fallback for C2 and reflective payload execution.
Heap-based Buffer Overflow in FreeRDP Windows Clipboard Client
1 CVEA heap-based buffer overflow in FreeRDP versions 3.29.0 and earlier allows a malicious RDP server to execute an out-of-bounds write in the memory of a paste consumer process when handling clipboard file transfers.
Heap Out-of-Bounds Read in FreeRDP Glyph Caching
1 TTP 1 CVEFreeRDP versions 3.28.0 and earlier are vulnerable to a heap out-of-bounds read during the processing of malicious RDP server glyph fragments, allowing for potential client-side crashes or information disclosure.
Shell Command Execution via Elastic Endpoint Console
1 rule 3 TTPsAttackers who compromise Elastic Endpoint console access can leverage its legitimate remote support feature to execute arbitrary shell commands on Linux endpoints, turning it into a command and control channel for persistence, tool deployment, and data exfiltration.
Accepted Default Telnet Port Connection
1 rule 4 TTPsThis threat brief details how threat actors exploit the insecure Telnet protocol on its default port 23 for initial access, lateral movement, and command and control, leveraging its unencrypted nature to compromise systems and exfiltrate data, emphasizing the need for robust detection and mitigation strategies.
Multiple Vulnerabilities in Absolute Secure Access
2 TTPsAn attacker can exploit multiple vulnerabilities in Absolute Secure Access to perform a denial of service attack or disclose confidential information.
Emerging Threat: QuimaRAT, a Cross-Platform Java-Based Remote Access Trojan
2 TTPsQuimaRAT is a newly identified Java-based Remote Access Trojan (RAT) distributed via a Malware-as-a-Service (MaaS) model, capable of targeting Windows, Linux, and macOS systems with a modular architecture for remote access and dynamic functionality expansion.
H3C NX15 Weak Password Recovery Vulnerability (CVE-2026-15479)
2 TTPs 1 CVE 5 IOCsA critical vulnerability, CVE-2026-15479, in H3C NX15 V100R017 allows remote attackers to perform weak password recovery by manipulating the 'newPass' argument in the '/api/login/modify' endpoint, leading to unauthorized administrator access.
RustDesk Authorization Bypass via Session Scope Enforcement Failure (CVE-2026-57850)
1 TTP 1 CVEAn authorization vulnerability exists in RustDesk before version 1.4.9 where the server-side fails to properly enforce connection scope for authenticated peers, allowing an attacker, having been granted a limited session type, to inject control messages typically reserved for a full Remote session and gain unauthorized observation and control over the host.
New Abuse of ClickOnce Technology: Stop Threat Actors from Clicking Once and Staying Forever
2 rules 5 TTPsThreat actors are exploiting Microsoft's ClickOnce technology to achieve initial access, execute malicious payloads, and maintain persistence. This abuse leverages ClickOnce's user-friendly deployment, minimal privilege requirements, and built-in update mechanism to bypass traditional security defenses and execute malware stealthily within legitimate Microsoft processes like rundll32.exe. Adversaries achieve persistence by pushing malicious updates, or by placing ClickOnce shortcut files (.appref-ms) in the Windows Startup folder or configuring them as scheduled tasks.
Suspicious DNS Queries to Remote Monitoring and Management Domains from Non-Browser Processes
1 rule 193 IOCsThis brief details the detection of DNS queries targeting commonly abused Remote Monitoring and Management (RMM) or remote access software domains, originating from non-browser processes, which is a common tactic for command and control, persistence, and lateral movement by threat actors.
VNC (Virtual Network Computing) to the Internet
1 rule 2 TTPsThis brief details the risk of VNC (Virtual Network Computing) traffic originating from internal networks and destined for the internet, indicating potential unauthorized access or a backdoor, as VNC is frequently exploited by threat actors when exposed externally via specific TCP ports (5800-5810).
VNC (Virtual Network Computing) from the Internet
1 rule 3 TTPsThis brief detects unauthorized Virtual Network Computing (VNC) traffic originating from the Internet and targeting internal network segments on TCP ports 5800-5810, indicating potential initial access or backdoor exploitation by threat actors leveraging exposed VNC services.
First Time Seen Remote Monitoring and Management Tool Detection
1 rule 3 TTPs 5 IOCsAdversaries are leveraging legitimate Remote Monitoring and Management (RMM) and remote access tools on Windows endpoints for command-and-control, persistence, and execution, with detection focusing on the first observed instance of these tools on a host.
Tiflux RMM Abused in Malspam Campaign
2 rules 1 TTP 2 IOCsA malspam campaign is leveraging the Tiflux RMM to gain remote access and persistence on victim machines, abusing legitimate remote management software for stealthy access and persistence.
Multiple Vulnerabilities in Oracle Java SE
2 rules 1 TTPA remote attacker, either anonymous or authenticated, can exploit multiple vulnerabilities in Oracle Java SE to compromise confidentiality, integrity, and availability.
Vulnerabilities Disclosed in IP KVM Devices from Multiple Vendors
2 rules 2 TTPsResearchers have disclosed unspecified vulnerabilities in IP KVM devices from four manufacturers, potentially allowing attackers to gain unauthorized access to connected systems.
VScode Remote Tunnel Abuse for Command and Control
2 rules 1 TTPAdversaries are leveraging the VScode remote tunnel feature to establish unauthorized access and control over Windows systems, potentially enabling command and control activities via disguised legitimate software.
Detection of Suspicious VScode Remote Tunnel Usage
2 rules 1 TTPThis brief details the detection of potential command and control activity through the suspicious use of the VScode remote tunnel feature, which allows attackers to establish unauthorized remote access to systems.
Remote Management Software Launch After MSI Install
3 rulesAttackers are leveraging MSI installers to deploy remote management software (RMM) such as ScreenConnect, Syncro, and VNC, potentially indicating unauthorized access and control over compromised systems.
First Time Seen Remote Monitoring and Management Tool Execution
3 rulesDetects the execution of previously unseen remote monitoring and management (RMM) tools or remote access software on compromised Windows endpoints, often leveraged for command-and-control, persistence, and execution of malicious commands.
Suspicious Remote File Copy via TeamViewer
2 rules 2 TTPsAttackers may abuse TeamViewer, a legitimate remote access tool, to transfer malware or tools into a compromised environment by creating executable or script files with suspicious extensions.
Remote Management Access Launch After MSI Install
2 rulesDetects a suspicious sequence of an MSI installer execution immediately followed by the execution of commonly abused Remote Management Software, potentially indicating unauthorized remote access.
Newly Observed ScreenConnect Host Server
2 rules 1 TTPDetection of ScreenConnect clients connecting to a newly observed host server outside the official ScreenConnect cloud, potentially indicating command and control activity or compromise.
Suspicious DNS Queries to RMM Domains from Non-Browser Processes
2 rulesDetection of DNS queries to remote monitoring and management (RMM) domains from non-browser processes indicating potential misuse of legitimate remote access tools for command and control.
Detection of Windows RMM Tool Execution
3 rules 1 TTPDetects process creation events indicative of remote management tools, potentially signifying legitimate use or malicious exploitation by threat actors abusing RMM software.
Remote File Copy via TeamViewer
2 rules 2 TTPsAttackers may abuse legitimate utilities such as TeamViewer to deploy malware interactively by remotely copying executable or script files during a TeamViewer session.
Detection of Level RMM Watchdog Task Creation
2 rules 2 TTPsThe creation of the 'Level Watchdog' task, indicative of the Level remote management tool installation, is detected, highlighting the potential abuse of legitimate RMM tools for persistence and execution by threat actors on Windows systems.