TA547 threat actor targets German orgs with Rhadamanthys info-stealer
The group appears to have incorporated LLM-generated PowerShell scripts in their attacks.
The group appears to have incorporated LLM-generated PowerShell scripts in their attacks.
The company will alert users who are individually targeted by mercenary spyware attacks.
The proposed order aims to mitigate any perceived threats posed to critical US infrastructure.
The files contained passwords, keys, and credentials.
The group engages in illicit activities like cryptomining, DDoS attacks and phishing.
April 2024 Patch Tuesday addresses over 100 vulnerabilities in various products.
The FlexStarling malware is delivered via malicious Android apps disguised as legitimate tools.
The threat actor took between 36 seconds and 47 minutes from initial access to the attempt to install an RMM tool or backdoor.
Attackers are now leveraging malware-infected hosts to initiate scanning requests.
The group uses specific tools, such as the customized variant of QuasarRAT and the XClient stealer.
Showing elements 1491 - 1500