IntroductionIn June 2026, Zscaler ThreatLabz identified a new malware family, tracked as SloppyRAT, that is likely leveraged by a ransomware-related threat actor. ThreatLabz observed SloppyRAT being ...
Living-off-the-land binaries, often shortened to LOLBins, are legitimate Windows executables that attackers abuse to carry out malicious activity while blending in with normal administration. The ...
Windows 11 ISO download: get the official ISO, verify SHA-256, create a bootable USB with Rufus, and follow the steps to ...
Cybercriminals are abusing legitimate ChatGPT shared-conversation pages to deliver NetSupport RAT through a multi-stage ...
Threat actors are increasingly exploiting overlooked Active Directory service principal name misconfigurations, making ordinary domain accounts vulnerable to Kerberoasting.
The ClickFix-style campaign features a sophisticated, multistage attack chain that includes reverse tunnels into victim ...
TerminalFix tricks victims into running malicious PowerShell commands, launching a multi-stage attack that ends with a ...
The pages impersonate Cloudflare and other trusted services. Instead of presenting a normal CAPTCHA challenge, they instruct users to open PowerShell or Command Prompt and paste ...
Microsoft Threat Intelligence provides analysis of a ClickFix campaign that uses fake CAPTCHA prompts, DLL sideloading, and a reverse tunnel, with detections and hunting guidance.
Microsoft Threat Intelligence has discovered TerminalFix, a campaign that uses fake CAPTCHAs to trick users into running PowerShell scripts.
A massive cybercriminal operation is leveraging thousands of compromised small-business websites to deliver ClickFix payloads ...
Microsoft Threat Intelligence observed a human-operated intrusion campaign that abuses Microsoft Teams external collaboration to impersonate IT support, gain remote access, and deploy a Node.js-based ...
Some results have been hidden because they may be inaccessible to you
Show inaccessible results