Microsoft Threat Intelligence observed a human-operated intrusion campaign that abuses Microsoft Teams external collaboration to impersonate IT support, gain remote access, and deploy a Node.js-based ...
Living-off-the-land binaries, often shortened to LOLBins, are legitimate Windows executables that attackers abuse to carry out malicious activity while blending in with normal administration. The ...
Nimbus Manticore uses trojanized coding challenges to deploy NodeRabbit and PollCat RATs across Windows, Linux, and macOS.
Threat actors are abusing legitimate remote-management tools, including ConnectWise ScreenConnect and Microsoft Quick Assist, ...
Researchers have uncovered a Blind Eagle-linked malware operation that uses GitHub repositories, phishing lures, VBScript, ...
Bogus software download sites deploy malware that weakens Windows defenses and establishes persistence in China-based ...
Phishing actors are abusing the legitimate Faronics Deploy endpoint-management platform to gain remote administrative control ...
ChatGPT shared links are used in ClickFix attacks, tricking Windows users into running PowerShell commands that download ...