logo

Publicly Available Tools Seen in Cyber Incidents Worldwide

ID: 6efad030-a9b1-5cb2-a7a7-f55a6e0010af

STIX ID: report--6efad030-a9b1-5cb2-a7a7-f55a6e0010af

Feed Name: CISA Cybersecurity Advisories

Threat Score
75/100

Date Published: 2022-11-17

Date Updated: 2026-04-19

Author: CISA

...
...

This joint advisory from five national cyber authorities details five widely available tools exploited in real incidents—JBiFrost (RAT), China Chopper (webshell), Mimikatz (credential dumper), PowerShell Empire (post-exploitation framework), and HTran (C2/proxy)—describing their capabilities, observed use against critical sectors, detection indicators (hashes, distinctive error strings, network behaviors), and prioritized mitigations for defenders.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.