IT threat evolution Q3 2024
ID: 5bbd8cc3-9010-57d0-9581-051084e1b6d0
STIX ID: report--5bbd8cc3-9010-57d0-9581-051084e1b6d0
Feed Name: Securelist by Kaspersky
This Q3 2024 threat report describes multiple active and emerging cyber threats: a new APT (CloudSorcerer) using cloud APIs and GitHub for C2, ongoing campaigns by groups like BlindEagle and Tropic Trooper, hacktivist activity linking Twelve and BlackJack, diverse ransomware operations (SEXi, Key Group, Mallox), macOS and cross-platform backdoors (HZ Rat, Loki), infostealer/clipper campaigns under “Tusk”, and targeted RAT campaigns (SambaSpy) — collectively demonstrating cloud abuse, DLL side-loading, exploitation of WinRAR CVE-2023-38831, and widespread active exploitation against governments, enterprises and regional victims.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
