logo

LevelBlue SpiderLabs Blog

ID: 9f9267fd-0707-5078-b951-6540ac6dc523

STIX ID: identity--9f9267fd-0707-5078-b951-6540ac6dc523

Feed Type: rss

Earliest post: 2025-10-29

Latest post: 2026-08-10

The security community's go-to destination for technical breakdowns of the latest threats, critical vulnerability disclosures and cutting-edge research.

01/01/2020
08/11/2026
Title Date Published Describes IncidentAuthorVisible
Beyond ‘Fake Updates’: From Application Store-Themed Phishing to Large-Scale Distribution of ScreenConnect2026-08-07TrueKing Orande and Cris TombocTrue
Release the RAVEN: Exploiting the Cracks2026-08-06TrueKarl BironTrue
Release the RAVEN: First Contact2026-08-05TrueKarl BironTrue
Review of the July 2026 Cyberattacks Against U.S. Water and Wastewater Systems2026-08-04TrueNikita KazymirskyiTrue
Release the RAVEN: An Offensive Reconnaissance and Attack Tool on Vulnerable Elasticsearch Nodes2026-07-29TrueKarl BironTrue
LegacyHive: Hunting Windows Profile Initialization Abuse Through Offline Registry Manipulation2026-07-27TrueSerhii Melnyk and Timmy ListerTrue
LevelBlue TTP Briefing Q2 2026: Stolen Identities Outpace Defenses2026-07-23TrueTrue
Exploitarium: Inside the Archive Behind the Mass 0-Day Drop2026-07-21TrueSerhii MelnykTrue
LegacyHive: Nightmare-Eclipse’s Latest Zero-Day Drop with a Stripped PoC2026-07-20TruePauline BolañosTrue
Still Circling: Blind Eagle's Toolkit Keeps Evolving2026-07-17TrueSerhii MelnykTrue
ClickFix on macOS: Blockchain-Powered Infostealer Hidden Inside Compromised Websites2026-07-16TrueRodel MendrezTrue
Mitigating New Vulnerabilities with owLSM2026-07-13TrueTrue
Hiding in the Chain: Multi-Stage LNK Attack Leveraging TON Blockchain to Deliver Node.JS Backdoor2026-07-09TrueNathaniel MoralesTrue
From Phishing to Persistence: A CrySome RAT Infection Chain Analysis2026-07-06TrueSean Shirley and Kyle SoptTrue
AsyncRAT and Remcos Delivered in Multi-Stage Phishing Campaign2026-07-02TrueLevelBlue SpiderLabsTrue
An Analysis of ValleyRAT Infection Campaigns from Fake Installers, Japanese Malicious Emails2026-06-30TrueHajime TakaiTrue
Novel Java-Based QuimaRAT Targets Windows, macOS, and Linux2026-06-25TrueTrue
LokiBot After a Decade: An Analysis of a Recent LokiBot Campaign2026-06-24TrueDawid NesterowiczTrue
Operation FlutterBridge: The FlutterShell macOS Backdoor2026-06-18TrueMaor GabayTrue
RoguePlanet and GreatXML: Detecting Local Privilege Escalation and BitLocker Security Boundary Abuse2026-06-17TrueSerhii MelnykTrue
Reversing NVIDIA’s CVE-2026-24190: How a Kernel Flaw Put Enterprise AI Clusters and Workstations at Risk2026-06-15TrueAlon BancicTrue
The Device Code Phishing Tsunami: What We’re Seeing in the Wild2026-06-09TrueJohn Kevin AdrianoTrue
macOS ClickFix Social Engineering Campaigns2026-06-04TrueMaor GabayTrue
ClickFix Is Now Hiring: From Job Platform Impersonation to Python-Based RAT Delivery2026-06-04TrueKing Orande and Cris TombocTrue
The Demon Arrives Later: A Havoc Stager Hides Behind Microsoft Defender DLP2026-06-03TrueJose MartinTrue
Sapphire Sleet Targets macOS in Multi-Stage Intrusion Campaign2026-05-28TrueMaor GabayTrue
From WinRE to SYSTEM: Hunting the YellowKey and MiniPlasma Attack Chain2026-05-22TrueTrue
YellowKey and GreenPlasma: Two New Windows Zero-Days Unveiled2026-05-19TrueJames BallantyneTrue
A Closer Look at The Gentlemen’s Alleged Leak2026-05-18TrueArthur ErzbergerTrue
Threat Analysis: Backdoored Electron Apps Evading Defenses2026-05-08TrueMichael MoroseTrue
Unmasking a Multi-Stage Loader: AutoIt Abuse Leading to Vidar Stealer Command-and-Control Communication2026-05-07TrueMahadev JoshiTrue
LevelBlue TTP Briefing Q1 2026: Trust Abuse Exposes Weaknesses2026-05-05TrueTrue
Inside Vect Ransomware-as-a-Service2026-04-30TrueSpiderLabs ResearcherTrue
Hacking Hotels via Smart Stationary Bikes: How Unsecured Gym Equipment Can Lead to RCE2026-04-29TrueJohn LopezTrue
Crypto Drainers as a Converging Threat: Insights into Emerging Hybrid Attack Ecosystems2026-04-23TrueSerhii Melnyk, King Orande, Cris Tomboc, Sean ShirleyTrue
A Closer Look at the Novel and Stealthy KarstoRAT Malware2026-04-21TrueChen AvianiTrue
Go With the Flow: Abusing OAuth Device Code Flow2026-04-20TrueJakub WiewiorskiTrue
RedSun and the Expanding Risk Window: Why Microsoft Defender Patching Can’t Wait2026-04-17TrueTrue
Why Attackers Are Bypassing Phishing Emails and Targeting Identity Instead2026-04-13TrueJamie MamroeTrue
Trojanized CPUID HWMonitor Installer Delivers Fileless .NET Payload via Obfuscated IPv6 Scriptlet2026-04-10TrueSean ShirleyTrue
Axios NPM Package Supply Chain Compromise Leads to RAT Deployment2026-04-09TrueMahadev Joshi and Sho KishimotoTrue
Err-Hiding and Seek: How ErrTraffic v3 Leverages EtherHiding in ClickFix Campaign2026-04-09TrueKing Orande and Cris TombocTrue
Major Supply Chain Compromise in the Popular axios npm Package2026-04-03TrueKarl SiglerTrue
Using RF Power Levels to Defeat MAC Address Randomization Enabling Passive Device Tracking2026-03-31TrueTom NeavesTrue
Azure ServiceBus WebSockets as a C2 Channel2026-03-24TrueStuart WhiteTrue
Tracing a Multi-Vector Malware Campaign: From VBS to Open Infrastructure 2026-03-23TrueSean ShirleyTrue
“Say My Name”: How MioLab is building MacOS Stealer Empire2026-03-20TrueMark Tsipershtein and Evgeny AnaninTrue
Fake CAPTCHA Campaign: Inside a Multi-Stage Stealer Assault2026-03-19TrueShabtay Barel, Serhii Melnyk, Rodel MendrezTrue
KongTuke: A King Among Threat Groups2026-03-18TrueTrue
How LevelBlue OTX and Cybereason XDR Detected a North Korea-Linked Remote IT Worker2026-03-17TrueTue LuuTrue

1–50 of 92