Datadog threat roundup: Top insights for Q1 2025
ID: 1ea8eab9-7136-56a6-bd63-428d94dcd956
STIX ID: report--1ea8eab9-7136-56a6-bd63-428d94dcd956
Feed Name: Datadog Security Labs
Datadog's Q1 2025 threat roundup details a range of cloud-focused and supply-chain threats: trojanized npm packages (including a compromised Rspack release) delivering cryptojacking and infostealers, multiple malicious npm campaigns that add SSH backdoors or deploy RATs, credential harvesting targeting Huawei/Alibaba/Tencent cloud users, opportunistic exploitation of internet-facing services and IoT (XorBot activity and Spring Boot-targeting droppers), and abuse of customer infrastructure for censorship-bypass proxies and miners; the report includes technical indicators, code snippets, IOCs, and mitigation guidance such as access key rotation, BEC/OAuth detection, and expanded monitoring.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
