logo

Halcyon Threat Insights 002: February 2024

ID: d573909d-1ea4-5ddc-8f5c-3328d6b4338c

STIX ID: report--d573909d-1ea4-5ddc-8f5c-3328d6b4338c

Feed Name: Halcyon Blog

Threat Score
70/100

Date Published: 2026-03-02

Date Updated: 2026-04-28

...
...

Halcyon detected and blocked a range of stealthy malware in February 2024 that act as precursors to ransomware — notably Trojans and stealers (ClipBanker, Doina, RedLine, VMProtect-packed samples, Malgent/RedCap) — with Finance, IT, and Education the most targeted verticals; the report highlights common TTPs such as evasion (AV whitelisting, anti-VM), DGA-based PowerShell, credential theft, lateral movement, C2, and data exfiltration used to enable double extortion ransomware operations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.