Cyble Sensors Detect WordPress Plugin Attack, New Trojan
ID: 5ec049ba-2dbc-56c3-a0c1-d4bbf8c7ef0a
STIX ID: report--5ec049ba-2dbc-56c3-a0c1-d4bbf8c7ef0a
Feed Name: Cyble Blog
Cyble's Threat Hunting Honeypot sensors detected active exploitation of multiple critical vulnerabilities (including several 9.x CVEs and unauthenticated RCEs), a new Octo2 banking trojan variant targeting European banks with DGA and device-takeover capabilities, more than 400 scam email addresses, and thousands of brute-force attacks against common service ports; the report includes IoCs (file hashes, package names, scam emails), attacker port distributions, and remediation recommendations (patching, blocking hashes/URLs/IPs/ports, resetting credentials).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
