Related Threat Clusters
-
MSHTA Utility Exploited in Ongoing Malware Campaigns
Bitdefender researchers have identified that the Microsoft HTML Application Host (MSHTA) utility is being actively exploited by cybercriminals to deliver a variety of malware, including infostealers and loaders. Despite…
8 articles · Updated May 19, 2026 -
Critical FatFs Vulnerabilities Enable Physical Access Attacks on Millions of Devices
Security firm runZero has identified seven unpatched vulnerabilities in the FatFs filesystem driver, affecting millions of embedded devices. These vulnerabilities can be exploited through malicious media or firmware…
11 articles · Updated July 3, 2026 -
DOUBLECUP Service Delivers Malware via Cached PNG Images
The DOUBLECUP loader-as-a-service, identified by SOCRadar, employs ClickFix attacks to conceal malware within PNG images cached by browsers. This service, operational since June 2026, targets Windows and macOS systems,…
4 articles · Updated August 4, 2026 -
CountLoader Malware Campaign Delivers Crypto Clipper via JavaScript and PowerShell
A large-scale malware campaign utilizing CountLoader has been discovered, deploying cryptocurrency clipper malware through a sophisticated infection chain. The attackers employ layered obfuscation and multi-stage…
2 articles · Updated May 19, 2026 -
AdaptixC2 Misused in Ransomware Operations Worldwide
Cybercriminals are increasingly exploiting AdaptixC2, a free emulation framework initially designed for penetration testing, for malicious payload delivery in ransomware attacks. This trend follows the release of new…
1 article · Updated October 31, 2025 -
AdaptixC2 Framework Misused in Ransomware Operations
Cybercriminals are exploiting AdaptixC2, an open-source Command and Control framework originally designed for penetration testing, for ransomware attacks. Recent research indicates a rise in its use for malicious…
1 article · Updated October 31, 2025
Recent Intelligence Reports
- DOUBLECUP turns ClickFix into cached PNG delivery for CountLoader and DeviceManager — Feeds.4Sysops · August 4, 2026
- DOUBLECUP Uses ClickFix and Cached PNGs to Deliver CountLoader and DeviceManager RAT — Thehackernews · August 4, 2026
- New DOUBLECUP ClickFix service hides malware in browser cache images — Bleepingcomputer · August 3, 2026
- Risky Bulletin: FatFs bugs enable physical access attacks on a load of devices — News.Risky.Biz · July 3, 2026
- Malware Campaign Uses JavaScript, PowerShell, and Shellcode to Deliver Crypto Clipper — Cybersecuritynews · May 19, 2026
- Attackers turn ancient Windows utility MSHTA into Swiss Army knife of hacking — Cybernews · May 19, 2026
- Microsoft's MSHTA Legacy Tool Still Powers Malware Campaigns on Windows — Bitdefender · May 19, 2026
- Internet Explorer may be dead, but its ghost still runs malware — Csoonline · May 19, 2026