Related Threat Clusters
-
GrayAlpha Threat Actor Uses MaskBat Loader for NetSupport RAT Deployments
Insikt Group identified GrayAlpha, a threat actor linked to FIN7, utilizing a custom loader named MaskBat to deploy NetSupport RAT through various infection vectors. These include fake browser update pages, fake 7-Zip…
2 articles · Updated August 6, 2026 -
Hackers Exploit QEMU VMs to Evade Detection and Deploy Ransomware
Hackers are utilizing QEMU, an open-source virtual machine emulator, to create hidden Linux environments within Windows systems, effectively evading endpoint security tools. This method allows for long-term access,…
8 articles · Updated April 17, 2026 -
Critical Vulnerabilities Discovered in Mozilla Products
Multiple vulnerabilities have been identified in Mozilla products, with the most severe allowing for arbitrary code execution. Exploitation could enable attackers to install programs, access, modify, or delete data, and…
44 articles · Updated April 8, 2026 -
Chrome Vulnerabilities Allow Arbitrary Code Execution and System Crashes
Google has released a critical security update for Chrome, addressing two high-severity vulnerabilities that could allow arbitrary code execution and denial-of-service attacks. Users on Windows, macOS, and Linux are…
503 articles · Updated February 4, 2026
Recent Intelligence Reports
- T1189 — attack.mitre.org · August 7, 2026
- Payouts King ransomware uses QEMU VMs to bypass endpoint security — Bleepingcomputer · April 17, 2026