WebSockets — Cyber Threats, Attacks & Incidents

Threat entity extracted from intelligence sources

Frequency
4
occurrences
First Seen
December 23, 2025
Last Seen
April 13, 2026

WebSockets is a technology platform tracked across 4 threat clusters and 4 intelligence report mentions on ThreatCluster. First observed December 23, 2025; most recent activity April 13, 2026.

Overview

WebSockets is a protocol that enables real-time, bidirectional communication over a single TCP connection, commonly used by modern web applications for live updates and interactive features. In cybersecurity, WebSockets can provide a persistent, low-latency transport for command-and-control, data exfiltration, and evading network controls due to its legitimate use in enterprise traffic. The cited articles illustrate how threat actors leverage web-based protocols and real-time channels in evolving campaigns, highlighting WebSockets as a relevant transport in contemporary intrusions.

Related Threat Clusters

  • Mirax Android RAT Transforms Infected Devices into Proxy Nodes

    Mirax, a newly identified Android Remote Access Trojan (RAT) and banking malware, has emerged as a significant threat, particularly in Spanish-speaking regions. It was first observed on underground forums in December…

    9 articles · Updated April 13, 2026
  • TA584 Expands Operations with Tsundere Bot via ClickFix Social Engineering

    The cybercriminal group TA584 has intensified its operations by deploying Tsundere Bot malware through ClickFix social engineering tactics. This initial access broker has significantly increased its campaign volume,…

    5 articles · Updated January 29, 2026
  • Malicious npm Package Steals WhatsApp Accounts and Messages

    A malicious npm package named lotusbail, masquerading as a WhatsApp Web API library, has been found to steal WhatsApp messages, credentials, and contacts. This package has been available for at least six months and has…

    5 articles · Updated December 22, 2025
  • TA584 Cybercriminal Group Intensifies Email Attacks in 2025

    Proofpoint reported a significant increase in activity from the cybercriminal group TA584 in 2025. The group is linked to initial access brokering and follow-on attacks, including ransomware and data theft, utilizing…

    2 articles · Updated January 30, 2026

Recent Intelligence Reports

  • Mirax Android Trojan Turns Devices Into Residential Proxy Nodes — Infosecurity-Magazine · April 13, 2026
  • Proofpoint details TA584's fast-evolving 2025 attacks — Securitybrief.Au · January 30, 2026
  • Initial access hackers switch to Tsundere Bot for ransomware attacks — Bleepingcomputer · January 28, 2026
  • WhatsApp API worked exactly as promised, and stole everything — Csoonline · December 23, 2025

CVSS v3.1 Breakdown