WebSockets is a technology platform tracked across 4 threat clusters and 4 intelligence report mentions on ThreatCluster. First observed December 23, 2025; most recent activity April 13, 2026.
WebSockets is a protocol that enables real-time, bidirectional communication over a single TCP connection, commonly used by modern web applications for live updates and interactive features. In cybersecurity, WebSockets can provide a persistent, low-latency transport for command-and-control, data exfiltration, and evading network controls due to its legitimate use in enterprise traffic. The cited articles illustrate how threat actors leverage web-based protocols and real-time channels in evolving campaigns, highlighting WebSockets as a relevant transport in contemporary intrusions.
Mirax, a newly identified Android Remote Access Trojan (RAT) and banking malware, has emerged as a significant threat, particularly in Spanish-speaking regions. It was first observed on underground forums in December…
The cybercriminal group TA584 has intensified its operations by deploying Tsundere Bot malware through ClickFix social engineering tactics. This initial access broker has significantly increased its campaign volume,…
A malicious npm package named lotusbail, masquerading as a WhatsApp Web API library, has been found to steal WhatsApp messages, credentials, and contacts. This package has been available for at least six months and has…
Proofpoint reported a significant increase in activity from the cybercriminal group TA584 in 2025. The group is linked to initial access brokering and follow-on attacks, including ransomware and data theft, utilizing…