MSBuild is a tool tracked across 9 threat clusters and 13 intelligence report mentions on ThreatCluster. First observed January 5, 2026; most recent activity July 5, 2026.
Chinese state-backed group TA416 has reemerged with intensified cyber espionage campaigns targeting European governments, following a quiet period since 2023. Proofpoint reported that the group's renewed activity began…
In 2026, the average time from vulnerability disclosure to exploitation has drastically decreased to around 8 hours, down from 53 days in 2024. This rapid weaponization is attributed to advancements in AI, which can…
A new phishing campaign has been identified that distributes a variant of the PureLogs infostealer malware through deceptive purchase-order-themed emails. The campaign utilizes a malicious JavaScript file contained in a…
A sophisticated cyber campaign is leveraging compromised websites and a malicious JavaScript file named transcript.pdf.js to deploy PureLog Stealer, a .NET-based infostealer. The attack uses a fileless infection method,…
Cyber attackers are increasingly leveraging MSBuild.exe, a legitimate Windows tool, to conduct fileless attacks that evade detection. By using Living Off the Land Binaries (LOLBins), these attacks bypass traditional…
A multi-stage phishing campaign has been detected distributing the XWorm remote access trojan (RAT) via malicious Excel attachments. The attack leverages CVE-2018-0802 in Microsoft Equation Editor to execute a fileless…
A new malware framework named Avalon has been discovered, utilizing a spoofed legal document to deliver a ransomware component known as CrownX. This previously undocumented malware employs a multi-stage, fileless attack…
A new phishing campaign is distributing the XWorm 7.2 Remote Access Trojan (RAT) through malicious Excel attachments disguised as business communications. The malware is being sold on Telegram marketplaces, allowing a…
A ClickFix social engineering campaign is targeting the hospitality sector in Europe by using fake Windows Blue Screen of Death (BSOD) screens. This tactic tricks users into manually compiling and executing malware on…