Related Threat Clusters
-
Vishing Campaigns Target Organizations via Microsoft Teams and New Operator Console
A vishing campaign, tracked as STAC4749, targeted North American organizations from February to June 2026, using Microsoft Teams to impersonate IT personnel and gain remote access. Attackers deployed a modular toolset,…
9 articles · Updated July 29, 2026 -
Malicious npm Packages Deploy NodeCordRAT to Target Cryptocurrency Developers
In November 2025, Zscaler ThreatLabz identified three malicious npm packages designed to target cryptocurrency developers. The packages, bitcoin-main-lib and bitcoin-lib-js, install a third package, bip40, which…
2 articles · Updated January 9, 2026 -
Malicious npm Packages Use Adspect Cloaking in Crypto Scam
A malware campaign has been identified that utilizes malicious npm packages to create fake websites designed to identify and exploit potential victims. The threat actor, known as 'dino_reborn', published these packages…
13 articles · Updated November 18, 2025 -
Tsundere Botnet Exploits Node.js and Blockchain for Multi-OS Attacks
The Tsundere botnet, identified by Kaspersky GReAT in mid-2025, utilizes legitimate Node.js packages and blockchain technology to distribute malware targeting Windows, Linux, and macOS users. The threat is linked to…
2 articles · Updated November 20, 2025
Recent Intelligence Reports
- Behind The Scenes Of A Vishing Operation — www.okta.com · July 30, 2026
- Malicious NPM Packages Deliver NodeCordRAT | ThreatLabz — Zscaler · January 8, 2026
- Blockchain and Node.js abused by Tsundere: an emerging botnet — Securelist · November 20, 2025