Procmon - Tool

Threat entity extracted from intelligence sources

Frequency
5
occurrences
First Seen
November 15, 2025
Last Seen
May 5, 2026

Related Threat Clusters

  • CloudZ RAT Exploits Microsoft Phone Link to Steal SMS OTPs

    A new malware campaign involving the CloudZ remote access trojan (RAT) and its Pheno plugin is targeting Microsoft’s Phone Link feature to intercept SMS-based one-time passwords (OTPs) and other sensitive data from…

    7 articles · Updated May 5, 2026
  • Russian APT Campaign Targets Ukraine with BadPaw and MeowMeow Malware

    A Russian cyber campaign has been identified targeting Ukrainian organizations using new malware families, BadPaw and MeowMeow, delivered via phishing emails. The operation begins with emails containing links to ZIP…

    4 articles · Updated March 5, 2026
  • Revival of Finger Command in ClickFix Malware Attacks

    Threat actors are exploiting the decades-old 'finger' command in new ClickFix malware attacks to execute remote commands on Windows devices. The command, which was historically used to retrieve user information on Unix…

    4 articles · Updated November 17, 2025
  • Revival of 'Finger' Command in ClickFix Malware Attacks

    Threat actors have reintroduced the decades-old 'finger' command in new ClickFix malware attacks to facilitate remote command execution on Windows devices. The command, originally used for user information retrieval on…

    2 articles · Updated November 17, 2025

Recent Intelligence Reports

  • New Infostealer Dubbed ‘Pheno’ Hijacks Windows’ Phone Link App to Steal MFA OTPs — Thecyberexpress · May 5, 2026
  • CloudZ RAT potentially steals OTP messages using Pheno plugin — Blog.Talosintelligence · May 5, 2026
  • Multi-Stage "BadPaw" Malware Campaign Targets Ukraine — Infosecurity-Magazine · March 4, 2026
  • New ClickFix attacks reuse ancient 'finger' command — Scworld · November 17, 2025
  • Decades-old ‘Finger’ protocol abused in ClickFix malware attacks — Bleepingcomputer · November 15, 2025

CVSS v3.1 Breakdown