Wireshark - Tool

Threat entity extracted from intelligence sources

Frequency
14
occurrences
First Seen
November 1, 2025
Last Seen
July 3, 2026

Wireshark is a tool tracked across 14 threat clusters and 14 intelligence report mentions on ThreatCluster. First observed November 1, 2025; most recent activity July 3, 2026.

Related Threat Clusters

  • Critical NGINX UI Vulnerability CVE-2026-33032 Under Active Exploitation

    A critical vulnerability in the nginx-ui web server management tool, tracked as CVE-2026-33032, has been actively exploited since March 2026. This flaw allows attackers to bypass authentication on the /mcp_message…

    22 articles · Updated April 15, 2026
  • SmartApeSG Campaign Distributes Multiple RATs via ClickFix Technique

    The SmartApeSG campaign employs a fake CAPTCHA page and ClickFix script to deliver various remote access trojans (RATs) including Remcos, NetSupport, StealC, and Sectop RAT. The attack begins with Remcos RAT, which…

    2 articles · Updated June 18, 2026
  • CloudZ RAT Exploits Microsoft Phone Link to Steal SMS OTPs

    A new malware campaign involving the CloudZ remote access trojan (RAT) and its Pheno plugin is targeting Microsoft’s Phone Link feature to intercept SMS-based one-time passwords (OTPs) and other sensitive data from…

    7 articles · Updated May 5, 2026
  • Critical Wireshark Vulnerabilities Enable Arbitrary Code Execution

    Wireshark has released version 4.6.5 to address over 40 vulnerabilities, including critical flaws that allow attackers to execute arbitrary code via malformed packets or malicious capture files. This update is crucial…

    6 articles · Updated May 1, 2026
  • Russian APT Campaign Targets Ukraine with BadPaw and MeowMeow Malware

    A Russian cyber campaign has been identified targeting Ukrainian organizations using new malware families, BadPaw and MeowMeow, delivered via phishing emails. The operation begins with emails containing links to ZIP…

    4 articles · Updated March 5, 2026
  • Multiple Vulnerabilities in Wireshark Allow Denial of Service and Code Execution

    Two critical vulnerabilities have been identified in Wireshark versions 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14. CVE-2026-5405 involves a crash in the RDP protocol dissector, while CVE-2026-5656 pertains to a profile import…

    2 articles · Updated May 7, 2026
  • SmartApeSG Deploys Remcos RAT via ClickFix Technique

    SmartApeSG has utilized the ClickFix technique to distribute the Remcos RAT, leveraging a fake CAPTCHA page on compromised legitimate sites. The malware targets Windows hosts, allowing persistent infections. Traffic…

    2 articles · Updated January 29, 2026
  • Understanding Ethical Hacking in Cybersecurity

    Ethical hacking, or penetration testing, is a crucial practice for identifying vulnerabilities in computer systems before malicious hackers can exploit them. In 2026, ethical hackers utilize tools like Nmap, Metasploit,…

    2 articles · Updated June 21, 2026
  • Revival of Finger Command in ClickFix Malware Attacks

    Threat actors are exploiting the decades-old 'finger' command in new ClickFix malware attacks to execute remote commands on Windows devices. The command, which was historically used to retrieve user information on Unix…

    4 articles · Updated November 17, 2025
  • Wireshark 4.6.2 Addresses Critical Vulnerabilities and Enhances Protocol Support

    Wireshark has released version 4.6.2, which includes fixes for critical crash vulnerabilities and improved plugin compatibility. This update addresses two denial-of-service vulnerabilities, including a notable crash in…

    2 articles · Updated December 15, 2025

Recent Intelligence Reports

  • What Is Offensive Cybersecurity — www.infosecurityeurope.com · July 3, 2026
  • How Hackers Operate: The Tools Behind Real — Analyticsinsight · June 21, 2026
  • 32826 — isc.sans.edu · June 18, 2026
  • Professional Certificate Programme in Cybersecurity and AI — iitmpravartak.emeritus.org · June 12, 2026
  • CVE-2026-5656 — nvd.nist.gov · May 7, 2026
  • New Infostealer Dubbed ‘Pheno’ Hijacks Windows’ Phone Link App to Steal MFA OTPs — Thecyberexpress · May 5, 2026
  • CloudZ RAT potentially steals OTP messages using Pheno plugin — Blog.Talosintelligence · May 5, 2026
  • Multiple Wireshark Vulnerabilities Allow Arbitrary Code Execution via Malformed Packets — Gbhackers · May 1, 2026

CVSS v3.1 Breakdown