2026-06-11
2026-06-11 09:28Z
INFO

UserAuthenticationMethod: Understanding M365 Sign-In Logs

Sekoia.io·sekoia.io

Sekoia.io documents the previously undocumented UserAuthenticationMethod field in Microsoft 365 audit logs, revealing it is a bitfield where each bit position maps to a distinct authentication method. Through correlation with Entra ID sign-in logs using shared correlation identifiers, researchers decoded 24 bit positions representing authentication methods ranging from password variants to passkeys and Windows Hello for Business. The field accumulates values during multi-factor authentication flows, capturing both primary and secondary factors in a single numeric value.

TACTA0006SRFIdentitySRFCloudSWEntra IdSWMicrosoft 365VNDMicrosoftTYPResearchTECT1110
72
Edit Score
2026-06-11
2026-06-11 09:27Z
HIGH

PolarEdge Backdoor on QNAP: CVE-2023-20118 Analysis

Sekoia.io·sekoia.ioCVE-2023-20118in the wild

Sekoia TDR reverse-engineered the PolarEdge Backdoor, a TLS-based implant deployed on QNAP, Cisco, Asus, and Synology devices via CVE-2023-20118. The 1.6 MB ELF binary implements a custom mbedTLS server listening on port 49254 for unauthenticated binary protocol commands, with configuration obfuscated via one-byte XOR and PRESENT block cipher encryption. The implant includes anti-analysis techniques (process masquerading, /proc remounting, watchdog fork), daily host fingerprinting to C2, and auxiliary connect-back and debug modes for C2 updates.

SRFOsTACTA0005TACTA0001SRFNetwork ApplianceTACTA0003TACTA0011VNDSynologyVNDCisco
78
Edit Score
2026-06-11
2026-06-11 09:27Z
HIGH

APT28 Operation Phantom Net Voxel: BeardShell & Covenant

Sekoia.io·sekoia.ioin the wild

Sekoia TDR published a detailed technical analysis of APT28's Operation Phantom Net Voxel targeting Ukrainian military personnel via Signal Desktop. The campaign chains weaponized Office documents with VBA macros, COM-hijack DLL persistence, PNG steganography to extract shellcode, Covenant Grunt C2 via Koofr cloud API, and BeardShell backdoor via icedrive. Analysis of compromised Koofr accounts revealed 42 unique infected hosts dating back to December 2024, with exfiltrated reconnaissance data.

SRFApplicationTACTA0005TACTA0001TACTA0002TACTA0003SRFCloudTACTA0011OSWindows
88
Edit Score
2026-06-11
2026-06-11 09:27Z
HIGH

Silent Smishing : The Hidden Abuse of Cellular Router APIs

Sekoia.io·sekoia.ioCVE-2023-43261in the wild

Sekoia TDR discovered active smishing campaigns exploiting unauthenticated SMS APIs in Milesight industrial cellular routers to send phishing SMS at scale. Over 18,000 routers are exposed on the public internet, with at least 572 confirmed vulnerable to unauthenticated access to SMS inbox/outbox functionality. Malicious SMS campaigns targeting Belgium, France, and other European countries have been active since at least February 2022, with phishing lures impersonating government services (CSAM, eBox), postal, banking, and telecom providers.

TACTA0001SRFNetworkSRFNetwork ApplianceSWMilesight Industrial Cellular RouterVNDMilesightTYPResearchTYPVulnerabilitySTGExecution
82
Edit Score
2026-06-11
2026-06-11 09:27Z
CRIT

Predators for Hire: Commercial Surveillance Vendors Overview

Sekoia.io·sekoia.ioin the wild

Sekoia's comprehensive report analyzes the commercial surveillance vendor (CSV) ecosystem from 2010–2025, documenting how private spyware companies evolved from niche suppliers into a sophisticated, industrialized market serving authoritarian regimes. The report traces three phases: emergence (2010–2015) driven by Arab Spring demand, industrialization (2016–2021) marked by zero-click/one-click mobile exploits and Israeli intelligence recruitment, and legitimacy crisis (2021–2024) following NGO exposures of human rights abuses. Key vendors profiled include NSO Group (Pegasus), Hacking Team (RCS), Intellexa (Predator), Candiru (DevilsTongue), and Paragon (Graphite), with documented targeting of journalists, activists, and political opponents across democracies and autocracies.

SRFApplicationSRFMobileTACTA0006TACTA0043TACTA0009TYPResearchTYPThreat IntelSTGExecution
82
Edit Score
2026-06-11
2026-06-11 09:27Z
HIGH

Global analysis of Adversary-in-the-Middle phishing threats

Sekoia.io·sekoia.io

Sekoia's TDR team published a comprehensive global analysis of Adversary-in-the-Middle (AitM) phishing threats covering January–April 2025, tracking 11 prevalent PhaaS kits (Tycoon 2FA, Storm-1167, NakedPages, Sneaky 2FA, EvilProxy, Evilginx) and documenting rapid TTP evolution from QR codes to HTML and SVG attachments. The report details the PhaaS ecosystem's professionalization, attack chains targeting Microsoft 365 and Google accounts to harvest session cookies and bypass MFA, and downstream Business Email Compromise (BEC) operations.

TACTA0001TACTA0006SRFIdentitySRFWebSRFCloudTYPResearchTYPThreat IntelSTGInitial Access
72
Edit Score
2026-06-11
2026-06-11 09:26Z
CRIT

The Sharp Taste of Mimo'lette: Mimo Targets Craft CMS

Sekoia.io·sekoia.ioCVE-2025-32432in the wild

Sekoia TDR analyzed a campaign by the Mimo intrusion set exploiting CVE-2025-32432 (unauthenticated RCE in Craft CMS, CVSS 10.0) to deploy a two-stage infection chain combining XMRig cryptominer, IPRoyal residential proxyware, and a UPX-packed Golang loader. The vulnerability was exploited within days of public PoC release, with the attacker using PHP deserialization to plant webshells in session files and execute arbitrary commands. Attribution links to Turkish-based operators using distinctive identifiers (etxarny, n1tr0, 4l4md4r) across TikTok and exploitation infrastructure.

SRFApplicationTACTA0005TACTA0001TACTA0002SRFWebSWCraft CmsTYPVulnerabilityTYPThreat Intel
82
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-06-11
2026-06-11 09:26Z
HIGH

ViciousTrap: Turning Edge Devices into Honeypots at Scale

Sekoia.io·sekoia.ioCVE-2023-20118CVE-2021-32030in the wild

Sekoia.io documented ViciousTrap, a Chinese-speaking threat actor who has compromised over 5,500 edge devices (Cisco SOHO routers, D-Link, ASUS, Linksys, QNAP, and others) by exploiting CVE-2023-20118 and CVE-2021-32030. The actor deploys a malicious script called NetGhost that redirects inbound traffic via iptables to attacker-controlled interception servers, effectively turning compromised devices into a distributed honeypot network to observe and collect exploitation attempts and zero-day exploits. The infrastructure is hosted in Malaysia under AS45839 (Shinjiru), monitors approximately 60 distinct device types, and shows sustained daily exploitation activity since March 2025.

TACTA0005TACTA0001TACTA0002SRFNetworkSRFNetwork ApplianceTACTA0007VNDCiscoVNDAsus
82
Edit Score
2026-06-11
2026-06-11 09:26Z
HIGH

Detecting Multi-Stage Infection Chains Madness

Sekoia.io·sekoia.ioin the wild

Sekoia TDR documents a multi-stage infection chain active since February 2024 that abuses Cloudflare tunnel infrastructure to deliver AsyncRAT. The attack chain begins with phishing emails containing .ms-library files triggering WebDAV access, progresses through LNK→HTA→BAT→Python execution stages with process injection into notepad.exe, and establishes persistence via Startup folder VBS/BAT files before reflectively loading a final payload from a JPEG image. The report provides detailed Sigma detection rules for each stage and IOCs including C2 infrastructure.

SRFApplicationTACTA0005TACTA0001TACTA0002SRFWebTACTA0003TACTA0011SWAsyncrat
76
Edit Score
2026-06-11
2026-06-11 09:26Z
HIGH

Interlock Ransomware: Evolving Under the Radar with ClickFix

Sekoia.io·sekoia.ioin the wild

Sekoia TDR published an in-depth analysis of the Interlock ransomware group, active since September 2024, documenting their evolving toolset and adoption of the ClickFix social-engineering technique for initial access. The group uses fake browser/security-software updaters delivering PowerShell backdoors, has shifted to ClickFix phishing (fake CAPTCHA prompts tricking users into pasting malicious commands), and deploys a custom RAT alongside credential stealers (LummaStealer, BerserkStealer). Infrastructure relies on Cloudflare tunnels and distributed VPS clusters across BitLaunch, Hetzner, and other providers for resilience.

SRFApplicationSRFOsTACTA0004TACTA0005TACTA0001TACTA0002SRFNetworkTACTA0006
72
Edit Score
2026-06-11
2026-06-11 09:25Z
CRIT

Lazarus ClickFake Interview Campaign: ClickFix Malware

Sekoia.io·sekoia.ioin the wild

Sekoia's TDR team discovered ClickFake Interview, a new Lazarus campaign targeting cryptocurrency industry employees via fake job interview websites. The campaign leverages the ClickFix tactic to deliver GolangGhost, a Go-based backdoor with remote control and browser-stealing capabilities, on both Windows and macOS. The campaign represents an evolution of the previously documented Contagious Interview campaign and aligns with Lazarus's 2024 shift from targeting decentralized to centralized finance entities.

SRFApplicationTACTA0005TACTA0001TACTA0002TACTA0006TACTA0007SRFWebTACTA0003
82
Edit Score
2026-06-11
2026-06-11 09:25Z
HIGH

ClearFake's New Variant: Web3 Exploitation for Malware Delivery

Sekoia.io·sekoia.ioin the wild

Sekoia TDR published a technical analysis of ClearFake's latest variant (active since December 2024), which abuses Binance Smart Chain smart contracts and fake CAPTCHA lures to deliver malware. The malware uses the EtherHiding technique to store obfuscated JavaScript, AES encryption keys, and malicious PowerShell commands in blockchain smart contracts, making the infrastructure resistant to takedown. The infection chain combines fake reCAPTCHA and Cloudflare Turnstile social engineering (ClickFix tactic) to trick users into executing PowerShell commands that ultimately deliver Emmenhtal Loader, Lumma Stealer, and Vidar Stealer.

SRFApplicationTACTA0001TACTA0002SRFWebSWClearfakeTYPResearchTYPThreat IntelSTGExecution
78
Edit Score
2026-06-11
2026-06-11 09:25Z
HIGH

PolarEdge: Unveiling an uncovered ORB network

Sekoia.io·sekoia.ioCVE-2023-20118in the wild

Sekoia's TDR team discovered PolarEdge, an active botnet of 2,000+ compromised edge devices exploiting CVE-2023-20118 in Cisco small business routers since late 2023. The campaign deploys a TLS backdoor (cipher_log) via multi-stage infection chains and targets additional devices from Asus, QNAP, and Synology. Infrastructure analysis links the operation to Russian proxy services (Proxyline/Stark Industries/Green Floid LLC) with potential state-nexus indicators.

SRFApplicationTACTA0005TACTA0001TACTA0002SRFNetwork ApplianceTACTA0003SWMbed TlsVNDSynology
78
Edit Score
2026-06-11
2026-06-11 09:25Z
HIGH

Cyber Threat Actors Impacting the Financial Sector in 2024

Sekoia.io·sekoia.io

Sekoia's 2024 financial sector threat report documents major cybercrime and state-sponsored actors targeting financial institutions. Key threat categories include Initial Access Brokers (IABs) commoditizing network access, ransomware groups like RansomHub and Scattered Spider conducting double-extortion campaigns, sophisticated Trojan operators (Solar Spider, GoldFactory) deploying banking malware with biometric harvesting, and Phishing-as-a-Service kits (Tycoon 2FA, Sneaky 2FA) enabling MFA bypass via Adversary-in-the-Middle attacks. State-sponsored actors from North Korea, Iran, and China are also actively targeting the sector for financial gain and espionage.

SRFApplicationSRFMobileTACTA0001TACTA0006TACTA0007SRFWebTYPResearchTYPThreat Intel
68
Edit Score
2026-06-11
2026-06-11 09:25Z
HIGH

RATatouille: Cooking Up Chaos in the I2P Kitchen

Sekoia.io·sekoia.ioin the wild

Sekoia TDR reverse-engineered I2PRAT, a multi-stage C++ RAT delivered via ClickFix campaigns since November 2024, which uses I2P for C2 anonymization. The malware employs sophisticated privilege escalation (RPC abuse, parent-process ID spoofing), dynamic API resolution with undocumented hashing, debugger suspension, and modular architecture with separate DLLs for file transfer, RDP, and reconnaissance. The loader disables Windows Defender, routes final C2 through I2P network, and uses AES-128-CBC encryption with Mersenne Twister-derived keys.

SRFOsTACTA0005TACTA0001TACTA0002TACTA0011OSWindowsTYPResearchTYPThreat Intel
78
Edit Score
2026-06-11
2026-06-11 09:24Z
CRIT

Targeted supply chain attack against Chrome browser extensions

Sekoia.io·sekoia.ioin the wild

Sekoia disclosed a targeted supply chain attack compromising ~12 Chrome extensions in December 2024 via spearphishing of extension developers with malicious OAuth applications. The attacker gained publishing permissions to inject credential-harvesting code targeting ChatGPT API keys, Facebook Business tokens, and session data, affecting hundreds of thousands of users. Infrastructure analysis reveals the threat actor has been active since at least 2023, shifting from distributing fake extensions to hijacking legitimate ones.

TACTA0001TACTA0006TACTA0009SRFBrowserSRFSupply ChainTYPVulnerabilityTYPThreat IntelSTGInitial Access
82
Edit Score
2026-06-11
2026-06-11 09:24Z
HIGH

Sneaky 2FA: exposing a new AiTM Phishing-as-a-Service

Sekoia.io·sekoia.io

Sekoia TDR exposed Sneaky 2FA, a new Adversary-in-the-Middle (AiTM) phishing kit sold as a service targeting Microsoft 365 accounts since October 2024. The kit, operated by Sneaky Log through a Telegram bot at $200/month, reuses authentication relay code from the W3LL OV6 phishing kit and employs anti-bot checks, Cloudflare Turnstile, obfuscation, and Wikipedia redirection to evade detection. The analysis includes detection opportunities based on impossible device shift detection via hardcoded User-Agent anomalies and shared indicators of compromise.

TACTA0001TACTA0006SRFIdentitySRFWebSWMicrosoft 365VNDMicrosoftTYPResearchTYPThreat Intel
78
Edit Score
2026-06-11
2026-06-11 09:24Z
HIGH

Double-Tap: APT28-Linked Espionage on Kazakhstan

Sekoia.io·sekoia.ioin the wild

Sekoia TDR documents the Double-Tap espionage campaign attributed with medium confidence to UAC-0063 (linked to APT28/GRU), targeting Kazakhstan's Ministry of Foreign Affairs and Central Asian diplomatic entities. The campaign weaponizes legitimate diplomatic documents with a novel two-stage Word macro infection chain that silently opens a second document to deploy the HATVIBE VBS backdoor, which loads the CHERRYSPY Python backdoor for strategic intelligence collection on Kazakhstan's geopolitical and economic relations.

SRFApplicationTACTA0001TACTA0002SRFWebTACTA0003TACTA0011SWCherryspySWHatvibe
78
Edit Score
2026-06-11
2026-06-11 09:24Z
HIGH

PlugX worm disinfection campaign feedbacks

Sekoia.io·sekoia.io

Sekoia recounts a multinational sovereign disinfection campaign against PlugX worm infections, a Mustang Panda variant spreading via flash drives. After sinkholing a C2 IP in September 2023, Sekoia developed two remote disinfection methods and built a portal enabling 34 countries to identify compromised assets and 10 countries to execute disinfection under legal frameworks, delivering 59,475 payloads to 5,539 IP addresses across ten nations.

SRFNetworkTACTA0011TYPResearchTYPThreat IntelSTGImpactEXPCmd InjectionSTAongoing
68
Edit Score
2026-06-11
2026-06-11 09:23Z
HIGH

Ransomware-driven data exfiltration: techniques & implications

Sekoia.io·sekoia.io

Sekoia's threat research report analyzes data exfiltration techniques and tools used by ransomware and extortion groups from 2019–2024. The report documents the evolution of double extortion tactics, operator tooling (custom and commodity), data targeting strategies, and detection methods. Key finding: ransomware operators increasingly pre-qualify and triage high-value data (financial, medical, network records) and some groups now skip encryption entirely, relying solely on exfiltration threats.

SRFNetworkTACTA0009TACTA0010TYPResearchTYPThreat IntelSTGExfilSTGCollectionTECT1020
68
Edit Score
2026-06-11
2026-06-11 09:23Z
HIGH

Helldown Ransomware: An Overview of this Emerging Threat

Sekoia.io·sekoia.ioCVE-2024-42057CVE-2024-11667in the wild

Sekoia's TDR team profiles Helldown, a fast-moving ransomware group that has compromised 31 victims in three months using double-extortion tactics. Initial access is achieved through exploitation of Zyxel firewall vulnerabilities (CVE-2024-11667), with the group deploying both Windows payloads derived from leaked LockBit 3 code and a newer Linux variant targeting VMware ESX servers. The group exfiltrates unusually large data volumes (averaging 70GB) and shows configuration similarities to Darkrace and Donex ransomware families.

SRFOsTACTA0005TACTA0001TACTA0002SRFNetwork ApplianceTACTA0009OSLinuxOSWindows
78
Edit Score
2026-06-11
2026-06-11 09:23Z
HIGH

China's State-Sponsored Cyber Operations & Ecosystem

Sekoia.io·sekoia.io

Sekoia's TDR team maps China's state-sponsored cyber ecosystem, identifying the PLA, MSS, and MPS as primary operators, with a shift toward MSS-led operations since 2021. The analysis reveals a three-tier structure: state ministries, provincial/municipal departments with autonomous authority, and private hack-for-hire firms (including I-SOON) that weaponize vulnerabilities collected by the state. Patriotic hackers, professionalized post-2002 and integrated via Military-Civil Fusion policy, contribute to malware development (PlugX, ShadowPad) and maintain parallel cybercrime activities.

TACTA0001SRFNetworkSRFCloudTACTA0042TACTA0043TYPResearchTYPThreat IntelSTGExecution
72
Edit Score
2026-06-11
2026-06-11 09:22Z
HIGH

ClickFix tactic: Revenge of detection – Detect Fake CAPTCHA

Sekoia.io·sekoia.io

Sekoia TDR provides a comprehensive analysis of ClickFix social engineering campaigns, breaking down two primary infection chains: Phantom Meet (using mshta/bitsadmin) and fake CAPTCHA (using PowerShell IWR/IEX). The report includes endpoint and network detection rules with Sigma correlation logic to identify each variant across multiple data sources.

SRFApplicationTACTA0001SRFWebTYPResearchTYPThreat IntelSTGExecutionSTGInitial AccessTECT1105
72
Edit Score
2026-06-11
2026-06-11 09:22Z
HIGH

ClickFix tactic: The Phantom Meet Infostealer Campaign

Sekoia.io·sekoia.ioin the wild

Sekoia TDR published a detailed analysis of ClickFix campaigns—a social engineering tactic emerging in 2024 that tricks users into executing malware via fake error pop-ups on spoofed web pages (Google Meet, Chrome, Facebook, reCAPTCHA). The report traces a specific cluster distributing Stealc, Rhadamanthys (Windows) and AMOS Stealer (macOS) to cryptocurrency/Web3 users, attributing operations to traffers teams Slavic Nation Empire and Scamquerteo, sub-groups of Marko Polo and CryptoLove respectively.

SRFApplicationTACTA0001TACTA0002SRFWebOSWindowsOSMacosSWRhadamanthysSWStealc
78
Edit Score
2026-06-11
2026-06-11 09:22Z
HIGH

Mamba 2FA: A new contender in the AiTM phishing ecosystem

Sekoia.io·sekoia.ioin the wild

Sekoia TDR discovered Mamba 2FA, a previously unknown adversary-in-the-middle (AiTM) phishing-as-a-service kit targeting Microsoft 365 and Entra ID accounts, sold on Telegram for $250/month since at least March 2024. The kit uses Socket.IO to relay credentials and MFA inputs in real-time, supports multiple phishing templates (OneDrive, SharePoint, generic sign-in, voicemail), reflects custom organizational branding, and has been actively exploited against multiple organizations. As of October 2024, the infrastructure now routes through commercial proxies (IPRoyal) to obscure relay server IP addresses in authentication logs.

TACTA0001TACTA0006SRFIdentitySRFWebSRFCloudSWEntra IdVNDMicrosoftTYPResearch
78
Edit Score