Threat Walkthroughs index
List of threats encountered in the wild with their indicators of compromise.
Below is a list of commonly found threats targeting corporate users, as they were found in the wild. Click any of the links for a description, distribution methods, attack flows and IOCs for each of those threats.
- SmartApeSG – Compromised site->fake error->zip->script (06-11-2024)
- ClearFake – Compromised site->fake error->copy/paste PowerShell (06-03-2024)
- Gootloader – SEO poisoning->fake forum->zip->.JS->PowerShell (05-21-2024)
- FakeBat – Google ad redirects to FakeBat, dropping zgRAT (05-05-2024)
- Nitrogen – Google ad for Advanced IP Scanner (05-03-2024)
- LockBit Black – Zipped attachment in email (05-01-2024)