Information Technology/IT
Breach intelligence, attack campaigns, and threat reports targeting the Information Technology/IT sector.
Explore Other Sectors
Information Technology/IT Threat Reports
Anatomy of an Akira Ransomware Attack: 42 Days Hidden After a Fake CAPTCHA
In early 2024, a sophisticated cyberattack attributed to the Akira ransomware group exploited a fake CAPTCHA page to infiltrate an organization's environment. Attackers used this social engineering technique as an entry point, deploying malware that enabled persistent access and undetected movement across internal systems for 42 days. During this period, lateral movement and privilege escalation allowed the attackers to exfiltrate data and ultimately deploy ransomware, encrypting vital business assets and causing significant operational disruption. The incident illustrates how modern ransomware actors leverage stealth, deception, and extended dwell times to maximize their impact. This case underscores an escalating trend of increasingly complex and targeted ransomware attacks that blend technical exploitation with effective social engineering. Organizations are being challenged to enhance east-west traffic security, real-time threat detection, and zero trust segmentation to counter these evolving threats.
8 months ago
Kill Chain
Unicode: The Hidden Security Threat Fueling 2024's Obfuscated Code Attacks
In late 2024, security researchers highlighted a series of application security vulnerabilities caused by improper handling of the Unicode character set, impacting numerous platforms and development environments. Attackers exploited Unicode features such as confusable characters, variant selectors, and bidirectional text markers, enabling impersonation, injection, and severe obfuscation of code in public repositories. Notably, a self-propagating worm known as "Glass Worm" leveraged invisible Unicode code points to disguise malicious code in Visual Studio Code extensions, bypassing manual code review and automated security checks. These techniques led to increased risk of code injection, credential spoofing, and long-term compromise of software supply chains. Unicode-driven attack techniques continue to gain prominence due to their effectiveness at evading human and automated detection. The recent spike in attacks demonstrates a broader trend towards supply chain risk and advanced code obfuscation, demanding urgent attention to Unicode normalization, secure coding practices, and robust detection mechanisms in compliance-driven industries.
8 months ago
Kill Chain
Malicious NPM Packages Exploit Adspect in 2024 Supply Chain Breach
In June 2024, security researchers uncovered a supply chain attack involving seven malicious packages on the NPM registry that abused the Adspect cloud-based service. Attackers used these packages to redirect users through Adspect, circumventing many security sandboxes and researcher analysis tools. This sophisticated evasion allowed threat actors to selectively route potential victims to malicious payloads while deflecting scrutiny from security firms. The malicious packages were rapidly removed from NPM, but not before posing a significant risk to open-source software supply chains. This incident highlights the increasing exploitation of trusted third-party platforms and infrastructure in software supply chain attacks. With adversaries leveraging evasive redirects and advanced obfuscation tactics, organizations face a growing need for robust dependency management, automated threat detection, and enhanced monitoring of public code repositories.
8 months ago
Kill Chain
Hackers Exploit Ray AI to Launch Global Cryptojacking Botnet (2024)
In late 2024, malicious actors exploited an unauthenticated remote code execution vulnerability (CVE-2023-48022) in the open-source Ray AI framework, transforming exposed development environments into a globally distributed cryptojacking operation. Attackers leveraged Ray's scheduling and orchestration APIs to gain unauthorized access and deploy cryptomining payloads, particularly targeting environments with premium NVIDIA A100 GPUs. The campaign, identified by Oligo Security, unfolded in multiple phases: after initial malware delivery via GitLab infrastructure was disrupted, attackers quickly shifted to hosting on GitHub to sustain their operation. Over 200,000 exposed Ray clusters worldwide were at risk, significantly impacting cloud AI operations, startups, and research environments. This incident marks a major evolution in threat actor adaptation: rather than exploiting traditional network vulnerabilities, adversaries weaponized trusted automation features to evade detection and maximize illicit gain. The campaign illustrates mounting risks to cloud-hosted AI workloads, the dangers of insecure API exposure, and the urgent need for stringent internal network controls to defend against cryptojacking and abuse of compute resources.
8 months ago
Kill Chain
CISA 2025 Issues Guidance to Mitigate Bulletproof Hosting Provider Risks
In November 2025, the Cybersecurity and Infrastructure Security Agency (CISA), together with the NSA, FBI, Department of Defense Cyber Crime Center, and international partners, released comprehensive guidance to combat risks posed by Bulletproof Hosting Providers (BPHs). BPHs are infrastructure providers that knowingly lease servers and networking resources to cybercriminals, enabling ransomware, phishing, malware distribution, and denial-of-service attacks at scale. The guidance urges Internet Service Providers and network operators to apply blocklists, traffic analysis, intelligence sharing, and stronger vetting to prevent malicious actors from exploiting BPH resources, aiming to bolster the digital resilience of critical infrastructure sectors globally. The ongoing proliferation of cyberattacks leveraging BPH infrastructure underscores the urgency of these recommendations. With threat actors increasingly turning to anonymized, resilient hosting to evade law enforcement and detection, proactive mitigation by ISPs is crucial to limiting damage and strengthening industry-wide cybersecurity defense.
8 months ago
Kill Chain
Fortinet FortiWeb Zero-Day Abuse: 2024 Attack Highlights Security Device Risks
In June 2024, Fortinet disclosed a critical zero-day vulnerability in its FortiWeb web application firewall that was being actively exploited in the wild. Threat actors leveraged the unknown flaw to gain unauthorized access to targeted organizations, bypassing authentication and potentially altering application configurations or exfiltrating sensitive data. Fortinet responded promptly by releasing security patches and urging customers to update affected devices, while security researchers warned this campaign was already impacting several organizations before public disclosure. This incident is part of a growing trend of sophisticated attacks targeting network and security appliances through undisclosed vulnerabilities. Organizations face heightened risk as attackers weaponize zero-days more quickly, making swift patch management and layered controls essential to defending digital infrastructure.
8 months ago
Kill Chain
Google Chrome 2024 Zero-Day Exploited in the Wild: What You Need to Know
In June 2024, Google disclosed and patched a critical zero-day vulnerability in the Chrome web browser (CVE-2024-5274) that had actively been exploited in the wild. Attackers leveraged a type confusion flaw in Chrome’s V8 JavaScript engine to execute arbitrary code on victim devices, enabling full compromise of targeted systems. Google's rapid response—releasing an emergency security update—helped mitigate exploitation risks. The vulnerability represented the seventh zero-day affecting Chrome this year, underscoring persistent targeting of popular browsers for initial access into corporate and consumer environments. This incident illustrates the sustained threat posed by browser zero-days and the increasing velocity with which attackers are weaponizing new flaws. As web browsers remain a ubiquitous endpoint attack vector, organizations must ensure rapid patch cycles and layered security controls to limit exposure.
8 months ago
Kill Chain
Microsoft Thwarts Record-Breaking 15.72 Tbps DDoS Attack Orchestrated by AISURU Botnet
In November 2025, Microsoft successfully detected and mitigated an unprecedented Distributed Denial-of-Service (DDoS) attack that peaked at 15.72 Tbps, targeting a cloud endpoint in Australia. The attack, orchestrated by the AISURU botnet leveraging TurboMirai-class malware, generated nearly 3.64 billion packets per second. Advanced protections within Microsoft's Azure platform automatically neutralized the threat before it could affect customer availability or data. Microsoft attributed the attack to highly automated botnets leveraging compromised IoT devices and observed a rapid, multi-vector assault designed to test cloud resilience and incident response. This record-breaking event highlights the escalating scale and sophistication of DDoS activity targeting foundational cloud infrastructure. As attackers exploit larger IoT botnets and novel malware strains, defenders face mounting pressure to evolve detection and mitigation at cloud-scale. Organizations must increasingly invest in robust DDoS protection and continuously monitor for emerging threats.
8 months ago
Kill Chain
ShadowRay 2.0: How Ray Cluster Flaws Fueled a Cryptomining Botnet
In June 2024, cybersecurity researchers identified a coordinated global attack campaign dubbed ShadowRay 2.0 targeting exposed Ray clusters—open-source distributed computing environments widely used in AI and machine learning workloads. Attackers exploited an unpatched remote code execution vulnerability in Ray's dashboard service, gaining unauthorized access to cloud and on-premises clusters. Once inside, adversaries deployed self-spreading cryptomining malware, turning infected clusters into part of a large-scale botnet that harnessed high-performance compute resources for illicit cryptocurrency mining, causing potential performance degradation, elevated cloud bills, and risk of further lateral movement. This campaign demonstrates the growing threat surface posed by AI and data infrastructure, as adversaries increasingly automate the exploitation of software supply chain and configuration weaknesses. The incident highlights the urgency of securing east-west traffic, enforcing least privilege, and maintaining continuous vulnerability management in distributed and cloud-native environments.
8 months ago
Kill Chain
npm Supply-Chain Threat: Seven Malicious Packages Cloak Crypto Scams in 2025
In late 2025, cybersecurity researchers uncovered a supply-chain attack involving seven malicious npm packages uploaded by the threat actor 'dino_reborn.' These packages leveraged Adspect cloaking technology to detect if visitors were victims or security researchers. Unsuspecting users were redirected to fraudulent cryptocurrency-themed websites, exposing them to potential scams or malware. The packages were published between September and November 2025 and remained available until detection, highlighting the challenges in securing open-source ecosystems. This incident is part of a growing trend involving supply-chain attacks targeting widely used software repositories. As more attackers adopt advanced evasion measures like traffic cloaking and nuanced social engineering, the risk and complexity of defending modern development pipelines are rapidly increasing.
8 months ago
Kill Chain
Researchers Reveal Tuoni C2’s Role in 2025 Real-Estate Cyber Attack
In early November 2025, a prominent U.S.-based real-estate company was targeted in a sophisticated cyber attack utilizing the Tuoni command-and-control (C2) framework, a new red-teaming tool known for implementing stealthy, in-memory payload delivery. The attackers exploited Tuoni C2’s advanced capabilities to infiltrate the network while evading traditional security controls, demonstrating lateral movement and attempting data collection within internal segments. Although swift detection halted major exfiltration, the intrusion highlighted gaps in east-west traffic visibility and segmentation, causing temporary disruption to key business systems and prompting an urgent review of internal controls. This attack underscores the growing trend of adversaries adopting novel, freely available C2 tools to bypass existing enterprise defenses. It reflects broader industry concern as C2 frameworks like Tuoni fuel increased attack sophistication, especially in sectors handling large volumes of sensitive data such as real estate and finance.
8 months ago
Kill Chain
Sneaky 2FA Kit Innovates with BitB Pop-up Phishing: MFA Bypass at Scale
In November 2025, security researchers reported on the evolving Sneaky 2FA Phishing-as-a-Service (PhaaS) kit, which now features sophisticated Browser-in-the-Browser (BitB) pop-ups that convincingly mimic legitimate browser address bars. These enhancements enable threat actors, including low-skilled attackers, to deploy highly realistic phishing attacks at scale and bypass multi-factor authentication (MFA) protections. Victims, typically employees of enterprises and large organizations, are tricked into entering credentials and 2FA codes into deceptive portals, facilitating account compromise and potential unauthorized access to sensitive business assets. This incident highlights a troubling trend of phishing toolkits increasing in sophistication, making advanced attacks accessible to broader criminal audiences. Organizations are now facing growing regulatory and operational pressure to update authentication, identity protection, and detection controls amid a wave of phishing leveraging MFA bypass and deceptive visual TTPs.
8 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports