Information Technology/IT
Breach intelligence, attack campaigns, and threat reports targeting the Information Technology/IT sector.
Explore Other Sectors
Information Technology/IT Threat Reports
Kimsuky APT Abuses Remote Wipe and KakaoTalk in South Korean Mobile Espionage (2024)
In early 2024, South Korean organizations were targeted by the Kimsuky APT, a North Korean-linked cyberespionage group notorious for sophisticated attacks against geopolitical rivals. Leveraging Google Find My Device’s legitimate remote-wipe capabilities, the attackers first gained access to Android phones through spear-phishing and malicious apps, then remotely wiped data or hijacked accounts. They also abused KakaoTalk, South Korea’s leading messaging app, for persistent access and exfiltration of sensitive information. This operation signifies an evolution in threat actor tactics by exploiting trusted platform features rather than relying solely on novel malware. This incident is highly relevant as cyberespionage groups increasingly leverage mobile platform features and popular apps for stealth operations. The case highlights advanced social engineering, trendsetting abuse of account-wiping tools, and the urgent need for stronger security controls for BYOD (Bring Your Own Device) environments.
8 months ago
Kill Chain
GlassWorm Supply Chain Attack Exposes VS Code and Developer Ecosystems
In June 2024, a coordinated supply chain attack involving the GlassWorm malware targeted the Open VSX marketplace, enabling the spread of compromised Visual Studio Code extensions. Attackers weaponized these extensions to propagate malware onto developer devices globally, facilitating lateral movement and potential data exfiltration within development environments. Threat actors leveraged the trust inherent in popular code repositories to deploy self-propagating malware, which remained undetected for weeks, impacting thousands of developers and exposing software supply chains to significant risk. This incident underscores the vulnerabilities presented by reliance on third-party developer tools and the sophisticated nature of modern supply-chain threats. The GlassWorm incident highlights a growing trend where attackers exploit software development ecosystems to gain broad access to sensitive environments. As reliance on open source and marketplace extensions increases, organizations must strengthen their posture against these evolving supply-chain vulnerabilities and ensure detection capabilities span both inbound and internal (east-west) traffic.
8 months ago
Kill Chain
Authentication Coercion Evolves: RPC Attack Bypasses Enterprise Security in 2024
In early 2024, a new evolution in authentication coercion attacks was uncovered, where threat actors exploited an obscure and poorly monitored remote procedure call (RPC) interface to bypass authentication barriers. Attackers leveraged this vector to coerce systems and services into issuing authentication requests, enabling credential relaying and lateral movement within enterprise networks. This approach bypassed traditional multi-factor authentication and monitoring controls, putting sensitive data and operations at risk across multiple organizations. The fallout included unauthorized access, potential data exfiltration, and major concerns about the visibility of east-west traffic in enterprise environments. This incident underscores a rising trend where attackers innovate to exploit less visible, often-overlooked system protocols. As attackers become more sophisticated, the risks posed by legacy interfaces and insufficient internal segmentation are growing, necessitating enhanced internal monitoring and alignment to zero trust principles.
8 months ago
Kill Chain
Yanluowang Initial Access Broker’s Guilty Plea: Ransomware Supply Chain Exposed
Between July 2021 and November 2022, a Russian national acted as an initial access broker (IAB) for the Yanluowang ransomware group, facilitating network entry for at least eight U.S. companies. After gaining unauthorized access, the IAB sold credentials and footholds to Yanluowang ransomware operators, enabling follow-on attacks that resulted in significant business disruptions, data encryption, and attempted extortion. U.S. law enforcement’s investigation led to the broker pleading guilty, marking a rare disruption of the ransomware ecosystem’s supply chain. This case underscores the increasing professionalization of ransomware operations, where roles like IABs are critical in enabling threat actors at scale. The incident's legal resolution reflects broader efforts to deter cybercrime, yet highlights the persistent risks posed by RaaS models and outsourced attacker infrastructure.
8 months ago
Kill Chain
GlassWorm: Malicious VS Code Extensions Trigger a New Wave of Supply-Chain Attacks
In late 2025, cybersecurity researchers discovered the 'GlassWorm' malware campaign actively targeting the Visual Studio Code (VS Code) ecosystem via three malicious extensions available on the official marketplace. With over 7,400 combined downloads, these extensions enabled threat actors to inject malware directly into developers' environments, facilitating credential theft, remote access, and potential downstream supply-chain attacks. Attackers leveraged trusted community tools as the entry vector, bypassing traditional perimeter defenses to gain a foothold in development workflows and potentially propagate malware throughout interconnected repositories. This incident underscores the rising prevalence of supply-chain attacks in the software development ecosystem and the unique risks posed by compromised IDE extensions. The popularity of VS Code amplifies the potential blast radius, highlighting an urgent need for improved extension vetting, granular access controls, and continuous threat monitoring within CI/CD pipelines.
8 months ago
Kill Chain
ClickFix Phishing Hits Hospitality: Hotel Credentials Compromised via PureRAT
In late 2025, the hospitality sector was targeted by a sophisticated, large-scale phishing campaign involving ClickFix-style lures that tricked hotel managers into revealing their credentials. Attackers leveraged compromised email accounts to distribute malicious links to numerous hotel establishments, leading victims to phishing sites that mimicked familiar workflow tools. Credential theft enabled deployment of PureRAT malware, which provided remote access to internal hotel systems and enabled lateral movement, resulting in compromised operations and data exposure for multiple organizations. This incident demonstrates the increasing use of advanced social engineering in credential-focused attacks against the hospitality industry. With phishing campaigns growing more convincing and commodity RATs like PureRAT widely available, organizations in high-turnover sectors face mounting risk from credential-based breaches and follow-on malware infections.
8 months ago
Kill Chain
Quantum Route Redirect PhaaS: The 2024 Microsoft 365 Phishing Surge
In 2024, cybersecurity researchers discovered that a Phishing-as-a-Service (PhaaS) platform named Quantum Route Redirect orchestrated a large-scale credential theft campaign targeting Microsoft 365 users globally. The threat actors leveraged a distributed network of roughly 1,000 malicious domains to automate phishing attacks and evade detection. Victims were lured through convincing emails, redirecting them seamlessly through multiple stages to capture login credentials. The campaign exploited the trust in corporate SaaS platforms, enabling attackers to compromise user identities, access sensitive business data, and potentially facilitate subsequent attacks across affected organizations. The incident highlighted widespread operational and reputational risks for enterprises relying on cloud collaboration platforms. This incident underscores the growing threat posed by PhaaS platforms, which are lowering the entry barrier for cybercriminals to launch sophisticated, scalable phishing campaigns. As email and identity-based attacks surge, organizations face urgent pressure to reinforce cloud security, strengthen user awareness, and adopt zero-trust frameworks to defend against evolving social engineering tactics.
8 months ago
Kill Chain
AI-Powered Malware & Hyper-V Exploits: The 2025 Multi-Vector Attack Recap
In early November 2025, a series of sophisticated cyberattacks targeted enterprise and consumer systems worldwide, exploiting vulnerabilities in Hyper-V virtual machines, RDP protocols, and leveraging malicious AI bots. Attackers deployed stealthy malware within virtualized environments to evade detection, while advanced spyware campaigns targeted Android devices using side-channel techniques to capture sensitive AI chat data. Additionally, high-profile service disruptions, including a mass WhatsApp account lockdown, affected millions of users and raised concerns about systemic vulnerabilities and cross-platform exploitation. The threat actors behind these incidents demonstrated new levels of coordination and adaptability, with alliances between major cybercrime groups amplifying the scope and impact of the campaigns. This incident underscores an accelerating trend toward multi-vector, AI-enabled cybercrime and highlights the convergence of ransomware, lateral movement, and novel attack methods across cloud and hybrid infrastructures. Security leaders should anticipate further escalation in both the sophistication and frequency of such attacks through 2025, heightening urgency for layered defenses and zero trust strategies.
8 months ago
Kill Chain
Triofox Flaw Exploited: How CVE-2025-12480 Enabled Remote Access Tool Attacks
In June 2025, cybersecurity researchers at Google's Mandiant Threat Defense uncovered active exploitation of a critical authentication bypass vulnerability (CVE-2025-12480, CVSS 9.1) affecting Gladinet's Triofox file-sharing and remote access platform. Attackers leveraged this n-day vulnerability—now patched—to gain unauthorized access to Triofox administrative configuration panels. With authentication circumvented, they uploaded and executed malicious payloads, specifically deploying remote access tools via the platform’s integrated antivirus feature. This enabled adversaries to establish persistent footholds, move laterally, and potentially exfiltrate sensitive corporate data and credentials. The incident underscores the ongoing urgency of patch management and monitoring, as threat actors continue to weaponize critical vulnerabilities within widely used collaboration and remote access tools. Industry experts warn of increasing attacks exploiting n-day vulnerabilities before patch adoption, reflecting a broader trend toward highly targeted lateral movement and remote tool deployment campaigns.
8 months ago
Kill Chain
ClickFix Hospitality Breach: Infostealer Attack Impacts Hotels and Their Customers
In early 2024, a cybercrime campaign known as "ClickFix" targeted hospitality providers globally using infostealer and remote access trojan (RAT) malware. Threat actors gained initial access via spear phishing and malicious links, compromising hotel systems to harvest sensitive booking data and customer contact information. Attackers leveraged this stolen data to conduct highly convincing secondary phishing attacks directed at hotel customers via both email and WhatsApp channels, exposing guests to social engineering, fraud, and further credential theft. This cascading impact emphasized the attacker's focus on exploiting trusted relationships across business and customer environments. The incident is notable for its dual-target strategy, harnessing a single breach to fuel broader downstream attacks and demonstrating attackers' sophisticated use of layered social engineering. As infostealer activity surges across the hospitality and service sectors, defenders must adapt to increasingly persistent, multi-stage campaigns that pose risks for both enterprise operations and their customers.
8 months ago
Kill Chain
runC Vulnerabilities Threaten Container Security: Docker and Kubernetes Breach 2024
In June 2024, critical vulnerabilities (CVE-2024-21626, CVE-2024-21627, and CVE-2024-21628) were disclosed in the runC container runtime, which underpins Docker, Kubernetes, and many modern container platforms. These flaws could be exploited by attackers to break out of a container, bypassing isolation controls and gaining unauthorized access to the underlying host system. A successful exploit would allow lateral movement and potentially compromise entire cloud or on-premises environments. Prompt patching and risk assessment are essential, as proof-of-concept exploits have already been published in the wild. This incident underscores the increasing sophistication and focus of attackers on supply chain and containerization technologies, as organizations accelerate cloud and DevOps adoption. As regulatory expectations around zero trust and runtime controls intensify, keeping pace with container threat vectors is now mission-critical for enterprise security teams.
8 months ago
Kill Chain
GlassWorm Supply Chain Attack: Malicious VSCode Extensions Threaten Open Source Ecosystem
In June 2024, the GlassWorm malware resurfaced in a significant supply chain attack on the OpenVSX and Visual Studio Code (VSCode) extension marketplaces. Threat actors uploaded three malicious extensions, which were collectively downloaded over 10,000 times before detection and removal. These extensions were designed to compromise developer environments by deploying malware capable of exfiltrating credentials and enabling persistent access. The attack leveraged trusted open-source ecosystems, making it difficult for end users and organizations to detect the compromise until indicators of compromise (IoCs) were published, potentially exposing sensitive data and intellectual property. This event underscores a broader rise in supply chain attacks targeting developer tools and open-source package ecosystems. The campaign highlights the urgent need for rigorous code vetting, extension auditing, and enhanced supply chain security controls as attackers increasingly exploit automated trust in widely used development platforms.
8 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports