Please confirm you are human

This browser or connection looks automated. Press and continuously hold the control for 3 seconds to enable Google-hosted web results and, when separately allowed, AI-assisted answers.

A successful check enables 100 search requests. Interactive access does not authorize scraping, systematic collection, or reuse of search output.

Hold with a pointer, or hold Space or Enter.

News

SOC Prime
socprime.com > active-threats > google-infrastructure-abused-to-hide-a-global-phishing-campaign

Global Phishing Campaign Abuses Google Infrastructure

2+ hour, 30+ min ago   (209+ words) SOC Prime Bias: High Defenders should block identified malicious domains across DNS, proxy, and SIEM controls. Organizations should monitor for unauthorized ScreenConnect installations and anomalous Telegram Bot API traffic. Google redirect protections should also be expanded to cover potentially abused…...

SOC Prime
socprime.com > active-threats > guildma-astaroth-malware-infection-from-brazilian-portuguese-email

Guildma (Astaroth) Spreads via Brazilian Phishing Email

1+ week, 1+ day ago   (343+ words) SOC Prime Bias: High A Windows host was infected with Guildma (Astaroth) malware through a malicious Brazilian Portuguese email containing a geofenced link. The attack delivers a ZIP archive with a Windows shortcut that downloads content into an alternate data…...

SOC Prime
socprime.com > active-threats > agent-tesla-bec-attack-delivers-an-in-memory-infostealer

Agent Tesla BEC Attack Delivers In-Memory Infostealer

2+ week, 1+ day ago   (323+ words) SOC Prime Bias: High A Business Email Compromise (BEC) campaign is using a sophisticated JScript dropper to distribute Agent Tesla v4 malware. The attack relies on Unicode emoji obfuscation to evade signature-based detection and uses DonutLoader to execute a reflective payload…...

SOC Prime
socprime.com > active-threats > malware-campaign-targets-korean-web-servers-running-softether-vpn

SoftEther VPN Malware Targets Korean Web Servers

3+ week, 2+ hour ago   (274+ words) SOC Prime Bias: High The Larva-26010 threat actor is targeting web and MS-SQL servers in South Korea to deploy SoftEther VPN. Compromised systems are repurposed as VPN servers, potentially using cascade connections to conceal the attackers’ true C&C infrastructure....

SOC Prime
socprime.com > active-threats > screenconnect-spread-at-scale-through-app-store-themed-phishing

Fake App Store Phishing Deploys ScreenConnect at Scale

4+ week, 2+ day ago   (295+ words) SOC Prime Bias: High A large-scale phishing campaign is using advanced social engineering techniques to deploy unauthorized ConnectWise ScreenConnect clients. Attackers impersonate trusted services such as the Microsoft Store, Apple App Store, and Google Meet through dynamic web content and…...

SOC Prime
socprime.com > active-threats > malware-analysis-of-a-phishing-email-attack-case-by-the-larva-24009-threat-actor

Larva-24009 Phishing Campaign Deploys QuasarRAT

1+ mon, 5+ day ago   (262+ words) SOC Prime Bias: High The Larva-24009 threat actor is running phishing campaigns against enterprises worldwide, including organizations in South Korea. The attacks use LNK files to launch obfuscated PowerShell scripts that install backdoors and remote access tools. The adversary focuses…...

SOC Prime
socprime.com > active-threats > multi-stage-lnk-attack-uses-ton-blockchain-to-deliver-a-node-js-backdoor

TON Blockchain LNK Attack Delivers a Node.js Backdoor

1+ mon, 3+ week ago   (216+ words) Multi-Stage LNK Attack Uses TON Blockchain to Deliver a Node.js Backdoor SOC Prime SOC Prime Bias: High Multi-Stage LNK Attack Uses TON Blockchain to Deliver a Node.js Backdoor A sophisticated multi-stage attack uses malicious LNK files delivered through…...

SOC Prime
socprime.com > active-threats > phishing-emails-masquerading-as-money-transfer-confirmations

Fake Money Transfer Emails Deliver Remcos RAT

1+ mon, 3+ week ago   (298+ words) SOC Prime Bias: High Threat actors are sending phishing emails disguised as payment confirmation messages to deliver malicious XLS attachments. These files abuse CVE-2017-0199 to retrieve an HTA file, which then launches an obfuscated PowerShell script through WMI. In the…...

Google News
socprime.com > active-threats > phishing-scam-trend-fake-project-proposal-emails

Fake Project Proposal Emails Deliver SnakeKeylogger

1+ mon, 3+ week ago   (294+ words) SOC Prime Bias: High Threat actors are distributing phishing emails disguised as urgent project proposals to deliver malware. The attack uses a compressed archive containing JavaScript malware, which then launches obfuscated PowerShell commands to deploy SnakeKeylogger. This infostealer gathers browser…...

SOC Prime
socprime.com > active-threats > op-report-from-ssa-phish-to-adaptixc2-a-multi-rat-intrusion

SSA Phishing Leads to AdaptixC2, XWorm, and ScreenConnect

2+ mon, 3+ week ago   (298+ words) SOC Prime SOC Prime Bias: High [Op Report] From SSA Phish to AdaptixC2: A Multi-RAT Intrusion A threat actor carried out a layered commodity intrusion beginning with a phishing email themed around the U.S. Social Security Administration. The operation relied on AdaptixC2 as…...