Skip to main content
FreeIntelHub
Feed Threat Feed Search Trending
Intelligence CVE Priority Vulnerability IOC Lookup IOC Feed YARA Rules Phishing Lookup Exploit Lookup Pastes Dark Web
Adversaries Threat Groups Software Campaigns
Explore Dashboard Geo Map Heatmap MITRE ATT&CK
Browse Sources Vendors Categories Sectors
RSS API
FreeIntelHub
/
Sign In

TTPs

20 articles

BleepingComputer TTPs NEW 2h ago

OpenClaw AI agent found falling for phishing attacks, spills user data

Phishing simulation on an OpenClaw email agent with various configuration profiles showed that it was susceptible to tactics commonly used to compromise huma...

T1566

BleepingComputer →

GBHackers TTPs 16h ago

Weedhack MaaS Targets Minecraft Players to Steal Credentials and Hijack Accounts

Weedhack, a Malware-as-a-Service (MaaS) operation specifically engineered to prey on Minecraft players, that has been active since at least January 2026. The...

T1078 T1588

GBHackers →

GBHackers TTPs 18h ago

Shai-Hulud Malware Campaign Abuses 23 PyPI Packages in Developer-Focused Attack

A rapidly evolving supply chain campaign dubbed “Shai-Hulud” is targeting developers through malicious Python packages. Researchers have identified 23 newly ...

GBHackers →

GBHackers TTPs Microsoft 1d ago

EDRChoker Tool Abuses Windows QoS Policies to Disrupt Endpoint Security Tools

A newly disclosed red-team tool dubbed “EDRChoker” is drawing attention across the cybersecurity community for its novel approach to disrupting Endpoint Dete...

T1562

GBHackers →

GBHackers TTPs Google Oracle 4d ago

New Magecart Attack Abuses Stripe as Malware C2

A novel Magecart campaign that weaponizes legitimate cloud services to evade detection: attackers are storing a JavaScript skimmer inside Stripe customer met...

T1041 1 IOC

GBHackers →

Security Affairs TTPs Microsoft Google Amazon 4d ago

PCPJack Exposed: Researchers Uncover 230-Node Cloud Email Relay Network

Researchers uncovered a 230-node cloud-based email relay network after the actor PCPJack accidentally exposed tools, logs, and C2 files online A threat actor...

T1598 1 IOC

Security Affairs →

Help Net Security TTPs 4d ago

AI is helping low-skill hackers pull off advanced cyberattacks

Anthropic has published an analysis of cyber-related misuse of its AI systems, examining 832 accounts that were banned for malicious cyber activity between M...

Help Net Security →

The Hacker News TTPs 5d ago

ThreatsDay Bulletin: AI Agents Gone Wrong, Sketchy C2 Tools, ClickFix Tricks, JS Backdoors & 20+ New Stories

It got stupid again. The internet still feels held together with tape.

The Hacker News →

GBHackers TTPs Proofpoint 5d ago

Proofpoint: TA4922 Deploys New RAT and Loader Arsenal

A rapidly evolving threat cluster tracked as TA4922, a Chinese-speaking cybercriminal actor deploying a diverse and expanding malware arsenal that now includ...

GBHackers →

GBHackers TTPs 5d ago

Phishing Attacks Pivot to Infostealer Malware Over Fake Login Pages

Cybercriminal tactics are evolving as phishing campaigns increasingly shift away from fake login pages toward infostealer malware designed to quietly harvest...

T1566

GBHackers →

GBHackers TTPs Cisco 5d ago

ClawHub, Cisco, and Vercel Skill Detection Tools Evaded by Malicious Uploads

Security researchers have shown that AI skill security scanners from ClawHub, Cisco, and Vercel’s skills.sh can be reliably bypassed using simple techniques,...

T1041

GBHackers →

GBHackers TTPs Amazon 6d ago

HazyBeacon Campaign Abuses AWS for Stealthy C2 Communications

A newly documented cyber espionage operation known as HazyBeacon, tracked as CL-STA-1020, is leveraging Amazon Web Services (AWS) to build stealthy command-a...

T1071

GBHackers →

SC Media TTPs Palo Alto Networks Jun 2

Heraclitus, AI LLMs, SSO, TTP, NetLogon, PAN-OS, AI Cost, Aaran Leyland... - SWN #586

SC Media →

Qualys Blog TTPs Amazon Intel Jun 2

The HazyBeacon Protocol – How Malware Weaponizes Amazon Web Services (AWS) Lambda Function URLs

Key Takeaways The Rise of Cloud-Native Command and Control (C2) Command and control (C2) infrastructure traditionally lived outside the victim environment. M...

T1071

Qualys Blog →

HackRead TTPs WordPress Jun 2

New WordPress Malware Uses Steam Profile Comments to Hide C2 Instructions

GoDaddy researchers found WordPress malware using Steam Community profile comments to hide encoded command and control data, with nearly 1,980 sites affected.

T1071

HackRead →

GBHackers TTPs Jun 2

Mustang Panda Uses LNK, PowerShell Chain to Deploy PlugX RAT

Mustang Panda is using a fake “Browser Updater” and a multi‑stage LNK–PowerShell loader to sideload PlugX through a legitimate G DATA antivirus binary, ultim...

GBHackers →

Help Net Security TTPs Sophos Jun 2

Sophos uncovers AI-powered malware lab built for EDR evasion

A threat actor used AI technologies to build a malware-testing framework for developing and refining endpoint detection and response (EDR) evasion techniques...

T1562

Help Net Security →

GBHackers TTPs Microsoft Jun 2

Hackers Use Spearphishing to Deploy AZUREVEIL Adaptix C2 Agent

Hackers are actively deploying a sophisticated malware framework dubbed AZUREVEIL, an Adaptix-based command-and-control (C2) agent, through a targeted spearp...

T1566

GBHackers →

GBHackers TTPs Jun 2

SolyxImmortal Malware Steals Passwords, Cookies, Files, and Keystrokes

A newly analyzed Python-based information stealer named SolyxImmortal is actively targeting sensitive user data, including browser credentials, cookies, docu...

T1041

GBHackers →

GBHackers TTPs Microsoft Jun 2

PHANTOMPULSE RAT Uses UAC Bypass to Hijack Windows Systems

New technical details about PHANTOMPULSE, a sophisticated remote access trojan (RAT) used in multi-stage intrusions targeting Windows environments. The malwa...

T1548

GBHackers →

1 2 3 ... 7 Next page»
FreeIntelHub · Open-source CTI platform

All articles belong to their respective owners. FreeIntelHub aggregates publicly available RSS feeds for informational purposes only. DMCA