Skip to main content
FreeIntelHub
Feed Threat Feed Search Trending
Intelligence CVE Priority Vulnerability IOC Lookup IOC Feed YARA Rules Phishing Lookup Exploit Lookup Pastes Dark Web
Adversaries Threat Groups Software Campaigns
Explore Dashboard Geo Map Heatmap MITRE ATT&CK
Browse Sources Vendors Categories Sectors
RSS API
FreeIntelHub
/
Sign In

TTPs

20 articles

The Hacker News TTPs Microsoft Broadcom May 20

Webworm Deploys EchoCreep and GraphWorm Backdoors Using Discord and MS Graph API

Cybersecurity researchers have flagged fresh activity from a China-aligned threat actor known as Webworm in 2025, deploying custom backdoors that employ Disc...

The Hacker News →

GBHackers TTPs May 20

Gremlin Stealer Hides C2 and Exfiltration Paths in Encrypted Resources

A newly identified variant of the Gremlin stealer malware is leveraging advanced obfuscation techniques to conceal its command-and-control (C2) infrastructur...

T1027 T1041

GBHackers →

GBHackers TTPs Microsoft May 20

GraphWorm Malware Abuses Microsoft OneDrive for Stealthy C2 Operations

A new activity from Webworm, a China-aligned advanced persistent threat (APT) group, revealing a significant evolution in its cyber espionage toolkit during ...

GBHackers →

Infosecurity Magazine TTPs May 20

China-Linked Webworm APT Evolves Tactics, Expands to European Targets

China-linked Webworm APT expands beyond Asia, targeting European government organizations and refining its cyber espionage tactics, according to ESET research

Infosecurity Magazine →

ESET Research TTPs May 20

Webworm: New burrowing techniques

ESET researchers describe new tools and techniques that the Webworm APT group recently added to its arsenal

ESET Research →

GBHackers TTPs May 20

Void Botnet Leverages Ethereum for Resilient C2

A newly identified botnet, named Void, is leveraging Ethereum smart contracts to build a resilient, hard-to-disrupt command-and-control (C2) infrastructure, ...

GBHackers →

GBHackers TTPs Google May 20

Trapdoor Android Ad Fraud Ring Abuses 455 Apps for Fake Clicks

A large-scale Android ad fraud campaign named “Trapdoor,” exposing a sophisticated ecosystem built on 455 malicious apps and 183 command-and-control (C2) dom...

T1189

GBHackers →

GBHackers TTPs May 20

Mini Shai-Hulud Attack Hits npm Ecosystem, Compromising Over 600 Packages

A large-scale supply chain attack targeting the npm ecosystem has resurfaced with a new variant of the Mini Shai-Hulud malware, compromising more than 600 pa...

T1195

GBHackers →

Help Net Security TTPs May 20

What happens when your identity provider becomes the kill chain

In this Help Net Security video, Colin Constable, CTO at Atsign, explains why your identity provider (IdP) has become the kill chain in cyberattacks. Attacke...

T1598

Help Net Security →

AWS Security Blog TTPs Amazon May 19

CIRT insights: How to help prevent unauthorized account removals from AWS Organizations

The AWS Customer Incident Response Team works with customers to help them recover from active security incidents. As part of this work, the team often uncove...

AWS Security Blog →

The Hacker News TTPs Google Intel May 19

Trapdoor Android Ad Fraud Scheme Hit 659 Million Daily Bid Requests Using 455 Apps

Cybersecurity researchers have disclosed details of a new ad fraud and malvertising operation dubbed Trapdoor targeting Android device users. The activity, p...

T1189

The Hacker News →

Help Net Security TTPs Microsoft Google Apple SentinelOne May 19

New macOS infostealer impersonates Apple, Microsoft, and Google in a single attack chain

A SHub macOS infostealer variant called Reaper impersonates Apple, Microsoft, and Google to trick users into executing malicious code, then targets browser d...

T1204

Help Net Security →

GBHackers TTPs Oracle May 19

JavaScript Malware Campaign Drops Crypto Clipper via PowerShell

A large-scale CountLoader campaign that uses layered obfuscation, multi-stage payload delivery, and covert command-and-control (C2) communication to deploy c...

T1027

GBHackers →

SC Media TTPs May 18

Malaysian government-linked campaign used hidden infrastructure for years

The operation, believed to be a long-term espionage effort, has maintained its command and control infrastructure for several years by employing sophisticate...

T1071

SC Media →

HackRead TTPs Cloudflare May 18

Government Backed Hackers Abuse Cloudflare in Malaysian Espionage Campaign

A campaign linked to a suspected Malaysian government operation has been using hidden command and control infrastructure for…

T1071

HackRead →

GBHackers TTPs May 18

Gremlin Stealer Hides Payloads in .NET Resources to Evade Detection

A newly discovered variant of the Gremlin Stealer is raising concerns among security researchers by adopting stealth-focused techniques that significantly re...

GBHackers →

Mandiant Blog TTPs Google Intel May 15

Welcome to BlackFile: Inside a Vishing Extortion Operation

Written by: Austin Larsen, Tyler McLellan, Genevieve Stark, Dan Ebreo Introduction Google Threat Intelligence Group (GTIG) has continued to track an expansiv...

T1566 T1557

Mandiant Blog →

Unit 42 TTPs May 15

Gremlin Stealer's Evolved Tactics: Hiding in Plain Sight With Resource Files

Unit 42 analyzes the evolution of Gremlin stealer. This variant uses advanced obfuscation, crypto clipping and session hijacking to compromise data.

T1027

Unit 42 →

GBHackers TTPs May 14

New Malware Framework Enables Screen Control and UAC Bypass

A sophisticated malware framework capable of screen control, browser artifact access, and User Account Control (UAC) bypass, highlighting how attackers are i...

T1548

GBHackers →

CSO Online TTPs May 13

Fired employee sought AI help to hide deletion of hosting firm’s customer data

The apparent revenge deletion of US federal databases after the dismissal of twin brothers from an online hosting company is another reminder to IT and HR le...

CSO Online →

«Previous page 1 2 3 4 5 6 7 Next page»
FreeIntelHub · Open-source CTI platform

All articles belong to their respective owners. FreeIntelHub aggregates publicly available RSS feeds for informational purposes only. DMCA