Emerging Threats

TIKTOUK: Tracing a WordPress Credential Collection Toolkit

TIKTOUK: Tracing a WordPress Credential Collection Toolkit 2026-10-01 at 15:41 By Maor Gabay TIKTOUK brings together WordPress probing, collection of exposed configuration data, recovery of encrypted email credentials, and JavaScript secret scanning. Its two Python components and Go-based Linux crawler turn website responses into structured results for a central hub: an HTTP service that distributes […]

TIKTOUK: Tracing a WordPress Credential Collection Toolkit Read More »

Citrix NetScaler CVE-2026-88771: Observed Exploitation Artifacts and Hunt Indicators

Citrix NetScaler CVE-2026-88771: Observed Exploitation Artifacts and Hunt Indicators 2026-09-30 at 23:34 By Sean Shirley With contributions from James Rodriguez, Gus Staminatos, and Timmy Lister. This article is an excerpt from LevelBlue SpiderLabs Blog View Original Source

Citrix NetScaler CVE-2026-88771: Observed Exploitation Artifacts and Hunt Indicators Read More »

Citrix NetScaler Zero-Day Exploited Globally

Citrix NetScaler Zero-Day Exploited Globally 2026-09-29 at 18:41 By Karl Sigler On Sept 27, Citrix released patches for two critical vulnerabilities being exploited in the wild. Based on current information, we confirm there has been no exposure or impact to LevelBlue or our clients. CISA has already added these vulnerabilities to the Known Exploited Vulnerabilities […]

Citrix NetScaler Zero-Day Exploited Globally Read More »

File Acquisition May Be Recorded as “FileAccessed” in Microsoft 365 (“M365”)

File Acquisition May Be Recorded as “FileAccessed” in Microsoft 365 (“M365”) 2026-09-24 at 15:30 By A recent trend has emerged where threat actor groups (e.g., ShinyHunters, PEAR, HELIX, etc.) have been leveraging phishing and vishing techniques to gain access to M365 email accounts. Through identity and token abuse, these actors have then automated large-scale file […]

File Acquisition May Be Recorded as “FileAccessed” in Microsoft 365 (“M365”) Read More »

One Patch Behind: Nightmare-Eclipse’s ShieldCrash and the Defender Bypass That Won’t Stay Fixed

One Patch Behind: Nightmare-Eclipse’s ShieldCrash and the Defender Bypass That Won’t Stay Fixed 2026-09-16 at 16:35 By Serhii Melnyk and Timmy Lister In our previous blog, we analyzed four proofs of concept (PoCs) from the leak persona Nightmare-Eclipse that targeted Kaspersky, Avast, NVIDIA, and CrowdStrike, respectively. This article is an excerpt from LevelBlue SpiderLabs Blog […]

One Patch Behind: Nightmare-Eclipse’s ShieldCrash and the Defender Bypass That Won’t Stay Fixed Read More »

Expanding the Attack Surface: Analyzing Nightmare-Eclipse’s Latest PoCs

Expanding the Attack Surface: Analyzing Nightmare-Eclipse’s Latest PoCs 2026-09-09 at 15:37 By Serhii Melnyk and Timmy Lister In our previous blog, we explored a series of disclosures from the leak persona Nightmare-Eclipse that focused heavily on Microsoft’s ecosystem, including Windows Defender, Cloud Files, and core operating system functionality. This article is an excerpt from LevelBlue SpiderLabs […]

Expanding the Attack Surface: Analyzing Nightmare-Eclipse’s Latest PoCs Read More »

Still Circling: Inside the Operator Behind Blind Eagle’s GitHub Loader

Still Circling: Inside the Operator Behind Blind Eagle’s GitHub Loader 2026-08-28 at 17:00 By Serhii Melnyk This is a collaborative follow-up to our original post, developed jointly with Emmanuel C., an independent security researcher not affiliated with LevelBlue, who contributed additional infrastructure and tooling findings based on an analysis of the same GitHub staging account. […]

Still Circling: Inside the Operator Behind Blind Eagle’s GitHub Loader Read More »

Cloud Sync Root RegistrationShieldBreak: Hunting Windows Defender Remediation Abuse and Cloud Files Hijacking

Cloud Sync Root RegistrationShieldBreak: Hunting Windows Defender Remediation Abuse and Cloud Files Hijacking 2026-08-19 at 18:40 By Serhii Melnyk and Timmy Lister Following GreenPlasma, YellowKey and MiniPlasma, RoguePlanet and GreatXML, and LegacyHive, the Nightmare-Eclipse disclosure actor has published ShieldBreak — its latest Windows proof of concept (PoC) released shortly after Microsoft’s August 2026 Patch Tuesday. […]

Cloud Sync Root RegistrationShieldBreak: Hunting Windows Defender Remediation Abuse and Cloud Files Hijacking Read More »

Beyond the Inbox: How BEC Leads to SSO Abuse

Beyond the Inbox: How BEC Leads to SSO Abuse 2026-08-13 at 20:40 By Jamie Mamroe and Federico Cedolini For years, many business email compromise (BEC) investigations have followed a familiar playbook: an attacker phishes credentials, logs into the victim’s mailbox, establishes persistence with inbox rules, monitors communications, and waits for an opportunity to steal money […]

Beyond the Inbox: How BEC Leads to SSO Abuse Read More »

The Infrastructure Relay: Inside Multi-Stage Phishing Redirection Chains

The Infrastructure Relay: Inside Multi-Stage Phishing Redirection Chains 2026-08-12 at 16:42 By Karla Agregado To stay ahead of evolving threats, LevelBlue utilizes a machine-learning-based URL scanner that constantly evaluates the digital landscape. We closely monitor VirusTotal for instances where LevelBlue acts as the sole detection layer — a crucial tactic for spotting new phishing campaigns […]

The Infrastructure Relay: Inside Multi-Stage Phishing Redirection Chains Read More »

Practical Cybersecurity for Small Water Utilities: 5 Steps to Reduce Operational Risk

Practical Cybersecurity for Small Water Utilities: 5 Steps to Reduce Operational Risk 2026-08-11 at 17:00 By Nolen Johnson Recent cyberattacks against U.S. water and wastewater systems delivered an important reminder: disrupting operational technology (OT) does not always require sophisticated malware or a previously unknown vulnerability. In the July 2026 activity, internet-facing programmable logic controllers (PLCs), […]

Practical Cybersecurity for Small Water Utilities: 5 Steps to Reduce Operational Risk Read More »

Beyond ‘Fake Updates’: From Application Store-Themed Phishing to Large-Scale Distribution of ScreenConnect

Beyond ‘Fake Updates’: From Application Store-Themed Phishing to Large-Scale Distribution of ScreenConnect 2026-08-07 at 16:10 By King Orande and Cris Tomboc The LevelBlue OpsCTI Team recently identified a large-scale phishing campaign leveraging a new social engineering method to deploy unauthorized ConnectWise ScreenConnect clients. Rather than relying on conventional phishing pages, the campaign recreates convincing software […]

Beyond ‘Fake Updates’: From Application Store-Themed Phishing to Large-Scale Distribution of ScreenConnect Read More »

Review of the July 2026 Cyberattacks Against U.S. Water and Wastewater Systems

Review of the July 2026 Cyberattacks Against U.S. Water and Wastewater Systems 2026-08-04 at 16:20 By Nikita Kazymirskyi In light of the water-sector activity described below, we’ve increased monitoring for related indicators of compromise across our client environments. Please contact your LevelBlue account team with questions specific to your environment. This article is an excerpt […]

Review of the July 2026 Cyberattacks Against U.S. Water and Wastewater Systems Read More »

LevelBlue TTP Briefing Q2 2026: Stolen Identities Outpace Defenses

LevelBlue TTP Briefing Q2 2026: Stolen Identities Outpace Defenses 2026-07-23 at 17:00 By Explore the latest tactics, techniques, and procedures (TTPs) our incident response (IR) experts are actively facing in the quarterly TTP Briefing, a report built on frontline threat intelligence from our global incident response investigations across LevelBlue during Q2 2026. This article is […]

LevelBlue TTP Briefing Q2 2026: Stolen Identities Outpace Defenses Read More »

LegacyHive: Nightmare-Eclipse’s Latest Zero-Day Drop with a Stripped PoC

LegacyHive: Nightmare-Eclipse’s Latest Zero-Day Drop with a Stripped PoC 2026-07-20 at 15:35 By Pauline Bolaños Vexed researcher Nightmare-Eclipse (aka Chaotic Eclipse, Dead Eclipse, and MSNightmare) released his ninth unpatched Windows vulnerability called LegacyHive. This latest bug drop is a Local Privilege Escalation (LPE) vulnerability affecting Windows User Profile, a component responsible for loading and unloading […]

LegacyHive: Nightmare-Eclipse’s Latest Zero-Day Drop with a Stripped PoC Read More »

Still Circling: Blind Eagle’s Toolkit Keeps Evolving

Still Circling: Blind Eagle’s Toolkit Keeps Evolving 2026-07-17 at 16:57 By Serhii Melnyk In June 2025, LevelBlue SpiderLabs published Tracing Blind Eagle to Proton66, in which we assessed with high confidence that Blind Eagle (also tracked as APT-C-36, APT-Q-98, TAG-144, AguilaCiega), a threat actor focused on Latin America, had moved part of its VBScript delivery […]

Still Circling: Blind Eagle’s Toolkit Keeps Evolving Read More »

ClickFix on macOS: Blockchain-Powered Infostealer Hidden Inside Compromised Websites

ClickFix on macOS: Blockchain-Powered Infostealer Hidden Inside Compromised Websites 2026-07-16 at 16:43 By Rodel Mendrez You’re browsing a legitimate small business website. Before the page loads, a familiar Cloudflare box appears: “Verify you are human.” It asks you to open Terminal, paste a code, and press Enter. You’ve seen this before. You follow the steps. […]

ClickFix on macOS: Blockchain-Powered Infostealer Hidden Inside Compromised Websites Read More »

Hiding in the Chain: Multi-Stage LNK Attack Leveraging TON Blockchain to Deliver Node.JS Backdoor

Hiding in the Chain: Multi-Stage LNK Attack Leveraging TON Blockchain to Deliver Node.JS Backdoor 2026-07-10 at 23:49 By Nathaniel Morales The LevelBlue Managed Threat Research team investigated a security alert in a customer environment involving a malicious ZIP file containing a Windows shortcut (.lnk) used for initial execution. When triggered, the LNK file executes a […]

Hiding in the Chain: Multi-Stage LNK Attack Leveraging TON Blockchain to Deliver Node.JS Backdoor Read More »

Hiding in the Chain: Multi-Stage LNK Attack Leveraging TON Blockchain to Deliver Node.JS Backdoor

Hiding in the Chain: Multi-Stage LNK Attack Leveraging TON Blockchain to Deliver Node.JS Backdoor 2026-07-09 at 16:52 By Nathaniel Morales The LevelBlue Managed Threat Research team investigated a security alert in a customer environment involving a malicious ZIP file containing a Windows shortcut (.lnk) used for initial execution. When triggered, the LNK file executes a […]

Hiding in the Chain: Multi-Stage LNK Attack Leveraging TON Blockchain to Deliver Node.JS Backdoor Read More »

Scroll to Top