Threat Intelligence

Ransomware Threats in Europe H1 2026: A Deep Dive into Regional Attack Patterns and Dominant Threat Actors

Ransomware Threats in Europe H1 2026: A Deep Dive into Regional Attack Patterns and Dominant Threat Actors 2026-08-07 at 13:58 By Mihir Bagwe Europe faced a ransomware onslaught in the first half of 2026 that sets a troubling precedent for the remainder of the year. According to Cyble Research and Intelligence Labs (CRIL), the region […]

Ransomware Threats in Europe H1 2026: A Deep Dive into Regional Attack Patterns and Dominant Threat Actors Read More »

Day in the Life of a Cybersecurity Director: Turning Intelligence into Action

Day in the Life of a Cybersecurity Director: Turning Intelligence into Action 2026-08-06 at 17:00 By Kenneth Ng When people hear the word cybersecurity, they often picture analysts racing to stop an attack in real time. Those roles are absolutely critical, but a lot of effective security happens long before an alert ever appears.  This

Day in the Life of a Cybersecurity Director: Turning Intelligence into Action Read More »

What stops attackers wrecking industrial plants is knowing how

What stops attackers wrecking industrial plants is knowing how 2026-08-05 at 07:30 By Mirko Zorz Engineers at an Israeli food producer spent most of a week rebuilding a refrigeration system after an intruder switched the gas cooler and receiver valves to manual and pinned them open. Liquid CO2 flooded the compressors and destroyed them. The

What stops attackers wrecking industrial plants is knowing how Read More »

Release the RAVEN: An Offensive Reconnaissance and Attack Tool on Vulnerable Elasticsearch Nodes

Release the RAVEN: An Offensive Reconnaissance and Attack Tool on Vulnerable Elasticsearch Nodes 2026-07-29 at 22:22 By Karl Biron You have almost certainly interacted with Elasticsearch today. The search bar on your company’s internal wiki. The autocomplete on the e-commerce site where you ordered lunch. The log aggregation dashboard your SOC team stares at for eight

Release the RAVEN: An Offensive Reconnaissance and Attack Tool on Vulnerable Elasticsearch Nodes Read More »

Google changes how it names cyber threat actors

Google changes how it names cyber threat actors 2026-07-27 at 16:08 By Sinisa Markovic Google Threat Intelligence Group (GTIG) has started using a new naming system for the threat actors it tracks. The change comes after Mandiant and Google’s Threat Analysis Group (TAG) merged into one unit, leaving the company with two separate naming schemes

Google changes how it names cyber threat actors Read More »

APTs Top the List of Most Active Threat Actors in H1 2026

APTs Top the List of Most Active Threat Actors in H1 2026 2026-07-27 at 15:38 By Ashish Khaitan You may have heard your peers say, “Cybercrime has become industrialized.” But did you have any proof?  We do.  Cyble Research and Intelligence Labs (CRIL) closed out its tracking for the first half of 2026 with a deep analysis

APTs Top the List of Most Active Threat Actors in H1 2026 Read More »

Still Circling: Blind Eagle’s Toolkit Keeps Evolving

Still Circling: Blind Eagle’s Toolkit Keeps Evolving 2026-07-17 at 16:57 By Serhii Melnyk In June 2025, LevelBlue SpiderLabs published Tracing Blind Eagle to Proton66, in which we assessed with high confidence that Blind Eagle (also tracked as APT-C-36, APT-Q-98, TAG-144, AguilaCiega), a threat actor focused on Latin America, had moved part of its VBScript delivery

Still Circling: Blind Eagle’s Toolkit Keeps Evolving Read More »

ClickFix on macOS: Blockchain-Powered Infostealer Hidden Inside Compromised Websites

ClickFix on macOS: Blockchain-Powered Infostealer Hidden Inside Compromised Websites 2026-07-16 at 16:43 By Rodel Mendrez You’re browsing a legitimate small business website. Before the page loads, a familiar Cloudflare box appears: “Verify you are human.” It asks you to open Terminal, paste a code, and press Enter. You’ve seen this before. You follow the steps.

ClickFix on macOS: Blockchain-Powered Infostealer Hidden Inside Compromised Websites Read More »

Hiding in the Chain: Multi-Stage LNK Attack Leveraging TON Blockchain to Deliver Node.JS Backdoor

Hiding in the Chain: Multi-Stage LNK Attack Leveraging TON Blockchain to Deliver Node.JS Backdoor 2026-07-10 at 23:49 By Nathaniel Morales The LevelBlue Managed Threat Research team investigated a security alert in a customer environment involving a malicious ZIP file containing a Windows shortcut (.lnk) used for initial execution. When triggered, the LNK file executes a

Hiding in the Chain: Multi-Stage LNK Attack Leveraging TON Blockchain to Deliver Node.JS Backdoor Read More »

Turning software supply chain security into a daily habit

Turning software supply chain security into a daily habit 2026-07-10 at 08:30 By Help Net Security In this Help Net Security video, Anastasia Tikhonova, Global Threat Research Lead at Group-IB, explains how to operationalize software supply chain risk. Instead of filing an SBOM away as a compliance document, she argues teams should use it every

Turning software supply chain security into a daily habit Read More »

Hiding in the Chain: Multi-Stage LNK Attack Leveraging TON Blockchain to Deliver Node.JS Backdoor

Hiding in the Chain: Multi-Stage LNK Attack Leveraging TON Blockchain to Deliver Node.JS Backdoor 2026-07-09 at 16:52 By Nathaniel Morales The LevelBlue Managed Threat Research team investigated a security alert in a customer environment involving a malicious ZIP file containing a Windows shortcut (.lnk) used for initial execution. When triggered, the LNK file executes a

Hiding in the Chain: Multi-Stage LNK Attack Leveraging TON Blockchain to Deliver Node.JS Backdoor Read More »

From Phishing to Persistence: A CrySome RAT Infection Chain Analysis

From Phishing to Persistence: A CrySome RAT Infection Chain Analysis 2026-07-06 at 17:00 By Sean Shirley and Kyle Sopt During a recent security alert, the LevelBlue MDR SOC successfully triaged and contained a structured, multi-stage infection chain designed to deliver the CrySome remote access trojan (RAT). The incident was subsequently analyzed in depth by LevelBlue’s

From Phishing to Persistence: A CrySome RAT Infection Chain Analysis Read More »

Mid-Year Threat Trends: What H1 2026 Signals for the Rest of the Year

Mid-Year Threat Trends: What H1 2026 Signals for the Rest of the Year 2026-07-06 at 15:59 By Ashish Khaitan The first half of 2026 has given security teams little room to breathe. Ransomware operators kept up a punishing pace. If that wasn’t enough, access brokers turned network intrusions into a marketplace, and nation-state activity blurred further into hacktivism

Mid-Year Threat Trends: What H1 2026 Signals for the Rest of the Year Read More »

Non-interactive SSH attacks dominate after login

Non-interactive SSH attacks dominate after login 2026-07-03 at 08:30 By Sinisa Markovic Anyone who runs a server with SSH exposed to the internet sees the same pattern in the logs. A steady stream of automated scanners tries to log in, hour after hour, from addresses all over the world. The common picture of what comes

Non-interactive SSH attacks dominate after login Read More »

Organizations struggle to prioritize known cyber risks

Organizations struggle to prioritize known cyber risks 2026-07-03 at 07:30 By Anamarija Pogorelec Organizations collect more cyber risk data than ever, with many still struggling to build a unified view of their exposure. The latest State of Threat Management report from Filigran found that security teams continue to work across disconnected tools, leaving important context

Organizations struggle to prioritize known cyber risks Read More »

AsyncRAT and Remcos Delivered in Multi-Stage Phishing Campaign

AsyncRAT and Remcos Delivered in Multi-Stage Phishing Campaign 2026-07-02 at 17:00 By LevelBlue SpiderLabs Over the past two weeks, LevelBlue SpiderLabs has been tracking an active phishing campaign distributing malicious spreadsheet attachments. What initially appeared to be a limited phishing attempt quickly evolved into a widespread campaign impacting multiple organizations across various industries, including manufacturing,

AsyncRAT and Remcos Delivered in Multi-Stage Phishing Campaign Read More »

An Analysis of ValleyRAT Infection Campaigns from Fake Installers, Japanese Malicious Emails

An Analysis of ValleyRAT Infection Campaigns from Fake Installers, Japanese Malicious Emails 2026-06-30 at 17:04 By Hajime Takai Key points LevelBlue has identified two distinct attack vectors associated with ValleyRAT: campaigns leveraging fake installers and campaigns initiated through malicious emails. The malicious email-based attack campaign analyzed in this report appears to target both Chinese and

An Analysis of ValleyRAT Infection Campaigns from Fake Installers, Japanese Malicious Emails Read More »

Novel Java-Based QuimaRAT Targets Windows, macOS, and Linux

Novel Java-Based QuimaRAT Targets Windows, macOS, and Linux 2026-06-25 at 17:00 By Remote access trojans (RATs) are legacy threats that continue to evolve alongside an expanding and ever-changing threat landscape. Following our recently published articles about novel and notable RATs, including KarstoRAT, the latest version of ClickFix, and ClickFix’s macOS variant, we analyzed QuimaRAT, a

Novel Java-Based QuimaRAT Targets Windows, macOS, and Linux Read More »

Scroll to Top