Trend Micro Research : Articles, News, Reports

Inside SHADOW-WATER-063’s Banana RAT: From Build Server to Banking Fraud

Inside SHADOW-WATER-063’s Banana RAT: From Build Server to Banking Fraud 2026-05-19 at 16:58 By In this blog entry, researchers from the TrendAI™ MDR team discuss how they mapped the full end-to-end operation of SHADOW-WATER-063’s Banana RAT banking malware by analyzing server-side artifacts and victim-side data. This article is an excerpt from Trend Micro Research, News […]

Inside SHADOW-WATER-063’s Banana RAT: From Build Server to Banking Fraud Read More »

Agentic Governance: Why It Matters Now

Agentic Governance: Why It Matters Now 2026-05-18 at 19:42 By AI agents now act inside the trust boundary with real credentials, and agentic governance is what keeps them from quietly breaking things at machine speed. This article is an excerpt from Trend Micro Research, News and Perspectives View Original Source

Agentic Governance: Why It Matters Now Read More »

Analyzing TeamPCP’s Supply Chain Attacks: Checkmarx KICS and elementary-data in CI/CD Credential Theft

Analyzing TeamPCP’s Supply Chain Attacks: Checkmarx KICS and elementary-data in CI/CD Credential Theft 2026-05-14 at 03:45 By Our research examines the April 22 Checkmarx KICS and April 24 elementary-data incidents as part of a broader TeamPCP supply chain campaign. Across both cases, the actor abused trusted CI/CD and release workflows to steal credentials at scale.

Analyzing TeamPCP’s Supply Chain Attacks: Checkmarx KICS and elementary-data in CI/CD Credential Theft Read More »

Vibe Hacking: Two AI-Augmented Campaigns Target Government and Financial Sectors in Latin America

Vibe Hacking: Two AI-Augmented Campaigns Target Government and Financial Sectors in Latin America 2026-05-12 at 09:28 By TrendAI™ Research has identified two emerging threat campaigns—SHADOW-AETHER-040 and SHADOW-AETHER-064—that use agentic AI to drive intrusion operations against government and financial organizations in Latin America, marking these among the first cases we have observed of AI agents executing

Vibe Hacking: Two AI-Augmented Campaigns Target Government and Financial Sectors in Latin America Read More »

What Is the Instructure Canvas Breach? Impact, Risks, and What Institutions Should Do

What Is the Instructure Canvas Breach? Impact, Risks, and What Institutions Should Do 2026-05-10 at 15:32 By The Instructure Canvas breach affects universities, K–12 school districts, and teaching hospitals globally. This blog entry intends to provide context and practical guidance. This article is an excerpt from Trend Micro Research, News and Perspectives View Original Source

What Is the Instructure Canvas Breach? Impact, Risks, and What Institutions Should Do Read More »

Supporting the National Cyber Strategy: How TrendAI™ Helps

Supporting the National Cyber Strategy: How TrendAI™ Helps 2026-05-06 at 22:57 By A deeper look at the first three pillars and outlining how our capabilities directly support government agencies working to bring this strategy to life. This article is an excerpt from Trend Micro Research, News and Perspectives View Original Source

Supporting the National Cyber Strategy: How TrendAI™ Helps Read More »

InstallFix and Claude Code: How Fake Install Pages Lead to Real Compromise

InstallFix and Claude Code: How Fake Install Pages Lead to Real Compromise 2026-05-06 at 01:31 By Targeting multiple industries worldwide, the InstallFix campaign uses fake Claude AI installer pages to trick users into running malware that collects system information, disables security features, achieves persistence, and connects to attacker-controlled C&C servers for additional payloads. This article

InstallFix and Claude Code: How Fake Install Pages Lead to Real Compromise Read More »

Quasar Linux (QLNX) – A Silent Foothold in the Supply Chain: Inside a Full-Featured Linux RAT With Rootkit, PAM Backdoor, Credential Harvesting Capabilities

Quasar Linux (QLNX) – A Silent Foothold in the Supply Chain: Inside a Full-Featured Linux RAT With Rootkit, PAM Backdoor, Credential Harvesting Capabilities 2026-05-05 at 02:51 By TrendAI™ Research breaks down Quasar Linux (QLNX), a previously undocumented sophisticated Linux RAT with low detection rates. In this blog, we examine a full-featured Linux threat incorporating a

Quasar Linux (QLNX) – A Silent Foothold in the Supply Chain: Inside a Full-Featured Linux RAT With Rootkit, PAM Backdoor, Credential Harvesting Capabilities Read More »

Kuse Web App Abused to Host Phishing Document

Kuse Web App Abused to Host Phishing Document 2026-04-29 at 17:47 By Bad actors took advantage of the legitimate name and services of Kuse, a popular AI-based app designed for workplaces. The attackers exploited the users’ trust in Kuse to carry out a phishing attack. This article is an excerpt from Trend Micro Research, News

Kuse Web App Abused to Host Phishing Document Read More »

Void Dokkaebi Uses Fake Job Interview Lure to Spread Malware via Code Repositories

Void Dokkaebi Uses Fake Job Interview Lure to Spread Malware via Code Repositories 2026-04-21 at 12:56 By Our research on Void Dokkaebi’s operations uncovered a campaign that turns infected developer repositories into malware delivery channels. By spreading through trusted workflows, organizational codebases, and open-source projects, the threat can scale from a single compromise to a

Void Dokkaebi Uses Fake Job Interview Lure to Spread Malware via Code Repositories Read More »

Identity Protection in the AI Era

Identity Protection in the AI Era 2026-04-15 at 23:09 By Enterprises aiming to predict and mitigate human, machine, and AI‑agent risks at scale demand AI‑powered identity‑first security without compromise. This article is an excerpt from Trend Micro Research, News and Perspectives View Original Source

Identity Protection in the AI Era Read More »

U.S. Public Sector Under Siege: Threat Intelligence for Q1 2026

U.S. Public Sector Under Siege: Threat Intelligence for Q1 2026 2026-04-10 at 12:11 By The first quarter of 2026 has reinforced a hard truth: U.S. government agencies and educational institutions are operating in the most hostile cyber threat environment ever recorded. This article is an excerpt from Trend Micro Research, News and Perspectives View Original

U.S. Public Sector Under Siege: Threat Intelligence for Q1 2026 Read More »

Claude Code Packaging Error Remains a Lure in an Active Campaign: What Defenders Should Do

Claude Code Packaging Error Remains a Lure in an Active Campaign: What Defenders Should Do 2026-04-07 at 20:32 By Threat actors leveraged Anthropic’s Claude Code npm release packaging error to distribute Vidar, GhostSocks, and PureLog Stealer. This blog details immediate steps organizations can take and best practices to prevent further risk. This article is an excerpt from

Claude Code Packaging Error Remains a Lure in an Active Campaign: What Defenders Should Do Read More »

Weaponizing Trust Signals: Claude Code Lures and GitHub Release Payloads

Weaponizing Trust Signals: Claude Code Lures and GitHub Release Payloads 2026-04-03 at 17:52 By A packaging error in Anthropic’s Claude Code npm release briefly exposed internal source code. This entry examines how threat actors rapidly weaponized the resulting attention, pivoting an existing AI-themed campaign to spread Vidar and GhostSocks. This article is an excerpt from

Weaponizing Trust Signals: Claude Code Lures and GitHub Release Payloads Read More »

TrendAI Insight: New U.S. National Cyber Strategy

TrendAI Insight: New U.S. National Cyber Strategy 2026-04-03 at 11:01 By TrendAI reviews the White House National Cyber Strategy, outlining six pillars to strengthen U.S. cybersecurity—from deterrence and regulation to federal modernization, critical infrastructure protection, AI leadership, and workforce development. This article is an excerpt from Trend Micro Research, News and Perspectives View Original Source

TrendAI Insight: New U.S. National Cyber Strategy Read More »

TrendAI™ Research at RSAC 2026: Advancing Defense Across AI‑Driven and Cyber‑Physical Threats

TrendAI™ Research at RSAC 2026: Advancing Defense Across AI‑Driven and Cyber‑Physical Threats 2026-03-31 at 16:05 By TrendAI™ Research explored agentic AI cybercrime and EV infrastructure security through two research sessions at RSAC 2026. This article is an excerpt from Trend Micro Research, News and Perspectives View Original Source

TrendAI™ Research at RSAC 2026: Advancing Defense Across AI‑Driven and Cyber‑Physical Threats Read More »

TeamPCP’s Telnyx Attack Marks a Shift in Tactics Beyond LiteLLM

TeamPCP’s Telnyx Attack Marks a Shift in Tactics Beyond LiteLLM 2026-03-30 at 18:52 By Moving beyond their LiteLLM campaign, TeamPCP weaponizes the Telnyx Python SDK with stealthy WAV‑based payloads to steal credentials across Linux, macOS, and Windows. This article is an excerpt from Trend Micro Research, News and Perspectives View Original Source

TeamPCP’s Telnyx Attack Marks a Shift in Tactics Beyond LiteLLM Read More »

Pawn Storm Campaign Deploys PRISMEX, Targets Government and Critical Infrastructure Entities

Pawn Storm Campaign Deploys PRISMEX, Targets Government and Critical Infrastructure Entities 2026-03-26 at 06:26 By This blog discusses the steganography, cloud abuse, and email-based backdoors used against the Ukrainian defense supply chain in the latest Pawn Storm campaign that TrendAI™ Research observed and analyzed. This article is an excerpt from Trend Micro Research, News and Perspectives View Original Source

Pawn Storm Campaign Deploys PRISMEX, Targets Government and Critical Infrastructure Entities Read More »

Copyright Lures Mask a Multi‑Stage PureLog Stealer Attack on Key Industries

Copyright Lures Mask a Multi‑Stage PureLog Stealer Attack on Key Industries 2026-03-20 at 10:22 By We look into a stealthy multi‑stage attack campaign that delivers PureLog Stealer entirely in memory using encrypted, fileless techniques. This article is an excerpt from Trend Micro Research, News and Perspectives View Original Source

Copyright Lures Mask a Multi‑Stage PureLog Stealer Attack on Key Industries Read More »

Why East-West Visibility Matters for Grid Security

Why East-West Visibility Matters for Grid Security 2026-03-18 at 12:35 By Learn how east-west traffic visibility helps detect and stop lateral movement attacks inside electric grid infrastructure and critical OT networks. This article is an excerpt from Trend Micro Research, News and Perspectives View Original Source

Why East-West Visibility Matters for Grid Security Read More »

Scroll to Top