Trend Micro Research : Research

Agenda Ransomware Group Adds SmokeLoader and NETXLOADER to Their Arsenal

Agenda Ransomware Group Adds SmokeLoader and NETXLOADER to Their Arsenal 2025-05-07 at 11:48 By During our monitoring of Agenda ransomware activities, we uncovered campaigns that made use of the SmokeLoader malware and a new loader we’ve named NETXLOADER. This article is an excerpt from Trend Micro Research, News and Perspectives View Original Source React to […]

React to this headline:

Loading spinner

Agenda Ransomware Group Adds SmokeLoader and NETXLOADER to Their Arsenal Read More »

Exploring PLeak: An Algorithmic Method for System Prompt Leakage

Exploring PLeak: An Algorithmic Method for System Prompt Leakage 2025-05-01 at 12:03 By What is PLeak, and what are the risks associated with it? We explored this algorithmic technique and how it can be used to jailbreak LLMs, which could be leveraged by threat actors to manipulate systems and steal sensitive data. This article is

React to this headline:

Loading spinner

Exploring PLeak: An Algorithmic Method for System Prompt Leakage Read More »

Earth Kasha Updates TTPs in Latest Campaign Targeting Taiwan and Japan

Earth Kasha Updates TTPs in Latest Campaign Targeting Taiwan and Japan 2025-04-30 at 12:02 By This blog discusses the latest modifications observed in Earth Kasha’s TTPs from their latest campaign detected in March 2025 targeting Taiwan and Japan. This article is an excerpt from Trend Micro Research, News and Perspectives View Original Source React to

React to this headline:

Loading spinner

Earth Kasha Updates TTPs in Latest Campaign Targeting Taiwan and Japan Read More »

NVIDIA Riva Vulnerabilities Leave AI-Powered Speech and Translation Services at Risk

NVIDIA Riva Vulnerabilities Leave AI-Powered Speech and Translation Services at Risk 2025-04-28 at 11:46 By Trend Research uncovered misconfigurations in NVIDIA Riva deployments, with two vulnerabilities, CVE-2025-23242 and CVE-2025-23243, contributing to their exposure. These security flaws could lead to unauthorized access, resource abuse, and potential misuse or theft of AI-powered inference services, including speech recognition

React to this headline:

Loading spinner

NVIDIA Riva Vulnerabilities Leave AI-Powered Speech and Translation Services at Risk Read More »

Earth Kurma APT Campaign Targets Southeast Asian Government, Telecom Sectors

Earth Kurma APT Campaign Targets Southeast Asian Government, Telecom Sectors 2025-04-25 at 11:22 By An APT group dubbed Earth Kurma is actively targeting government and telecommunications organizations in Southeast Asia using advanced malware, rootkits, and trusted cloud services to conduct cyberespionage. This article is an excerpt from Trend Micro Research, News and Perspectives View Original

React to this headline:

Loading spinner

Earth Kurma APT Campaign Targets Southeast Asian Government, Telecom Sectors Read More »

Russian Infrastructure Plays Crucial Role in North Korean Cybercrime Operations

Russian Infrastructure Plays Crucial Role in North Korean Cybercrime Operations 2025-04-24 at 05:08 By In this blog entry, we discuss how North Korea’s significant role in cybercrime – including campaigns attributed to Void Dokkaebi – is facilitated by extensive use of anonymization networks and the use of Russian IP ranges. This article is an excerpt

React to this headline:

Loading spinner

Russian Infrastructure Plays Crucial Role in North Korean Cybercrime Operations Read More »

FOG Ransomware Spread by Cybercriminals Claiming Ties to DOGE

FOG Ransomware Spread by Cybercriminals Claiming Ties to DOGE 2025-04-21 at 05:11 By This blog details our investigation of malware samples that conceal within them a FOG ransomware payload. This article is an excerpt from Trend Micro Research, News and Perspectives View Original Source React to this headline:

React to this headline:

Loading spinner

FOG Ransomware Spread by Cybercriminals Claiming Ties to DOGE Read More »

CrazyHunter Campaign Targets Taiwanese Critical Sectors

CrazyHunter Campaign Targets Taiwanese Critical Sectors 2025-04-16 at 11:55 By This blog entry details research on emerging ransomware group CrazyHunter, which has launched a sophisticated campaign aimed at Taiwan’s essential services. This article is an excerpt from Trend Micro Research, News and Perspectives View Original Source React to this headline:

React to this headline:

Loading spinner

CrazyHunter Campaign Targets Taiwanese Critical Sectors Read More »

ZDI-23-1527 and ZDI-23-1528: The Potential Impact of Overly Permissive SAS Tokens on PC Manager Supply Chains

ZDI-23-1527 and ZDI-23-1528: The Potential Impact of Overly Permissive SAS Tokens on PC Manager Supply Chains 2025-04-15 at 13:47 By In ZDI-23-1527 and ZDI-23-1528 we uncover two possible scenarios where attackers could have compromised the Microsoft PC Manager supply chain. This article is an excerpt from Trend Micro Research, News and Perspectives View Original Source

React to this headline:

Loading spinner

ZDI-23-1527 and ZDI-23-1528: The Potential Impact of Overly Permissive SAS Tokens on PC Manager Supply Chains Read More »

BPFDoor’s Hidden Controller Used Against Asia, Middle East Targets

BPFDoor’s Hidden Controller Used Against Asia, Middle East Targets 2025-04-14 at 14:12 By A controller linked to BPF backdoor can open a reverse shell, enabling deeper infiltration into compromised networks. Recent attacks have been observed targeting the telecommunications, finance, and retail sectors across South Korea, Hong Kong, Myanmar, Malaysia, and Egypt. This article is an

React to this headline:

Loading spinner

BPFDoor’s Hidden Controller Used Against Asia, Middle East Targets Read More »

Incomplete NVIDIA Patch to CVE-2024-0132 Exposes AI Infrastructure and Data to Critical Risks

Incomplete NVIDIA Patch to CVE-2024-0132 Exposes AI Infrastructure and Data to Critical Risks 2025-04-10 at 12:16 By A previously disclosed vulnerability in NVIDIA Container Toolkit has an incomplete patch, which, if exploited, could put a wide range of AI infrastructure and sensitive data at risk. This article is an excerpt from Trend Micro Research, News

React to this headline:

Loading spinner

Incomplete NVIDIA Patch to CVE-2024-0132 Exposes AI Infrastructure and Data to Critical Risks Read More »

The Espionage Toolkit of Earth Alux: A Closer Look at its Advanced Techniques

The Espionage Toolkit of Earth Alux: A Closer Look at its Advanced Techniques 2025-03-31 at 12:23 By The cyberespionage techniques of Earth Alux, a China-linked APT group, are putting critical industries at risk. The attacks, aimed at the APAC and Latin American regions, leverage powerful tools and techniques to remain hidden while stealing sensitive data.

React to this headline:

Loading spinner

The Espionage Toolkit of Earth Alux: A Closer Look at its Advanced Techniques Read More »

A Deep Dive into Water Gamayun’s Arsenal and Infrastructure

A Deep Dive into Water Gamayun’s Arsenal and Infrastructure 2025-03-28 at 17:54 By Trend Research discusses the delivery methods, custom payloads, and techniques used by Water Gamayun, the suspected Russian threat actor abusing a zero-day vulnerability in the Microsoft Management Console framework (CVE-2025-26633) to execute malicious code on infected machines. This article is an excerpt

React to this headline:

Loading spinner

A Deep Dive into Water Gamayun’s Arsenal and Infrastructure Read More »

CVE-2025-26633: How Water Gamayun Weaponizes MUIPath using MSC EvilTwin

CVE-2025-26633: How Water Gamayun Weaponizes MUIPath using MSC EvilTwin 2025-03-25 at 17:18 By Trend Research identified Russian threat actor Water Gamayun exploiting CVE-2025-26633, a zero-day vulnerability in the Microsoft Management Console that attackers exploit to execute malicious code and exfiltrate data. This article is an excerpt from Trend Micro Research, News and Perspectives View Original

React to this headline:

Loading spinner

CVE-2025-26633: How Water Gamayun Weaponizes MUIPath using MSC EvilTwin Read More »

Albabat Ransomware Group Potentially Expands Targets to Multiple OS, Uses GitHub to Streamline Operations

Albabat Ransomware Group Potentially Expands Targets to Multiple OS, Uses GitHub to Streamline Operations 2025-03-21 at 11:36 By Trend Research encounters new versions of the Albabat ransomware, which appears to target Windows, Linux, and macOS devices. We also reveal the group’s use of GitHub to streamline their ransomware operation. This article is an excerpt from

React to this headline:

Loading spinner

Albabat Ransomware Group Potentially Expands Targets to Multiple OS, Uses GitHub to Streamline Operations Read More »

ZDI-CAN-25373: Windows Shortcut Exploit Abused as Zero-Day in Widespread APT Campaigns

ZDI-CAN-25373: Windows Shortcut Exploit Abused as Zero-Day in Widespread APT Campaigns 2025-03-21 at 07:21 By Trend Zero Day Initiative™ (ZDI) uncovered both state-sponsored and cybercriminal groups extensively exploiting ZDI-CAN-25373, a Windows .lnk file vulnerability that enables hidden command execution. This article is an excerpt from Trend Micro Research, News and Perspectives View Original Source React

React to this headline:

Loading spinner

ZDI-CAN-25373: Windows Shortcut Exploit Abused as Zero-Day in Widespread APT Campaigns Read More »

SocGholish’s Intrusion Techniques Facilitate Distribution of RansomHub Ransomware

SocGholish’s Intrusion Techniques Facilitate Distribution of RansomHub Ransomware 2025-03-14 at 07:18 By Trend Research analyzed SocGholish’s MaaS framework and its role in deploying RansomHub ransomware through compromised websites, using highly obfuscated JavaScript loaders to evade detection and execute various malicious tasks. This article is an excerpt from Trend Micro Research, News and Perspectives View Original

React to this headline:

Loading spinner

SocGholish’s Intrusion Techniques Facilitate Distribution of RansomHub Ransomware Read More »

AI-Assisted Fake GitHub Repositories Fuel SmartLoader and LummaStealer Distribution

AI-Assisted Fake GitHub Repositories Fuel SmartLoader and LummaStealer Distribution 2025-03-11 at 10:15 By In this blog entry, we uncovered a campaign that uses fake GitHub repositories to distribute SmartLoader, which is then used to deliver Lumma Stealer and other malicious payloads. The campaign leverages GitHub’s trusted reputation to evade detection, using AI-generated content to make

React to this headline:

Loading spinner

AI-Assisted Fake GitHub Repositories Fuel SmartLoader and LummaStealer Distribution Read More »

From Event to Insight: Unpacking a B2B Business Email Compromise (BEC) Scenario

From Event to Insight: Unpacking a B2B Business Email Compromise (BEC) Scenario 2025-03-05 at 09:50 By Trend Micro™ Managed XDR assisted in an investigation of a B2B BEC attack that unveiled an entangled mesh weaved by the threat actor with the help of a compromised server, ensnaring three business partners in a scheme that spanned

React to this headline:

Loading spinner

From Event to Insight: Unpacking a B2B Business Email Compromise (BEC) Scenario Read More »

Exploiting DeepSeek-R1: Breaking Down Chain of Thought Security

Exploiting DeepSeek-R1: Breaking Down Chain of Thought Security 2025-03-04 at 16:00 By This entry explores how the Chain of Thought reasoning in the DeepSeek-R1 AI model can be susceptible to prompt attacks, insecure output generation, and sensitive data theft. This article is an excerpt from Trend Micro Research, News and Perspectives View Original Source React

React to this headline:

Loading spinner

Exploiting DeepSeek-R1: Breaking Down Chain of Thought Security Read More »

Scroll to Top