Cyberattack

Cyberattack / Industry Updates

APT37 Strikes Again, This Time with NarwhalRAT

North Korea's APT37 has launched a new NarwhalRAT campaign using spearphishing emails and malicious LNK files to deploy data-stealing malware. Researchers also uncovered infrastructure links and fresh indicators that expand the group's known operational footprint.

A DNS Investigation of LenAI’s ErrTraffic ClickFix Distribution Network

An analysis of LenAI's ErrTraffic ClickFix infrastructure uncovered new DNS links, exposing malicious domains, IPs, typosquatting clusters, and email connections that broaden threat visibility and support stronger detection and incident response through expanded network intelligence.

Inside a TDS-Powered ClickFix Malware Ecosystem: A DNS Deep Dive

DNS analysis of a malware distribution ecosystem uncovered thousands of linked artifacts, exposing typosquatting, malicious infrastructure and victim connections that broaden detection opportunities beyond Check Point Research's original indicators through expanded DNS intelligence correlation efforts.

DNS Investigation: Threat Actor TA4922 Goes Global

TA4922 is expanding beyond nearby targets, deploying a fast-changing malware arsenal across Europe and Africa. A DNS investigation uncovered thousands of connected domains, dozens of malicious assets and signs of compromised victim infrastructure worldwide today.

Under the DNS Hood of an Ongoing Legacy MSHTA Tool Attack

A DNS analysis of infrastructure behind ongoing MSHTA abuse uncovered malicious registrations, typosquatting clusters, victim activity, and hundreds of linked indicators, revealing how legacy Windows tooling continues enabling modern malware campaigns through interconnected DNS intelligence.

macOS ClickFix Campaign Delivers AMOS and Other Infostealers: A DNS Deep Dive

A DNS deep dive into Microsoft's macOS ClickFix campaign uncovered victim infrastructure, typosquatting clusters, malicious registrations, and hundreds of linked indicators, exposing a broader infostealer ecosystem beyond the original 140 network IoCs identified by Microsoft.

DNS Deep Dive: TA416 European Government Espionage Campaigns

An extensive DNS analysis of TA416's renewed European espionage campaign uncovered malicious infrastructure, typosquatting clusters, historical network activity, and thousands of connected artifacts that expand defenders' visibility beyond Proofpoint's original indicators for proactive threat hunting.

DNS Deep Dive: GHOST STADIUM Takes Advantage of FIFA 2026

A DNS investigation of the GHOST STADIUM phishing operation uncovered typosquatting clusters, malicious infrastructure, victim-linked IP activity, and thousands of connected domains, revealing the scale of a FIFA 2026 ticket fraud ecosystem.

A DNS Investigation of Shadow-Earth-053

A DNS investigation of Shadow-Earth-053 uncovered hundreds of victim-linked connections and a sprawling infrastructure tied to China-aligned cyber-espionage. Analysis of known indicators exposed additional domains, IP addresses, and registration patterns that broaden the campaign's suspected footprint.

DNS Deep Diving into FakeWallet Crypto Stealer

A DNS-focused investigation of the FakeWallet crypto-stealer campaign uncovered links to malicious infrastructure, potential victims, and thousands of connected domains, revealing signs of pre-staged operations and suggesting the wallet-phishing scheme was broader and longer-running than first reported.