Live

Intelligence Feed

Latest threat intelligence articles from trusted security sources, auto-processed to extract entities, IoCs, and TTPs.

Filtered by source: fortinet Clear filter
Tracking Malware and Attack Expansion: A Hacker Group’s Journey across Asia | FortiGuard Labs

3w ago · fortinet

FortiGuard Labs has identified a persistent hacker group conducting phishing campaigns across Asia, targeting users in Mainland China, Taiwan, Japan, and Malaysia. The group uses malicious PDFs, Word, and Excel documents that mimic official government communications to deliver malware such as Winos 4.0 and HoldingHands. The attacks have evolved to include multi-stage delivery mechanisms, abuse of legitimate digital signatures, and use of Windows Task Scheduler for stealthy execution, complicating detection and analysis.

28 IoCs
Confucius Espionage: From Stealer to Backdoor | FortiGuard Labs

3w ago · fortinet

The Confucius threat group, a state-aligned cyber-espionage actor, has evolved its tactics from using document stealers like WooperStealer to deploying Python-based backdoors such as AnonDoor. Initially targeting organizations in Pakistan via spear-phishing and malicious Office documents, the group has advanced to using LNK files, DLL side-loading, and scheduled tasks for persistence. Their campaigns now feature layered obfuscation, custom Python RATs, and sophisticated data exfiltration techniques, indicating a growing level of operational sophistication.

16 IoCs 1 Malware