Two threat campaigns used agentic AI to run full kill chain operations against government and financial targets in Latin America. TrendAI™ Research breaks down SHADOW-AETHER-040 and SHADOW-AETHER-064: https://t.co/QD2hz4R1yw
We investigated a CN #APT that targeted multiple governments and companies with government contracts in Asia. In half of the targets we found a second group with different malware toolkit but sharing the infection vector and some post-exploitation tools https://t.co/IN12VBv5k4
Our research shows PeckBirdy is a multi-environment C&C framework used by China-aligned actors to deploy modular backdoors. Malware analysis details are available on our blog: https://t.co/P1ia59JKsd
DKnife can hijack #Android application updates by intercepting the update manifest requests. The targeted applications are mostly popular Chinese-language services.
We saw Earth Estries, an advanced #APT group, sharing its access to Earth Naga (Flax Typhoon). We introduce the term "Premier Pass" to describe this behavior, and propose a four-tier classification framework for collaboration types among advanced groups https://t.co/JVlnE9dP1S
Coordinated intrusions by Earth Estries and Earth Naga show that defenders must rethink attribution and monitor the broader China-aligned APT ecosystem, not just isolated groups. Get the latest insights: https://t.co/iEkJ5O15QT
We first introduced the term “Premier Pass” during my talk at @pivot_con — describing a trend of advanced collaboration among China-aligned APT groups like Earth Estries & Earth Naga.
Today, we published a blog post that explores the concept in depth.
https://t.co/vgIq4IFGJ9
Trend™ Research exposes how attackers use SNMP and Telnet exploits to compromise Cisco switches and deploy rootkits. See how Trend Vision One™ enables proactive defense: https://t.co/SBCV7jqW0Y
TAOTH used spear phishing and a reregistered, previously abandoned update domain to infect devices of dissidents, journalists, and executives in East Asia. Our analysis details their infection methods and defense strategies.
See our threat insights: ⬇️ https://t.co/lrfcDFE6lo
Trend™ Research has identified Earth Lamia as an #APT threat actor that exploits vulnerabilities in web applications to gain access to organizations, using various techniques for data exfiltration.
Learn more: ⬇️ https://t.co/jq3yHMdHSU
Trend Micro's @jspchc writes about an active threat actor, named Earth Lamia, targeting multiple industries in Brazil, India & Southeast Asian countries since at least 2023. The APT primarily exploits vulnerabilities in web applications for access. https://t.co/JIoL0NVmfU
We released a report on a threat actor using an updated version of #Shadowpad including anti-debugging features, that in some cases deploy a custom ransomware family. We have mainly seen the manufacturing industry being targeted in Europe and Asia https://t.co/dZsevM8wLr #APT
Discover the threat posed by the cross-platform DarkNimbus backdoor. Earth Minotaur utilizes the MOONSHINE exploit kit to target Android and Windows devices.
Read the full report on our blog: ⬇️ https://t.co/gQvDbtjqPp
Trend Micro's Joseph C Chen & Daniel Lunghi investigate a group named Earth Minotaur that used the MOONSHINE exploit kit leading to the DarkNimbus Android backdoor. MOONSHINE exploit kit targets vulnerabilities in instant messaging apps on Android devices. https://t.co/xpjNvKKnV5
New research from @jspchc and @thehellu uncovers a campaign leveraging the Moonshine framework to deliver Chrome Nday exploits targeting Android devices. Thanks for giving the credit to my research! #moonshine
Our latest report presents Earth Minotaur, a threat actor targeting Tibetans and Uyghurs using Moonshine, an exploitation framework for Android described in 2019 by @citizenlab leveraging vulnerabilities in applications embedding old versions of Chrome https://t.co/cWcCIRQhEZ
Trend Micro researchers analyse two distinct attack chains employed by the Earth Estries (aka Salt Typhoon) group that demonstrate the varied tactics, techniques and tools they use to compromise targeted systems. https://t.co/cnigWOV20R
NEW ENTRY: In this report, we detailed how Waterbear and Deuterbear operate, including the stages of infection, command and control (C&C) interaction, and #malware component behavior.
Find out more about these two malware variants here: https://t.co/BqBHgjd6QO
Trend Micro's @jspchc & @thehellu look into a new APT campaign, named Earth Krahang, targeting several government entities worldwide, with a strong focus on Southeast Asia. Their investigation identified multiple links between Earth Krahang & Earth Lusca. https://t.co/GEpIiT6v9U