TrendAI™ Threat Research
27 articles
-
ResearchEdge Under Siege: How State-Sponsored Actors Exploit Your Perimeter
Edge devices have become a primary entry point for state-sponsored espionage, giving attackers a cheaper, faster path to network access, credential theft, and traffic interception. Our report examines the threat landscape, economics, and actor activity driving this shift, along with what CISOs and security leaders can do to respond.
April 20th, 2026 12 minTrendAI™ Threat Research
Read article -
ResearchRansomware Spotlight: Agenda
Agenda has rapidly grown into one of the most prolific and dangerous ransomware operations, leveraging advanced techniques, cross-platform variants, and alliances with other major threat groups. Its aggressive double-extortion model and expanding victim base across critical industries make it a serious enterprise risk that demands proactive detection and defense.
March 18th, 2026 10 minTrendAI™ Threat Research
Read article -
ResearchRansomware Spotlight: Rhysida
The threat actors behind the Rhysida ransomware targeted multiple industries by posing as a cybersecurity team that offered to help its victims identify security weaknesses in their networks and systems. Although the group’s activity was first observed back in May 2023, its leak site was established as early as March 2023. Like other ransomware groups, it employs double extortion tactics to pressure its victims into paying a ransom demand in Bitcoin.
February 21st, 2024 7 minTrendAI™ Threat Research
Read article -
ResearchRansomware Spotlight: Play
Play is shaping up to be a player on the rise within the ransomware landscape, with its operators likely to continue using the ransomware in future. We take a deep dive into its operations and offer ways in which organizations can shore up their defenses against this emerging threat.
July 21st, 2023 8 minTrendAI™ Threat Research
Read article -
ResearchRansomware Spotlight: TargetCompany
We detail everything you need to know about TargetCompany, a ransomware family with different monickers, including the evolution of its attack flow as it cemented its place in the threat landscape.
June 5th, 2023 8 minTrendAI™ Threat Research
Read article -
ResearchRansomware Spotlight: BlackCat
Known for its unconventional methods and use of advanced extortion techniques, BlackCat has quickly risen to prominence in the cybercrime community. As this ransomware group forges its way to gain more clout, we examine its operations and discuss how organizations can shore up their defenses against it.
October 27th, 2022 8 minTrendAI™ Threat Research
Read article -
ResearchRansomware Spotlight: Black Basta
A relative newcomer in 2022, the Black Basta ransomware group has wasted no time making a name for itself by upgrading its toolset and racking up its victim count around the world mere months since its ransomware was first detected. Learn more about this new ransomware and fortify your organization’s defenses against this threat.
September 1st, 2022 8 minTrendAI™ Threat Research
Read article -
ResearchRansomware Spotlight: BlackByte
BlackByte is a ransomware group that has been building a name for itself since 2021. Like its contemporaries, it has gone after critical infrastructure for a higher chance of getting a payout. What techniques sets it apart?
July 5th, 2022 8 minTrendAI™ Threat Research
Read article -
ResearchRansomware Spotlight: RansomEXX
RansomEXX is a ransomware variant that gained notoriety after a spate of attacks in 2020 and continues to be active today. With its targeted nature and history for choosing high-profile victims, we shine our spotlight on RansomEXX to reveal its tactics, techniques, and procedures.
May 17th, 2022 9 minTrendAI™ Threat Research
Read article -
ResearchRansomware Spotlight: AvosLocker
AvosLocker is a relatively new ransomware variant that sports the staples of modern ransomware, namely a layered extortion scheme that begins with stolen data. We shed light on this emerging ransomware family and its key techniques.
April 4th, 2022 8 minTrendAI™ Threat Research
Read article -
ResearchProbing the Activities of Cloud-Based Cryptocurrency-Mining Groups
Our research into cloud-based cryptocurrency mining sheds light on the malicious actor groups involved in this space, their ongoing battle for cloud resources, and the actual extent of the impact of their attacks.
March 29th, 2022 7 minTrendAI™ Threat Research
Read article -
ResearchRansomware Spotlight: REvil
Now that the reign of REvil has come to an end, it's time to regroup and strategize. What can organizations learn from REvil’s tactics? We review the rise, downfall, and future of its operations using insights into the group's arsenal and inner inner workings.
December 20th, 2021 9 minTrendAI™ Threat Research
Read article -
ResearchModern Ransomware's Double Extortion Tactics and How to Protect Enterprises Against Them
Modern ransomware like Nefilim present new challenges and security concerns for enterprises across the world. How do these new families differ from traditional ransomware? And what can organizations do to mitigate risks?
June 8th, 2021 14 minTrendAI™ Threat Research
Read article -
ResearchSecurity 101: Virtual Patching
What happens to an unpatched or vulnerable application or organization’s IT infrastructure? Here's how virtual patching helps enterprises address vulnerability and patch management woes.
March 4th, 2021 5 minTrendAI™ Threat Research
Read article -
ResearchCOVID-19 Used in Malicious Campaigns
Threat actors take advantage of the spread of COVID-19 for malicious campaigns. Goods and services related to the virus also appear in underground marketplaces and cybercriminal forums.
November 11th, 2020 23 minTrendAI™ Threat Research
Read article -
ResearchUnusual CEO Fraud via Deepfake Audio Steals US$243,000 From UK Company
An unusual case of CEO fraud used a deepfake audio, an artificial intelligence (AI)-generated audio, and was reported to have conned US$243,000 from a U.K.-based energy company.
September 5th, 2019 3 minTrendAI™ Threat Research
Read article -
ResearchBEC Scam Costing Almost US$11 Million Leads to FBI Arrest of Nigerian Businessman
The CEO of the Invictus Group of Companies, Obinwanne Okeke, has reportedly been arrested by the FBI after he was accused of conspiracy to commit computer and wire fraud.
August 20th, 2019 4 minTrendAI™ Threat Research
Read article -
ResearchWhat You Need to Know About the LockerGoga Ransomware
The systems of Norsk Hydro were reportedly struck by LockerGoga ransomware. Here's what you need to know about this threat and how to defend against it.
March 20th, 2019 7 minTrendAI™ Threat Research
Read article -
ResearchAttacks Against Industrial Machines via Vulnerable Radio Remote Controllers: Security Analysis and Recommendations
Radio frequency (RF) technology is being used in operations to control various industrial machines. However, the lack of implemented security in RF communication protocols could lead to production sabotage, system control, and unauthorized access.
January 15th, 2019 8 minTrendAI™ Threat Research
Read article -
ResearchCryptocurrency-mining Malware Targets Linux Systems, Uses Rootkit for Stealth
We recently encountered a cryptocurrency-mining malware affecting Linux systems. It is notable for being bundled with a rootkit component that hides the malicious process’ presence from monitoring tools.
November 8th, 2018 6 minTrendAI™ Threat Research
Read article -
ResearchRed Alert 2.0 Android Trojan Spreads Via Third Party App Stores
A spate of new attacks targeting the Android operating system have been discovered using a banking trojan named Red Alert 2.0.
September 20th, 2017 2 minTrendAI™ Threat Research
Read article -
ResearchA Shift in the ATM Malware Landscape: From Physical to Network-based Attacks
ATM malware has become a mainstay in many cybercriminals’ arsenal due to its capability to steal money. In our joint efforts with Europol’s EC3, we explain in detail how criminals continue to leverage different ATM malware families and attack types.
September 5th, 2017 4 minTrendAI™ Threat Research, Europol’s European Cybercrime Centre (EC3)
Read article -
ResearchWhat do Hackers do with Your Stolen Identity?
Identity theft is currently a gold mine for cybercriminals—one that reached an all-time high in 2016, with up to $16 billion worth of losses caused by fraud and identity theft. But what exactly happens with the stolen information?
June 21st, 2017 9 minTrendAI™ Threat Research
Read article -
ResearchRogue Robots: Testing the Limits of an Industrial Robot’s Security
The modern world relies heavily on industrial robots. But is the current robotics ecosystem secure enough to withstand a cyber attack?
May 3rd, 2017 5 minTrendAI™ Threat Research
Read article -
ResearchFrom Espionage to Cyber Propaganda: Pawn Storm's Activities over the Past Two Years
This paper takes a look at Pawn Storm's operations within the last two years, and how the group has expanded their activities from espionage to the use of cyber propaganda tactics.
April 25th, 2017 2 minTrendAI™ Threat Research
Read article -
ResearchOperation Pawn Storm: Fast Facts and the Latest Developments
Operation Pawn Storm is an active economic and political cyber-espionage operation that has targeted high-profile entities from government institutions to media personalities. Here are its latest developments.
January 16th, 2016 3 minTrendAI™ Threat Research
Read article -
ResearchFollow the Data: Dissecting Data Breaches and Debunking the Myths
A decade's worth of breaches has led to this. Forward-looking threat researcher Numaan Huq analyzes what has happened to the stolen data affecting major US industries. We map out the probabilities; see where the information goes and how much it's sold.
September 22nd, 2015 9 minTrendAI™ Threat Research
Read article