Skip to main content

Research Insights

Stay ahead of threats with expert research, threat intelligence, and actionable cybersecurity insights.

hero image

Featured Articles

Malware Network Research Features Botnets Industrial and Energy Cryptocurrency
Cryptocurrency Miner Uses Hacking Tool Haiduc and App Hider Xhide to Brute Force Machines and Servers

The cryptocurrency-miner, a multi-component threat comprised of different Perl and Bash scripts, miner binaries, the application hider Xhide, and a scanner tool, propagates by scanning vulnerable machines and brute-forcing (primarily default) credentials.

Read Article
Exploits and Zero-Days Research Features Malware Network Information technology Cyber Crime
Malicious Script Plagues Over 2,000 WordPress Accounts, Redirects Visitors to Scam Sites

Over 2,000 WordPress sites were compromised by a malicious script that redirects visitors to scam sites, gains admin access, and installs fake plugins.

Read Article
Phishing and BEC Research Features Cyber Crime General Markets Social Engineering
New Bait Used in Instagram Profile Hacking Scheme

Hackers spread messages supposedly sent from Instagram Help Center claiming that the user's account is at risk of being deleted.

Read Article
AI Deep Dives Machine Learning General Markets Social Engineering
Exploiting AI: How Cybercriminals Misuse and Abuse AI and ML

We discuss the present state of the malicious uses and abuses of AI and ML and the plausible future scenarios in which cybercriminals might abuse these technologies for ill gain.

Read Article
Cyber Crime Deep Dives General Markets Social Engineering Cryptocurrency Cybercriminal Underground
Unmasking Pig-Butchering Scams and Protecting Your Financial Future

This report delves into the nature of pig-butchering scams, how scammers carry out their operations, the new pig-butchering tactics we’ve observed in the wild, and what individuals can do to avoid falling for these fraudulent investments and dealing with massive amounts of debt.

Read Article
Ransomware and extortion Healthcare & Life Sciences Manufacturing Exploits and Zero-Days Cybercriminal Underground
Ransomware Spotlight: INC

INC ransomware has been observed to exploit CVE-2023-3519 and uses HackTool.Win32.ProcTerminator.A for defense evasion and HackTool.PS1.VeeamCreds for credential access in its different attack chains.

Read Article
Ransomware and extortion Research Features Raas Exploits and Zero-Days Cybercriminal Underground Information technology Education Financial services
Ransomware Spotlight: Ransomhub

RansomHub is a young Ransomware-as-a-Service (RaaS) group tracked by Trend Micro as Water Bakunawa. Despite being a young ransomware group first detected in February 2024, RansomHub moves boldly by targeting larger enterprises more likely to pay ransoms.

Read Article
AI Exploits and Zero-Days LLMS General Markets Deep Dives
Unveiling AI Agent Vulnerabilities Part III: Data Exfiltration

In the third part of our series we demonstrate how risk intensifies in multi-modal AI agents, where hidden instructions embedded within innocuous-looking images or documents can trigger sensitive data exfiltration without any user interaction.

Read Article
Cyber Crime Exploits and Zero-Days IoT and Smart Devices Network Deep Dives Software supply chain Botnets Financial services
The Rise of Residential Proxies as a Cybercrime Enabler

This research discusses how residential proxies help cybercriminals bypass antifraud and IT security systems, and how vulnerabilities in the IoT supply chain are exploited where Android-based devices are shipped pre-infected.

Read Article
AI Deep Dives Software supply chain LLMS Information technology
Slopsquatting: When AI Agents Hallucinate Malicious Packages

Our research examines how AI coding assistants can hallucinate plausible but non-existent package names—therefore enabling slopsquatting attacks—while also providing practical defense strategies that organizations can implement to secure their development pipelines

Read Article