LevelBlue TTP Briefing Q2 2026: Stolen Identities Outpace Defenses
July 23, 2026
Stay Informed
Sign up to receive the latest security news and trends straight to your inbox from LevelBlue.
LegacyHive: Nightmare-Eclipse’s Latest Zero-Day Drop with a Stripped PoC
July 20, 2026 | Pauline Bolaños
Vexed researcher Nightmare-Eclipse (aka Chaotic Eclipse, Dead Eclipse, and ...
Still Circling: Blind Eagle's Toolkit Keeps Evolving
July 17, 2026 | Serhii Melnyk
In June 2025, LevelBlue SpiderLabs published Tracing Blind Eagle to Proton66, ...
ClickFix on macOS: Blockchain-Powered Infostealer Hidden Inside Compromised Websites
July 16, 2026 | Rodel Mendrez
You're browsing a legitimate small business website. Before the page loads, a ...
Hiding in the Chain: Multi-Stage LNK Attack Leveraging TON Blockchain to Deliver Node.JS Backdoor
July 09, 2026 | Nathaniel Morales
The LevelBlue Managed Threat Research team investigated a security alert in a ...
From Phishing to Persistence: A CrySome RAT Infection Chain Analysis
July 06, 2026 | Sean Shirley and Kyle Sopt
During a recent security alert, the LevelBlue MDR SOC successfully triaged and ...
AsyncRAT and Remcos Delivered in Multi-Stage Phishing Campaign
July 02, 2026 | Fernando Martinez Sidera
Over the past two weeks, LevelBlue SpiderLabs has been tracking an active ...
An Analysis of ValleyRAT Infection Campaigns from Fake Installers, Japanese Malicious Emails
June 30, 2026 | Hajime Takai
Key points LevelBlue has identified two distinct attack vectors associated with ...
RoguePlanet and GreatXML: Detecting Local Privilege Escalation and BitLocker Security Boundary Abuse
June 17, 2026 | Serhii Melnyk
Following our previous research, LevelBlue SpiderLabs continued monitoring a ...
The Device Code Phishing Tsunami: What We’re Seeing in the Wild
June 09, 2026 | John Kevin Adriano
With contributions from Cris Tomboc.
macOS ClickFix Social Engineering Campaigns
June 04, 2026 | Maor Gabay
Overview The "ClickFix" threat landscape has undergone a significant ...
ClickFix Is Now Hiring: From Job Platform Impersonation to Python-Based RAT Delivery
June 04, 2026 | King Orande and Cris Tomboc
The LevelBlue OpsIntel CTI team examined the latest version of the ClickFix ...
The Demon Arrives Later: A Havoc Stager Hides Behind Microsoft Defender DLP
June 03, 2026 | Jose Martin
In Brazil, Nota Fiscal eletrônica (NF-e) is the everyday name for an official ...
Sapphire Sleet Targets macOS in Multi-Stage Intrusion Campaign
May 28, 2026 | Maor Gabay
We recently observed a multi-stage macOS intrusion campaign conducted by the ...
From WinRE to SYSTEM: Hunting CVE-2026-45585 Exploitation and the MiniPlasma Attack Chain
May 22, 2026 | Serhii Melnyk
Since April 2026, LevelBlue SpiderLabs’ Cyber Threat Intelligence team has ...
YellowKey and GreenPlasma: Two New Windows Zero-Days Unveiled
May 19, 2026 | James Ballantyne
Two novel Windows zero-day vulnerabilities dubbed YellowKey, which bypasses ...
A Closer Look at The Gentlemen’s Alleged Leak
May 18, 2026 | Arthur Erzberger
Executive Summary The Gentlemen is an active ransomware and extortion operation ...
Threat Analysis: Backdoored Electron Apps Evading Defenses
May 08, 2026 | Michael Morose
This Threat Analysis report is part of the “Purple Team Series” in which the ...
Unmasking a Multi-Stage Loader: AutoIt Abuse Leading to Vidar Stealer Command-and-Control Communication
May 07, 2026 | Mahadev Joshi
LevelBlue’s Security Services issues Threat Analysis reports to inform on ...
LevelBlue TTP Briefing Q1 2026: Trust Abuse Exposes Weaknesses
May 05, 2026
Explore the latest trends, techniques, and procedures (TTPs) our incident ...
Inside Vect Ransomware-as-a-Service
April 30, 2026 | SpiderLabs Researcher
Vect ransomware, a new group that emerged in January 2026, has recently begun ...
Crypto Drainers as a Converging Threat: Insights into Emerging Hybrid Attack Ecosystems
April 23, 2026 | Serhii Melnyk, King Orande, Cris Tomboc, Sean Shirley
LevelBlue SpiderLabs’ Cyber Threat Intelligence Team continues to observe a ...
A Closer Look at the Novel and Stealthy KarstoRAT Malware
April 21, 2026 | Chen Aviani
For almost three decades now, threat actors have used remote access trojans ...
Go With the Flow: Abusing OAuth Device Code Flow
April 20, 2026 | Jakub Wiewiorski
In early 2026, phishing attacks are still among the top contributors to the ...
RedSun and the Expanding Risk Window: Why Microsoft Defender Patching Can’t Wait
April 17, 2026
A newly disclosed zero-day vulnerability, dubbed RedSun, is raising fresh ...
Why Attackers Are Bypassing Phishing Emails and Targeting Identity Instead
April 13, 2026 | Jamie Mamroe
One of the fastest growing initial access techniques we are seeing right now is ...
Trojanized CPUID HWMonitor Installer Delivers Fileless .NET Payload via Obfuscated IPv6 Scriptlet
April 10, 2026 | Sean Shirley
Overview Recent reporting has identified a trojanized version of the CPUID ...
Axios NPM Package Supply Chain Compromise Leads to RAT Deployment
April 09, 2026 | Mahadev Joshi and Sho Kishimoto
KEY OBSERVATIONS Malicious Package Versions Identified: Malicious versions of ...