Join us at Gartner SEC London and discover how LevelBlue can help you secure what’s next. Learn More

SpiderLabs Blog

Explore the latest threats, critical vulnerability disclosures, cutting-edge research, and intelligence from our elite global threat experts.

circleradial-blogs

Expanding the Attack Surface: Analyzing Nightmare-Eclipse's Latest PoCs

September 09, 2026 | Serhii Melnyk and Timmy Lister

Hunter

Stay Informed

Sign up to receive the latest security news and trends straight to your inbox from LevelBlue.

Still Circling: Inside the Operator Behind Blind Eagle's GitHub Loader

August 28, 2026 | Serhii Melnyk

This is a collaborative follow-up to our original post, developed jointly with ...

Cloud Sync Root RegistrationShieldBreak: Hunting Windows Defender Remediation Abuse and Cloud Files Hijacking

August 19, 2026 | Serhii Melnyk and Timmy Lister

Following GreenPlasma, YellowKey and MiniPlasma, RoguePlanet and GreatXML, and ...

The Infrastructure Relay: Inside Multi-Stage Phishing Redirection Chains

August 12, 2026 | Karla Agregado

To stay ahead of evolving threats, LevelBlue utilizes a machine-learning-based ...

Beyond ‘Fake Updates’: From Application Store-Themed Phishing to Large-Scale Distribution of ScreenConnect

August 07, 2026 | King Orande and Cris Tomboc

The LevelBlue OpsCTI Team recently identified a large-scale phishing campaign ...

Review of the July 2026 Cyberattacks Against U.S. Water and Wastewater Systems

August 04, 2026 | Nikita Kazymirskyi

In light of the water-sector activity described below, we've increased ...

LevelBlue TTP Briefing Q2 2026: Stolen Identities Outpace Defenses

July 23, 2026

Explore the latest tactics, techniques, and procedures (TTPs) our incident ...

LegacyHive: Nightmare-Eclipse’s Latest Zero-Day Drop with a Stripped PoC

July 20, 2026 | Pauline Bolaños

Vexed researcher Nightmare-Eclipse (aka Chaotic Eclipse, Dead Eclipse, and ...

Still Circling: Blind Eagle's Toolkit Keeps Evolving

July 17, 2026 | Serhii Melnyk

In June 2025, LevelBlue SpiderLabs published Tracing Blind Eagle to Proton66, ...

ClickFix on macOS: Blockchain-Powered Infostealer Hidden Inside Compromised Websites

July 16, 2026 | Rodel Mendrez

You're browsing a legitimate small business website. Before the page loads, a ...

Hiding in the Chain: Multi-Stage LNK Attack Leveraging TON Blockchain to Deliver Node.JS Backdoor

July 09, 2026 | Nathaniel Morales

The LevelBlue Managed Threat Research team investigated a security alert in a ...

From Phishing to Persistence: A CrySome RAT Infection Chain Analysis

July 06, 2026 | Sean Shirley and Kyle Sopt

During a recent security alert, the LevelBlue MDR SOC successfully triaged and ...

AsyncRAT and Remcos Delivered in Multi-Stage Phishing Campaign

July 02, 2026 | Fernando Martinez Sidera

Over the past two weeks, LevelBlue SpiderLabs has been tracking an active ...

An Analysis of ValleyRAT Infection Campaigns from Fake Installers, Japanese Malicious Emails

June 30, 2026 | Hajime Takai

Key points LevelBlue has identified two distinct attack vectors associated with ...

RoguePlanet and GreatXML: Detecting Local Privilege Escalation and BitLocker Security Boundary Abuse

June 17, 2026 | Serhii Melnyk

Following our previous research, LevelBlue SpiderLabs continued monitoring a ...

The Device Code Phishing Tsunami: What We’re Seeing in the Wild

June 09, 2026 | John Kevin Adriano

With contributions from Cris Tomboc.

macOS ClickFix Social Engineering Campaigns

June 04, 2026 | Maor Gabay

Overview The "ClickFix" threat landscape has undergone a significant ...

ClickFix Is Now Hiring: From Job Platform Impersonation to Python-Based RAT Delivery

June 04, 2026 | King Orande and Cris Tomboc

The LevelBlue OpsIntel CTI team examined the latest version of the ClickFix ...

The Demon Arrives Later: A Havoc Stager Hides Behind Microsoft Defender DLP

June 03, 2026 | Jose Martin

In Brazil, Nota Fiscal eletrônica (NF-e) is the everyday name for an official ...

Sapphire Sleet Targets macOS in Multi-Stage Intrusion Campaign

May 28, 2026 | Maor Gabay

We recently observed a multi-stage macOS intrusion campaign conducted by the ...

From WinRE to SYSTEM: Hunting CVE-2026-45585 Exploitation and the MiniPlasma Attack Chain

May 22, 2026 | Serhii Melnyk

Since April 2026, LevelBlue SpiderLabs’ Cyber Threat Intelligence team has ...

YellowKey and GreenPlasma: Two New Windows Zero-Days Unveiled

May 19, 2026 | James Ballantyne

Two novel Windows zero-day vulnerabilities dubbed YellowKey, which bypasses ...

A Closer Look at The Gentlemen’s Alleged Leak

May 18, 2026 | Arthur Erzberger

Executive Summary

Threat Analysis: Backdoored Electron Apps Evading Defenses

May 08, 2026 | Michael Morose

This Threat Analysis report is part of the “Purple Team Series” in which the ...

Unmasking a Multi-Stage Loader: AutoIt Abuse Leading to Vidar Stealer Command-and-Control Communication

May 07, 2026 | Mahadev Joshi

LevelBlue’s Security Services issues Threat Analysis reports to inform on ...

LevelBlue TTP Briefing Q1 2026: Trust Abuse Exposes Weaknesses

May 05, 2026

Explore the latest trends, techniques, and procedures (TTPs) our incident ...

Inside Vect Ransomware-as-a-Service

April 30, 2026 | SpiderLabs Researcher

Vect ransomware, a new group that emerged in January 2026, has recently begun ...

Crypto Drainers as a Converging Threat: Insights into Emerging Hybrid Attack Ecosystems

April 23, 2026 | Serhii Melnyk, King Orande, Cris Tomboc, Sean Shirley

LevelBlue SpiderLabs’ Cyber Threat Intelligence Team continues to observe a ...