Release the RAVEN: Destruction and Discipline
August 18, 2026 | Karl Biron
Stay Informed
Sign up to receive the latest security news and trends straight to your inbox from LevelBlue.
Release the RAVEN: Data Heist and Persistence
August 14, 2026 | Karl Biron
We have access through port 9200. We have code execution through port 5601. ...
Release the RAVEN: Kibana Under Siege
August 13, 2026 | Karl Biron
In Parts 1 and 2, every command targeted port 9200. Every exploit, every ...
CNCMachineRMS: The Undocumented RAT At the End of a BabaDeda Chain
August 10, 2026 | Rodel Mendrez
This post is the result of an investigation into a case we worked on, in which ...
Release the RAVEN: Exploiting the Cracks
August 06, 2026 | Karl Biron
In Part 1, we went from a single open port to a complete map of the target. ...
Release the RAVEN: First Contact
August 05, 2026 | Karl Biron
You are mid-engagement. Nmap finishes its sweep and port 9200 lights up on a ...
Release the RAVEN: An Offensive Reconnaissance and Attack Tool on Vulnerable Elasticsearch Nodes
July 29, 2026 | Karl Biron
You have almost certainly interacted with Elasticsearch today. The search bar ...
Still Circling: Blind Eagle's Toolkit Keeps Evolving
July 17, 2026 | Serhii Melnyk
In June 2025, LevelBlue SpiderLabs published Tracing Blind Eagle to Proton66, ...
ClickFix on macOS: Blockchain-Powered Infostealer Hidden Inside Compromised Websites
July 16, 2026 | Rodel Mendrez
You're browsing a legitimate small business website. Before the page loads, a ...
Hiding in the Chain: Multi-Stage LNK Attack Leveraging TON Blockchain to Deliver Node.JS Backdoor
July 09, 2026 | Nathaniel Morales
The LevelBlue Managed Threat Research team investigated a security alert in a ...
From Phishing to Persistence: A CrySome RAT Infection Chain Analysis
July 06, 2026 | Sean Shirley and Kyle Sopt
During a recent security alert, the LevelBlue MDR SOC successfully triaged and ...
AsyncRAT and Remcos Delivered in Multi-Stage Phishing Campaign
July 02, 2026 | Fernando Martinez Sidera
Over the past two weeks, LevelBlue SpiderLabs has been tracking an active ...
An Analysis of ValleyRAT Infection Campaigns from Fake Installers, Japanese Malicious Emails
June 30, 2026 | Hajime Takai
Key points LevelBlue has identified two distinct attack vectors associated with ...
Novel Java-Based QuimaRAT Targets Windows, macOS, and Linux
June 25, 2026 | Chen Aviani and Nikita Kazymirskyi
Remote access trojans (RATs) are legacy threats that continue to evolve ...
LokiBot After a Decade: An Analysis of a Recent LokiBot Campaign
June 24, 2026 | Dawid Nesterowicz
In Norse mythology, Loki, the god of mischief, has powerful and deceptive ...
Operation FlutterBridge: The FlutterShell macOS Backdoor
June 18, 2026 | Maor Gabay
Identified through macOS endpoint monitoring, the CL-CRI-1089 cluster, ...
Sapphire Sleet Targets macOS in Multi-Stage Intrusion Campaign
May 28, 2026 | Maor Gabay
We recently observed a multi-stage macOS intrusion campaign conducted by the ...
From WinRE to SYSTEM: Hunting CVE-2026-45585 Exploitation and the MiniPlasma Attack Chain
May 22, 2026 | Serhii Melnyk
Since April 2026, LevelBlue SpiderLabs’ Cyber Threat Intelligence team has ...
Threat Analysis: Backdoored Electron Apps Evading Defenses
May 08, 2026 | Michael Morose
This Threat Analysis report is part of the “Purple Team Series” in which the ...
Unmasking a Multi-Stage Loader: AutoIt Abuse Leading to Vidar Stealer Command-and-Control Communication
May 07, 2026 | Mahadev Joshi
LevelBlue’s Security Services issues Threat Analysis reports to inform on ...
Crypto Drainers as a Converging Threat: Insights into Emerging Hybrid Attack Ecosystems
April 23, 2026 | Serhii Melnyk, King Orande, Cris Tomboc, Sean Shirley
LevelBlue SpiderLabs’ Cyber Threat Intelligence Team continues to observe a ...
Go With the Flow: Abusing OAuth Device Code Flow
April 20, 2026 | Jakub Wiewiorski
In early 2026, phishing attacks are still among the top contributors to the ...
Why Attackers Are Bypassing Phishing Emails and Targeting Identity Instead
April 13, 2026 | Jamie Mamroe
One of the fastest growing initial access techniques we are seeing right now is ...
Trojanized CPUID HWMonitor Installer Delivers Fileless .NET Payload via Obfuscated IPv6 Scriptlet
April 10, 2026 | Sean Shirley
Overview Recent reporting has identified a trojanized version of the CPUID ...
Err-Hiding and Seek: How ErrTraffic v3 Leverages EtherHiding in ClickFix Campaign
April 09, 2026 | King Orande and Cris Tomboc
The LevelBlue SpiderLabs team examined the latest version of ErrTraffic, which ...
Azure ServiceBus WebSockets as a C2 Channel
March 24, 2026 | Stuart White
In offensive security, the ability to blend seamlessly with legitimate traffic ...
Tracing a Multi-Vector Malware Campaign: From VBS to Open Infrastructure
March 23, 2026 | Sean Shirley
Recently LevelBlue SpiderLabs initiated an investigation into a multi-stage ...
Fake CAPTCHA Campaign: Inside a Multi-Stage Stealer Assault
March 19, 2026 | Shabtay Barel, Serhii Melnyk, Rodel Mendrez
This report expands LevelBlue’s ongoing investigation into a multi-stage ...