The eSentire Blog

Apr 20, 2026

Six Days Ahead: How eSentire Detected NetScaler Exploitation Before the Industry Caught Up

On April 2, 2026, eSentire’s Threat Response Unit (TRU) identified active exploitation attempts targeting Citrix…

READ NOW →

Posts from TRU Intelligence Center

TRU Positive/Bulletin

35 M

STX RAT: A new RAT in 2026 with Infostealer Capabilities

What did we find?In late February 2026, eSentire's Threat Response Unit (TRU) observed an attempted delivery of a…

READ NOW →

Threat Intelligence

8 M

Examining the Blast Radius from the Axios npm Supply Chain Compromise

What Happened?eSentire's Security Advisory on this incident can be found here:…

READ NOW →

TRU Positive/Bulletin

9 M

Tycoon 2FA Infrastructure Update: Threat Actors Adapt Following Global Coalition Takedown

What did we find?Following the organized global coalition takedown of Tycoon 2FA phishing infrastructure led by…

READ NOW →

TRU Positive/Bulletin

16 M

EtherRAT & SYS_INFO Module: C2 on Ethereum (EtherHiding), Target Selection, CDN-Like Beacons

What did we find?In March 2026, eSentire's Threat Response Unit (TRU) detected EtherRAT in a customer's…

READ NOW →
6 M

How eSentire Runs Expert-level Threat Investigations at Scale with Claude

Originally posted by https://claude.com/customers/esentire. 99.96% ransomware containment…

READ NOW →

Managed Detection and Response

4 M

eSentire Wins Multiple Leader Badges in the G2 Spring 2026 Grid® Reports

We are thrilled to share that eSentire has been recognized with multiple badges by G2 as part of their…

READ NOW →

TRU Positive/Bulletin

9 M

MuddyWater APT + Tsundere Botnet: EtherHiding the C2

What did we find?In March 2026, eSentire's Threat Response Unit (TRU) investigated an open-directory web server…

READ NOW →

TRU Positive/Bulletin

24 M

North Korean APT Malware Analysis: DEV#POPPER RAT and OmniStealer (Everyday I'm Shufflin')

What did we find?In February 2026, eSentire's Threat Response Unit (TRU) detected DEV#POPPER, a sophisticated…

READ NOW →

Threat Response Unit

3 M

Microsoft Announces Disruption of Tycoon 2FA in Coordination with Industry Partners

March 4, 2026 – Today, Microsoft announced they took action to disrupt and coordinate seizure of infrastructure…

READ NOW →
Page
of 35