The eSentire Blog

Offensive Security

9 M

AI-Enabled Offense and Defense, One Continuous Flywheel

Key Takeaways …

READ NOW →

TRU Positive/Bulletin

25 M

Nimbus RAT: How Threat Actors Are Abusing Microsoft Teams and Google Drive to Deploy a Java RAT

What did we find?In early April 2026, eSentire's Threat Response Unit (TRU) identified an intrusion targeting a…

READ NOW →

Offensive Security

28 M

Amatera Stealer 4.0.2 Beta: What's New in This Variant

What did we find?In late April 2026, eSentire's Threat Response Unit (TRU) intercepted an attempted delivery of…

READ NOW →

TRU Positive/Bulletin

26 M

Tycoon 2FA Operators Adopt OAuth Device Code Phishing

What did we find?In late April 2026, the eSentire Threat Response Unit (TRU) analyzed a phishing campaign that…

READ NOW →

TRU Positive/Bulletin

34 M

Multi-Stage SEO Poisoning Campaign Targets Chinese-Speaking Developers with Kong RAT

What did we find?In March 2026, eSentire's Threat Response Unit detected a sophisticated multi-stage malware…

READ NOW →

TRU Positive/Bulletin

35 M

STX RAT: A new RAT in 2026 with Infostealer Capabilities

What did we find?In late February 2026, eSentire's Threat Response Unit (TRU) observed an attempted delivery of a…

READ NOW →

Threat Intelligence

8 M

Examining the Blast Radius from the Axios npm Supply Chain Compromise

What Happened?eSentire's Security Advisory on this incident can be found here:…

READ NOW →

TRU Positive/Bulletin

9 M

Tycoon 2FA Infrastructure Update: Threat Actors Adapt Following Global Coalition Takedown

What did we find?Following the organized global coalition takedown of Tycoon 2FA phishing infrastructure led by…

READ NOW →

TRU Positive/Bulletin

16 M

EtherRAT & SYS_INFO Module: C2 on Ethereum (EtherHiding), Target Selection, CDN-Like Beacons

What did we find?In March 2026, eSentire's Threat Response Unit (TRU) detected EtherRAT in a customer's…

READ NOW →

TRU Positive/Bulletin

9 M

MuddyWater APT + Tsundere Botnet: EtherHiding the C2

What did we find?In March 2026, eSentire's Threat Response Unit (TRU) investigated an open-directory web server…

READ NOW →

TRU Positive/Bulletin

24 M

North Korean APT Malware Analysis: DEV#POPPER RAT and OmniStealer (Everyday I'm Shufflin')

What did we find?In February 2026, eSentire's Threat Response Unit (TRU) detected DEV#POPPER, a sophisticated…

READ NOW →

Threat Response Unit

3 M

Microsoft Announces Disruption of Tycoon 2FA in Coordination with Industry Partners

March 4, 2026 – Today, Microsoft announced they took action to disrupt and coordinate seizure of infrastructure…

READ NOW →
Page
of 19