The eSentire Blog

TRU Positive/Bulletin

9 M

Tycoon 2FA Infrastructure Update: Threat Actors Adapt Following Global Coalition Takedown

What did we find?Following the organized global coalition takedown of Tycoon 2FA phishing infrastructure led by…

READ NOW →

TRU Positive/Bulletin

16 M

EtherRAT & SYS_INFO Module: C2 on Ethereum (EtherHiding), Target Selection, CDN-Like Beacons

What did we find?In March 2026, eSentire's Threat Response Unit (TRU) detected EtherRAT in a customer's…

READ NOW →

TRU Positive/Bulletin

9 M

MuddyWater APT + Tsundere Botnet: EtherHiding the C2

What did we find?In March 2026, eSentire's Threat Response Unit (TRU) investigated an open-directory web server…

READ NOW →

TRU Positive/Bulletin

24 M

North Korean APT Malware Analysis: DEV#POPPER RAT and OmniStealer (Everyday I'm Shufflin')

What did we find?In February 2026, eSentire's Threat Response Unit (TRU) detected DEV#POPPER, a sophisticated…

READ NOW →

TRU Positive/Bulletin

22 M

Tenant from Hell: Prometei's Unauthorized Stay in Your Windows Server

What did we find? In January 2026, eSentire's Threat Response Unit (TRU) detected a malicious command attempting…

READ NOW →

TRU Positive/Bulletin

19 M

EVALUSION Campaign Delivers Amatera Stealer and NetSupport RAT

Adversaries don’t work 9-5 and neither do we. At eSentire, our 24/7 SOCs are staffed with Elite Threat…

READ NOW →

TRU Positive/Bulletin

10 M

Unpacking NetSupport RAT Loaders Delivered via ClickFix

Adversaries don’t work 9-5 and neither do we. At eSentire, our 24/7 SOCs are staffed with Elite Threat…

READ NOW →

TRU Positive/Bulletin

11 M

New Rust Malware "ChaosBot" Uses Discord for Command and Control

Adversaries don’t work 9-5 and neither do we. At eSentire, our 24/7 SOCs are staffed with Elite Threat…

READ NOW →

TRU Positive/Bulletin

11 M

Eye of the Storm: Analyzing DarkCloud's Latest Capabilities

Adversaries don’t work 9-5 and neither do we. At eSentire, our 24/7 SOCs are staffed with Elite Threat…

READ NOW →

TRU Positive/Bulletin

16 M

New Botnet Emerges from the Shadows: NightshadeC2

Adversaries don’t work 9-5 and neither do we. At eSentire, our 24/7 SOCs are staffed with Elite Threat…

READ NOW →

TRU Positive/Bulletin

10 M

Threat Actors Deploy Sinobi Ransomware via Compromised SonicWall SSL VPN Credentials

Adversaries don’t work 9-5 and neither do we. At eSentire, our 24/7 SOCs are staffed with Elite Threat…

READ NOW →

TRU Positive/Bulletin

19 M

Unmasking Interlock Group's Evolving Malware Arsenal

Adversaries don’t work 9-5 and neither do we. At eSentire, our 24/7 SOCs are staffed with Elite Threat…

READ NOW →
Page
of 15