Archive for SOCRadar

SOCRadar Uncovers AI-Powered PhaaS “AnonyMousKIT” Stealing Apple IDs/Passwords

Posted in Commentary with tags on August 24, 2026 by itnerd

Today, SOCRadar’s Threat Research Unit (STRU) published new research about AnonyMousKIT, an AI-powered Phishing-as-a-Service (PhaaS) platform built to steal the Apple ID and passcode needed to unlock a stolen iPhone. A basic coding mistake in its backend exposed the whole operation — developer, resellers, and operators.

Apple’s Activation Lock turns a stolen iPhone into scrap unless someone gets the owner’s Apple ID and passcode. AnonyMousKIT turns that into a subscription service: load a stolen device’s details into the panel once, and it works through email, SMS, WhatsApp, a recorded call, and an AI phone call on its own until the owner responds. Two exposed relative file paths handed STRU months of production logs, tracing this one storefront back to a shared codebase running on 506 domains under 168 brand names.

What STRU found:

  • Device-led lures: messages cite the phone’s real Apple model number, like iPhone16,2, and its live Find My location pulled straight off the stolen device.
  • An AI voice agent posing as Apple Support: a rented commercial voice AI, scripted as “Alice from Apple Support” in English, Spanish, and Portuguese, talks victims into reading out their passcode live, then walks them to the phishing link.
  • A reseller network behind the rebrands: the shared codebase ties 506 domains and 168 storefronts together; scanning that family found 30 still-active backends across 42 domains.

The color detail:

  • Ten cents a call: 200 AI voice calls, 90% to Brazil, cost the operator $19.24 total — cheap enough that targets don’t need to be chosen carefully.
  • The bait doesn’t even work: the panel’s four “free” jailbreak tools only run on chips up to the iPhone A11, while 92.7% of targeted devices are A12 or newer.
  • One buyer, three storefronts: an identical setup-check email (26 log lines, every time) shows up in 12 of 24 exposed backends, and three storefronts launched in the same second on April 10, 2026, sharing the same Gmail relay accounts.

The defender takeaway:

  • The tell is the ask: no legitimate Apple or IT support team will ever call and request a passcode or 2FA code out loud.
  • Not just a consumer problem: AnonyMousKIT alone emailed lures to 27 South African government addresses and a local university — a compromised personal Apple ID can still expose corporate Keychain credentials.
  • Still running as of our last collection date, and SOCRadar continues tracking the wider family.

To view the full research, IOCs, and ATT&CK mapping, see the just-published report  Exposing AnonyMousKIT: AI-Powered PhaaS Supply Chain

SOCRadar Now Offered Through GuidePoint Security 

Posted in Commentary with tags on August 24, 2026 by itnerd

SOCRadar today announced a new reseller collaboration with GuidePoint Security, the leading cybersecurity solution provider that helps organizations make better decisions that minimize risk. The collaboration is designed to expand customer access to SOCRadar’s award-winning Extended Threat Intelligence platform through GuidePoint’s extensive network of enterprise and public sector customers. 

As organizations face increasingly sophisticated cyber threats, SOCRadar’s comprehensive threat intelligence capabilities and intelligence-driven approach, combined with GuidePoint’s proven advisory and integration expertise, enable customers to proactively identify, assess, and mitigate external risks before they impact business operations. 

SOCRadar is the pioneer of Agentic Threat Intelligence serving organizations across more than 150 countries. The company’s award-winning Agentic Threat Intelligence Platform delivers an industry-first early warning cyber risk detection and mitigation system to proactively identify and reduce external cyber threats before attackers can exploit them. The platform uniquely combines AI agents with one of the industry’s most comprehensive cyber intelligence ecosystems to continuously discover, investigate, and prioritize risks across the internet, deep web, dark web, social media platforms, third-party ecosystems, and exposed digital assets. Integrating Brand Protection and Attack Surface Management (ASM) through its XTI platform, SOCRadar helps customers defend against external threats like phishing, brand impersonation and ransomware, as well as account takeover, exposed credentials, supply chain risks, and emerging attacker activity. 

FTP Banners: The New Dead Drop Resolver Delivering Novel RATs

Posted in Commentary with tags on August 21, 2026 by itnerd

The SOCRadar Threat Research Unit has unveiled a delivery technique that they haven’t seen documented before: threat actors are hiding staging commands inside FTP server banners, the greeting text a server sends when you connect to port 21.

Key details

  • Threat actors are hiding malware staging commands inside FTP server banners – the greeting text a server returns on port 21. A shortcut file connects, reads the banner, executes what’s in it. Nothing malicious in the file itself.
  • This is a dead drop resolver on a protocol nobody inspects for content. The technique has not been documented before.
  • Live since early July 2026 and still operational.

Full research can be read here: https://socradar.io/blog/ftp-banners-new-dead-drop-resolver-rats/ 

SOCRadar Goes Inside the LiteLLM Supply Chain Attack That Exposed 2,500+ Companies 

Posted in Commentary with tags on August 13, 2026 by itnerd

Today, the SOCRadar research team published a new research report on the LiteLLM supply chain attack that exposed 2,500 companies. It includes full attack chain, TeamPCP profile, IOC table, five detection checks, rotation guidance andFAQ.  

What’s different from general coverage:

  • They worked from the ranked company list. SOCRadar analyzed the 2,188 organization records at row level and the timeline changes.
  • The 40-minute PyPI window was the end of a 5-day collection run, not the start. 95% of affected organizations were already exposed before March 24, and the earliest record lands 18 minutes after the poisoned Trivy build published on March 19.

SOCRadar Findings/Differentiators:

  • Six CI/CD platforms, GitHub Actions and GitLab CI near-equal, self-hosted GitLab included
  • Footprint skews European and Latin American, Germany then Brazil then France, 137 TLDs, eight .gov
  • Credentials reach npm and Docker publishing tokens, Stripe, Twilio, SendGrid, not just AI keys
  • Our Dark Web monitoring caught the loot brokered on Telegram at 150+ GB, tied to Vect ransomware

SOCRadar’s report is here: LiteLLM Supply Chain Attack: Inside the AI Breach That Exposed 2,500+ Companies 

SOCRadar Named No. 542 on the 2026 Inc. 5000 List, the Most Prestigious Ranking of America’s Fastest-Growing Private Companies 

Posted in Commentary with tags on August 11, 2026 by itnerd

SOCRadar, a global leader in extended threat intelligence and cybersecurity, today announced it has been ranked No. 542 on the 2026 Inc. 5000 list, the annual list of the fastest-growing private companies in America. The list is the most prestigious ranking of the nation’s most successful independent and entrepreneurial businesses, recognizing companies that have achieved remarkable growth while driving innovation, creating jobs, and shaping the future of the economy. Past honorees include companies such as Microsoft, Meta, Chobani, Oracle, and Patagonia. 

This year’s Inc. 5000 recognizes a new class of companies redefining what growth looks like. From AI and advanced manufacturing to healthcare, consumer products, and professional services, these businesses are expanding their impact, creating jobs and proving that entrepreneurial ambition continues to fuel the U.S. economy. Among the 5,000 companies on the list, the median three-year revenue growth rate was 130%, and those companies have collectively added more than 627,208 jobs to the U.S. economy over the past three years. 

For the full Inc. 5000 list, honoree company profiles, and a searchable database by industry and location, please visit: www.inc.com/inc5000

Inc. will celebrate the honorees at the 2026 Inc. 5000 Conference & Gala, taking place October 14–16 in Dallas, Texas and the top 500 will be listed in the Fall issue of Inc. Magazine. Tickets are on sale now.

Inc. 5000 List Methodology 

Companies on the 2026 Inc. 5000 are ranked according to percentage revenue growth from 2022 to 2025. To qualify, companies must have been founded and generating revenue by March 31, 2022. They must be U.S.-based, privately held, for-profit, and independent—not subsidiaries or divisions of other companies—as of December 31, 2025. (Since then, some on the list may have gone public or been acquired.) The minimum revenue required for 2022 is $100,000; the minimum for 2025 is $2 million. As always, Inc. reserves the right to decline applicants for subjective reasons. 

SOCRadar Discovers Infostealer “Kynx” Hunting for Wallets, Games, and AI Tools

Posted in Commentary with tags on August 8, 2026 by itnerd

Following a post by skocherhan on X, the SOCRadar Threat Research Unit (STRU) analyzed Kynx, a Malware-as-a-Service (MaaS) stealer featuring a web panel deeply integrated with the malware’s execution flow. 

Kynx is sold on a tiered subscription model (Free, Plus, Pro, Ultra) through a Turkish gaming forum, and reaches well beyond typical credential theft into crypto wallets, gaming accounts, and AI developer tools like Claude Code, Cursor, GitHub Copilot, and ChatGPT.

What STRU Discovered:

  • AI-assisted development: The developer openly credits Gemini for helping build the malware, including its App-Bound Encryption (ABE) bypass and anti-VM detection.
  • A wide, deliberate target list: 65 cryptocurrency wallet extensions, 16 gaming platforms (Steam, Roblox, Minecraft, Battle.net), 8 AI/developer tools, 9 VPN providers, Discord tokens, and browser-saved credentials and card data.
  • A convincing lure: Kynx masks itself behind a fake system update banner, likely distributed via cracked software or ClickFix-style pages, while it runs anti-sandbox checks before exfiltrating data.
  • Live infrastructure: We traced its C2 to kynxdev[.]xyz, where it uses single-use tokens with a 5-minute validity window and permanent IP bans for invalid requests.


Why it matters: Kynx is a clean example of AI showing up on both sides of the malware economy at once — lowering the bar to build sophisticated stealers, and creating a new class of high-value target in the AI tools developers now trust with code and credentials. IOCs include the C2 domain, SHA256 hashes for the binary, and the staging directory pattern (WinSysHealth-{6 digits}) it drops in %TEMP%.

The full report can be found here

SOCRadar Uncovers Formula 1 Phishing Campaign

Posted in Commentary with tags on August 5, 2026 by itnerd

The SOCRadar Threat Research Unit (STRU) has identified and analyzed a multi-stage phishing campaign that exploits the high-intensity demand for Formula 1 Grand Prix tickets.

The attackers use highly convincing replicas of official ticketing platforms to deceive victims, tricking them into providing payment information and two-factor authentication (2FA) tokens. The operation allows attackers to engage in real-time, operator-controlled social engineering, adapting their tactics to bypass multi-factor authentication (MFA) measures.

What sets this attack apart is the backend: Human operators watch each victim’s session live and push a bank specific verification screen tailored to the card just entered, adapting on the fly to get past MFA.

What SOCRadar Uncovered:

  • Full source code recovery: A hosting misconfiguration on one domain, f1-tickets-sg[.]com, let us pull the kit’s complete backend code rather than just the rendered pages – including the Python cloning script, which has Russian-language comments.
  • A 134-page storefront: The mirror reproduces the legitimate site’s entire information architecture (news, event info, FAQs, even the real 15-page Terms & Conditions PDF) far beyond what a stripped-down lure would need.
  • Bank specific fraud, chosen live: The kit reads the victim’s card BIN, identifies the issuing bank, and serves one of eight pre-branded challenge pages (Emirates NBD, RAKBank, HSBC, and five other mostly UAE institutions) while an operator on a live polling connection decides in real time whether to show an OTP prompt, a balance check, a push approval screen, or a generic fallback.
  • A wider domain network: At least 11 lookalike domains impersonate the Singapore and Spanish Grand Prix under a predictable naming pattern, sharing one backend; several are already flagged as malicious.

Why it matters: It is a manned fraud operation. A person is actively steering each victim toward the exact verification screen their bank would show, which is exactly what static phishing detection misses. It’s also a preview of how ticket phishing for major sporting events keeps evolving around those brief, high urgency sales windows.
IOCs include the domain cluster, the live C2 host at 144.31.3[.]209, and behavioral fingerprints such as the session cookie and the URL flags used to switch challenge screens.

To view the full research, please see SOCRadar Formula 1 Phishing Campaign

SOCRadar Launches Human Identity Exposure for its Extended Threat Intelligence Platform

Posted in Commentary with tags on August 4, 2026 by itnerd

At Black Hat 2026 today, SOCRadar, a global leader in extended threat intelligence and cybersecurity, announced the launch of SOCRadar Human Identity Exposure, a new Identity & Access layer for its Extended Threat Intelligence (XTI) platform.

SOCRadar Human Identity Exposure unifies fragmented identity exposure data, including breach repositories, stealer infections, attacker telemetry, PII, data leaks, and CTI signals into a single, decision-ready record. By providing investigative analysts with a unified operational surface, it accelerates identity risk prioritization and eliminates hours of manual data correlation. Because these records are built entirely from external, attacker-held data ingested directly by the platform, there is zero integration required from HR or IAM systems. 

By tapping into the full depth and breadth of the XTI platform, SOCRadar Human Identity Exposure gives analysts an instant, comprehensive snapshot of an individual’s identity risk. Complete with automated risk scoring, critical exposure insights, and actionable pivot points, this new identity and access layer operationalizes disparate data points for swift investigation and decision-making.

Identity is now the primary path into an enterprise network, not a secondary one. Verizon’s 2025 Data Breach Investigations Report found compromised credentials were the initial vector in 22% of confirmed breaches — the leading vector for the second straight year — and The SANS Institute reported that 90% of organizations experienced at least one identity-related incident in the past year. IBM prices the average compromised-credential breach at $4.67M, with a 246-day mean time to identify and contain.

Human Identity Exposure Card

SOCRadar Human Identity Exposure includes a Human Identity Exposure Card that offers a consolidated investigative profile of an individual’s identity, inferred directly from collected breach incident data, exposed PII records, and infostealer logs, including:

  • Unified Risk Scoring: An in-platform scoring grade metric that quantifies identity risk analysis from across multiple datasets and criteria such as credential breaches and exposures, high sensitivity PII, critical data categories, PII leak records, and whether an individual’s identity shows up across various sources (e.g. leaks, breaches, infostealers).
  • Unified Personal Data Records: This widget allows analysts to see an individual’s level of public exposure by aggregating a variety of unique personal data types from across multiple PII exposure records and making them available in one central location.
  • Breach Timeline: Analysts can easily track every exposure signal, stealer hit, and external attacker telemetry record tied to an identity in a single timeline view. 
  • People Graph: This interactive visual widget provides analysts with the ‘exposure surface’ tied to an individual’s email via a graph that displays the most critical points of exposure along various attack paths.
  • Modeled Attack Scenarios: The platform automatically models potential attack scenarios (e.g. credential stuffing, stealer account takeover, sim swap, business email compromise, etc.) based on exposed data and attack telemetry with the specific attack path, confidence scoring for likelihood of attack, and defensive blocks for attack prevention.
  • Identity Location Map: Analysts can see the estimated geo-location on a map derived from breach metadata.
  • Linked Accounts: The platform surfaces all social media accounts tied to an individual’s identity record.

Additionally, analysts can leverage the platform’s Compromised Data Exposure Report, a one-click reporting feature that instantly generates identity leak incident reports for rapid sharing with stakeholders and more precise incident tracking. These reports illuminate exposed PII, password hashes, and login credentials, while providing automated risk scoring, assessments, and step-by-step remediation guidance.

WP Botnet Master – How a Security Researcher’s Paid Course Built a 2.1-Million-Credential WordPress Botnet

Posted in Commentary with tags on July 24, 2026 by itnerd

Today, SOCRadar published new research WP Botnet Master: How a Security Researcher’s Paid Course Built a 2.1-Million-Credential WordPress Botnet.

On 13 July 2026, SOCRadar Researchers recovered the complete toolkit behind a distributed WordPress brute-force operation the operator called “WP Botnet Master.” We expected to be looking at the work of a single skilled attacker. What we found was a graduation project.

The server they pulled apart did not belong to a lone hacker. It belonged to a paying student of a structured, commercial “training” program run by a WordPress security researcher who sells cybercrime as a course – complete with a curriculum, a lab blueprint, a community, and an AI-assisted workflow that lets students build and run credential-harvesting botnets with almost no skill of their own.

One student, acting alone, harvested 2,118,764 WordPress administrator credentials from 606,591 domains across 100 countries. There are roughly 295 more people in the community that trained him. The botnet is a symptom. The academy is the disease.

Key Points:

  • threat actor operating as “KING” (@Real_King_Engine) sells a paid course, the ISAL Framework, that teaches students to stand up attack infrastructure, generate exploits with commercial AI assistants, deploy web shells, and run a credential-harvesting botnet at internet scale.
  • KING is a WPScan-credited vulnerability researcher with three published advisories and a Wordfence Intelligence researcher account carrying an approved bounty payout. These are real, verifiable identities – used as legal cover (“educational and defensive research only”) and as a credibility funnel to convert hobbyists into paying students.
  • The recovered botnet server does not belong to KING. It belongs to one of his students, a self-published developer who identifies publicly as Saeful Rochim (“dalung,” github.com/dalungid), tied to the recovered toolkit by a confirmed code-authorship fingerprint match.
  • The course teaches push-button, AI-assisted exploitation. In a paying student’s own words: “The system did everything automatically – I only drank soda.” Both Anthropic Claude and Google Gemini appear in the toolchain.
  • The output SOCRadar recovered: 272 million sites scanned, 2,118,764 administrator credentials harvested across 606,591 domains in 100 countries, and 137 active web shells across 24 countries.
  • As of the time of writing, the master command-and-control server (217.216.72.31) remained online and continued ingesting fresh target lists.

This is scalable, repeatable, and deliberately deniable cybercrime. Each of the ~295 community members is a candidate to reproduce the full operation – and an English-language edition of the course is already in development.

To view the full report, please see WP Botnet Master: How a Security Researcher’s Paid Course Built a 2.1-Million-Credential WordPress Botnet 

SOCRadar launches wp2shell exposure checker 

Posted in Commentary with tags on July 22, 2026 by itnerd

SOCRadar has launched a free wp2shell checker to help organizations quickly determine whether their WordPress websites may be exposed to CVE-2026-63030, a critical remote code execution vulnerability affecting recent WordPress versions.

The tool allows users to enter a domain and assess potential exposure without manually reviewing WordPress versions or configurations—particularly useful for organizations managing large numbers of public-facing, subsidiary, staging or forgotten websites.

The checker is designed to help security teams:

  • Quickly identify potentially exposed WordPress assets
  • Verify whether automatic WordPress updates were successfully applied
  • Prioritize vulnerable or overlooked sites for remediation
  • Reduce the risk posed by unknown WordPress installations across the external attack surface

SOCRadar has also published a supporting technical analysis explaining how the wp2shell vulnerability chain can lead to unauthenticated remote code execution, which WordPress versions are affected and what defenders should look for in their logs.

You can access the checker and analysis here:
https://socradar.io/blog/wp2shell-wordpress-rce-cve-2026-63030/