Archive for SOCRadar

Operation Conflict Compass: Konni Targets Ukraine via Malicious LNK Lures

Posted in Commentary with tags on September 22, 2026 by itnerd

Since 2009, the Democratic People’s Republic of Korea (DPRK) has fully integrated cyber operations into its national strategy, leveraging state-nexus threat groups to execute cyberespionage, conduct sabotage and influence operations, and generate revenue for state-sponsored nuclear weapons programs.

Recently, the SOCRadar Threat Research Unit (STRU) uncovered Operation Conflict Compass, a targeted campaign by the DPRK-aligned actor Konni, aimed at gathering intelligence on the ongoing trajectory of the Russian invasion of Ukraine.

Key points: 

  • Spear-phishing ZIPs with LNK files disguised as PDFs, using Russia-Ukraine peace framework. Targeting potentially points to diplomatic entities, think tanks, and NGOs.
  • The chain sets up a scheduled task that runs a PowerShell downloader STRU named VelvetCake every minute. It keeps almost no capability on the host, pulling and running server-side scripts on demand, then wiping its artifacts.
  • A recovered second-stage script performs host enumeration and screen capture, exfiltrated over HTTP POST.
  • The same components were also delivered via a trojanized Zoom installer.
  • Attribution to Konni is moderate confidence: targeting, VelvetCake code characteristics, shared C2 and GitHub staging infrastructure, and operator time zone. 

For full details, the research can be read here: https://socradar.io/blog/operation-conflict-compass-konni-ukraine-lnk-lure/

VectraRAT, An Undocumented Full-Stack MaaS Built From Scratch Documented By SOCRadar

Posted in Commentary with tags on September 14, 2026 by itnerd

SOCRadar’s Threat Research Unit (STRU) has documented VectraRAT, a Malware-as-a-Service platform built entirely from scratch rather than forked from leaked RAT code. Renting from $250 a month, it gives operators hidden-desktop control, keylogging, clipboard hijacking, browser credential theft, and a UAC bypass that elevates with no prompt.

Key Takeaways: 

  • VectraRAT is a previously undocumented, full-stack Malware-as-a-Service platform built from scratch. It is not a reskin of AsyncRAT, XWorm, or QuasarRAT.
  • It pairs a Go control server called VectraHub, with a Vue3 operator panel compiled into the binary, with a native C++ Windows implant. The two speak a proprietary binary TCP protocol using MessagePack over port 3308.
  • The operator “Vectra” is a rebrand of an older identity, “Nyxel”, with a YouTube channel dating back to August 2022. Nearly four years of activity with no public reporting.
  • Capabilities span both the RAT and the stealer space: hidden desktop (HVNC), keylogging, SOCKS5 relay, clipboard hijacking with regex replacement, remote shell, and mass browser credential theft, plus a UAC bypass that elevates without a prompt.
  • Rented from $250 per month and delivered through the Amadey loader and ClickFix pages, with 48% of observed victim entries on corporate Windows editions, including active exfiltration from Windows Server 2025 hosts.

The research can be read here: https://socradar.io/blog/vectrarat-undocumented-stack-maas/

Download the full report (PDF) for the complete technical analysis, including the decompiled protocol internals, panel artifacts, and the full indicator set.

SOCRadar Uncovers AI-Powered PhaaS “AnonyMousKIT” Stealing Apple IDs/Passwords

Posted in Commentary with tags on August 24, 2026 by itnerd

Today, SOCRadar’s Threat Research Unit (STRU) published new research about AnonyMousKIT, an AI-powered Phishing-as-a-Service (PhaaS) platform built to steal the Apple ID and passcode needed to unlock a stolen iPhone. A basic coding mistake in its backend exposed the whole operation — developer, resellers, and operators.

Apple’s Activation Lock turns a stolen iPhone into scrap unless someone gets the owner’s Apple ID and passcode. AnonyMousKIT turns that into a subscription service: load a stolen device’s details into the panel once, and it works through email, SMS, WhatsApp, a recorded call, and an AI phone call on its own until the owner responds. Two exposed relative file paths handed STRU months of production logs, tracing this one storefront back to a shared codebase running on 506 domains under 168 brand names.

What STRU found:

  • Device-led lures: messages cite the phone’s real Apple model number, like iPhone16,2, and its live Find My location pulled straight off the stolen device.
  • An AI voice agent posing as Apple Support: a rented commercial voice AI, scripted as “Alice from Apple Support” in English, Spanish, and Portuguese, talks victims into reading out their passcode live, then walks them to the phishing link.
  • A reseller network behind the rebrands: the shared codebase ties 506 domains and 168 storefronts together; scanning that family found 30 still-active backends across 42 domains.

The color detail:

  • Ten cents a call: 200 AI voice calls, 90% to Brazil, cost the operator $19.24 total — cheap enough that targets don’t need to be chosen carefully.
  • The bait doesn’t even work: the panel’s four “free” jailbreak tools only run on chips up to the iPhone A11, while 92.7% of targeted devices are A12 or newer.
  • One buyer, three storefronts: an identical setup-check email (26 log lines, every time) shows up in 12 of 24 exposed backends, and three storefronts launched in the same second on April 10, 2026, sharing the same Gmail relay accounts.

The defender takeaway:

  • The tell is the ask: no legitimate Apple or IT support team will ever call and request a passcode or 2FA code out loud.
  • Not just a consumer problem: AnonyMousKIT alone emailed lures to 27 South African government addresses and a local university — a compromised personal Apple ID can still expose corporate Keychain credentials.
  • Still running as of our last collection date, and SOCRadar continues tracking the wider family.

To view the full research, IOCs, and ATT&CK mapping, see the just-published report  Exposing AnonyMousKIT: AI-Powered PhaaS Supply Chain

SOCRadar Now Offered Through GuidePoint Security 

Posted in Commentary with tags on August 24, 2026 by itnerd

SOCRadar today announced a new reseller collaboration with GuidePoint Security, the leading cybersecurity solution provider that helps organizations make better decisions that minimize risk. The collaboration is designed to expand customer access to SOCRadar’s award-winning Extended Threat Intelligence platform through GuidePoint’s extensive network of enterprise and public sector customers. 

As organizations face increasingly sophisticated cyber threats, SOCRadar’s comprehensive threat intelligence capabilities and intelligence-driven approach, combined with GuidePoint’s proven advisory and integration expertise, enable customers to proactively identify, assess, and mitigate external risks before they impact business operations. 

SOCRadar is the pioneer of Agentic Threat Intelligence serving organizations across more than 150 countries. The company’s award-winning Agentic Threat Intelligence Platform delivers an industry-first early warning cyber risk detection and mitigation system to proactively identify and reduce external cyber threats before attackers can exploit them. The platform uniquely combines AI agents with one of the industry’s most comprehensive cyber intelligence ecosystems to continuously discover, investigate, and prioritize risks across the internet, deep web, dark web, social media platforms, third-party ecosystems, and exposed digital assets. Integrating Brand Protection and Attack Surface Management (ASM) through its XTI platform, SOCRadar helps customers defend against external threats like phishing, brand impersonation and ransomware, as well as account takeover, exposed credentials, supply chain risks, and emerging attacker activity. 

FTP Banners: The New Dead Drop Resolver Delivering Novel RATs

Posted in Commentary with tags on August 21, 2026 by itnerd

The SOCRadar Threat Research Unit has unveiled a delivery technique that they haven’t seen documented before: threat actors are hiding staging commands inside FTP server banners, the greeting text a server sends when you connect to port 21.

Key details

  • Threat actors are hiding malware staging commands inside FTP server banners – the greeting text a server returns on port 21. A shortcut file connects, reads the banner, executes what’s in it. Nothing malicious in the file itself.
  • This is a dead drop resolver on a protocol nobody inspects for content. The technique has not been documented before.
  • Live since early July 2026 and still operational.

Full research can be read here: https://socradar.io/blog/ftp-banners-new-dead-drop-resolver-rats/ 

SOCRadar Goes Inside the LiteLLM Supply Chain Attack That Exposed 2,500+ Companies 

Posted in Commentary with tags on August 13, 2026 by itnerd

Today, the SOCRadar research team published a new research report on the LiteLLM supply chain attack that exposed 2,500 companies. It includes full attack chain, TeamPCP profile, IOC table, five detection checks, rotation guidance andFAQ.  

What’s different from general coverage:

  • They worked from the ranked company list. SOCRadar analyzed the 2,188 organization records at row level and the timeline changes.
  • The 40-minute PyPI window was the end of a 5-day collection run, not the start. 95% of affected organizations were already exposed before March 24, and the earliest record lands 18 minutes after the poisoned Trivy build published on March 19.

SOCRadar Findings/Differentiators:

  • Six CI/CD platforms, GitHub Actions and GitLab CI near-equal, self-hosted GitLab included
  • Footprint skews European and Latin American, Germany then Brazil then France, 137 TLDs, eight .gov
  • Credentials reach npm and Docker publishing tokens, Stripe, Twilio, SendGrid, not just AI keys
  • Our Dark Web monitoring caught the loot brokered on Telegram at 150+ GB, tied to Vect ransomware

SOCRadar’s report is here: LiteLLM Supply Chain Attack: Inside the AI Breach That Exposed 2,500+ Companies 

SOCRadar Named No. 542 on the 2026 Inc. 5000 List, the Most Prestigious Ranking of America’s Fastest-Growing Private Companies 

Posted in Commentary with tags on August 11, 2026 by itnerd

SOCRadar, a global leader in extended threat intelligence and cybersecurity, today announced it has been ranked No. 542 on the 2026 Inc. 5000 list, the annual list of the fastest-growing private companies in America. The list is the most prestigious ranking of the nation’s most successful independent and entrepreneurial businesses, recognizing companies that have achieved remarkable growth while driving innovation, creating jobs, and shaping the future of the economy. Past honorees include companies such as Microsoft, Meta, Chobani, Oracle, and Patagonia. 

This year’s Inc. 5000 recognizes a new class of companies redefining what growth looks like. From AI and advanced manufacturing to healthcare, consumer products, and professional services, these businesses are expanding their impact, creating jobs and proving that entrepreneurial ambition continues to fuel the U.S. economy. Among the 5,000 companies on the list, the median three-year revenue growth rate was 130%, and those companies have collectively added more than 627,208 jobs to the U.S. economy over the past three years. 

For the full Inc. 5000 list, honoree company profiles, and a searchable database by industry and location, please visit: www.inc.com/inc5000. 

Inc. will celebrate the honorees at the 2026 Inc. 5000 Conference & Gala, taking place October 14–16 in Dallas, Texas and the top 500 will be listed in the Fall issue of Inc. Magazine. Tickets are on sale now.

Inc. 5000 List Methodology 

Companies on the 2026 Inc. 5000 are ranked according to percentage revenue growth from 2022 to 2025. To qualify, companies must have been founded and generating revenue by March 31, 2022. They must be U.S.-based, privately held, for-profit, and independent—not subsidiaries or divisions of other companies—as of December 31, 2025. (Since then, some on the list may have gone public or been acquired.) The minimum revenue required for 2022 is $100,000; the minimum for 2025 is $2 million. As always, Inc. reserves the right to decline applicants for subjective reasons. 

SOCRadar Discovers Infostealer “Kynx” Hunting for Wallets, Games, and AI Tools

Posted in Commentary with tags on August 8, 2026 by itnerd

Following a post by skocherhan on X, the SOCRadar Threat Research Unit (STRU) analyzed Kynx, a Malware-as-a-Service (MaaS) stealer featuring a web panel deeply integrated with the malware’s execution flow. 

Kynx is sold on a tiered subscription model (Free, Plus, Pro, Ultra) through a Turkish gaming forum, and reaches well beyond typical credential theft into crypto wallets, gaming accounts, and AI developer tools like Claude Code, Cursor, GitHub Copilot, and ChatGPT.

What STRU Discovered:

  • AI-assisted development: The developer openly credits Gemini for helping build the malware, including its App-Bound Encryption (ABE) bypass and anti-VM detection.
  • A wide, deliberate target list: 65 cryptocurrency wallet extensions, 16 gaming platforms (Steam, Roblox, Minecraft, Battle.net), 8 AI/developer tools, 9 VPN providers, Discord tokens, and browser-saved credentials and card data.
  • A convincing lure: Kynx masks itself behind a fake system update banner, likely distributed via cracked software or ClickFix-style pages, while it runs anti-sandbox checks before exfiltrating data.
  • Live infrastructure: We traced its C2 to kynxdev[.]xyz, where it uses single-use tokens with a 5-minute validity window and permanent IP bans for invalid requests.


Why it matters: Kynx is a clean example of AI showing up on both sides of the malware economy at once — lowering the bar to build sophisticated stealers, and creating a new class of high-value target in the AI tools developers now trust with code and credentials. IOCs include the C2 domain, SHA256 hashes for the binary, and the staging directory pattern (WinSysHealth-{6 digits}) it drops in %TEMP%.

The full report can be found here. 

SOCRadar Uncovers Formula 1 Phishing Campaign

Posted in Commentary with tags on August 5, 2026 by itnerd

The SOCRadar Threat Research Unit (STRU) has identified and analyzed a multi-stage phishing campaign that exploits the high-intensity demand for Formula 1 Grand Prix tickets.

The attackers use highly convincing replicas of official ticketing platforms to deceive victims, tricking them into providing payment information and two-factor authentication (2FA) tokens. The operation allows attackers to engage in real-time, operator-controlled social engineering, adapting their tactics to bypass multi-factor authentication (MFA) measures.

What sets this attack apart is the backend: Human operators watch each victim’s session live and push a bank specific verification screen tailored to the card just entered, adapting on the fly to get past MFA.

What SOCRadar Uncovered:

  • Full source code recovery: A hosting misconfiguration on one domain, f1-tickets-sg[.]com, let us pull the kit’s complete backend code rather than just the rendered pages – including the Python cloning script, which has Russian-language comments.
  • A 134-page storefront: The mirror reproduces the legitimate site’s entire information architecture (news, event info, FAQs, even the real 15-page Terms & Conditions PDF) far beyond what a stripped-down lure would need.
  • Bank specific fraud, chosen live: The kit reads the victim’s card BIN, identifies the issuing bank, and serves one of eight pre-branded challenge pages (Emirates NBD, RAKBank, HSBC, and five other mostly UAE institutions) while an operator on a live polling connection decides in real time whether to show an OTP prompt, a balance check, a push approval screen, or a generic fallback.
  • A wider domain network: At least 11 lookalike domains impersonate the Singapore and Spanish Grand Prix under a predictable naming pattern, sharing one backend; several are already flagged as malicious.

Why it matters: It is a manned fraud operation. A person is actively steering each victim toward the exact verification screen their bank would show, which is exactly what static phishing detection misses. It’s also a preview of how ticket phishing for major sporting events keeps evolving around those brief, high urgency sales windows.
IOCs include the domain cluster, the live C2 host at 144.31.3[.]209, and behavioral fingerprints such as the session cookie and the URL flags used to switch challenge screens.

To view the full research, please see SOCRadar Formula 1 Phishing Campaign

SOCRadar Launches Human Identity Exposure for its Extended Threat Intelligence Platform

Posted in Commentary with tags on August 4, 2026 by itnerd

At Black Hat 2026 today, SOCRadar, a global leader in extended threat intelligence and cybersecurity, announced the launch of SOCRadar Human Identity Exposure, a new Identity & Access layer for its Extended Threat Intelligence (XTI) platform.

SOCRadar Human Identity Exposure unifies fragmented identity exposure data, including breach repositories, stealer infections, attacker telemetry, PII, data leaks, and CTI signals into a single, decision-ready record. By providing investigative analysts with a unified operational surface, it accelerates identity risk prioritization and eliminates hours of manual data correlation. Because these records are built entirely from external, attacker-held data ingested directly by the platform, there is zero integration required from HR or IAM systems. 

By tapping into the full depth and breadth of the XTI platform, SOCRadar Human Identity Exposure gives analysts an instant, comprehensive snapshot of an individual’s identity risk. Complete with automated risk scoring, critical exposure insights, and actionable pivot points, this new identity and access layer operationalizes disparate data points for swift investigation and decision-making.

Identity is now the primary path into an enterprise network, not a secondary one. Verizon’s 2025 Data Breach Investigations Report found compromised credentials were the initial vector in 22% of confirmed breaches — the leading vector for the second straight year — and The SANS Institute reported that 90% of organizations experienced at least one identity-related incident in the past year. IBM prices the average compromised-credential breach at $4.67M, with a 246-day mean time to identify and contain.

Human Identity Exposure Card

SOCRadar Human Identity Exposure includes a Human Identity Exposure Card that offers a consolidated investigative profile of an individual’s identity, inferred directly from collected breach incident data, exposed PII records, and infostealer logs, including:

  • Unified Risk Scoring: An in-platform scoring grade metric that quantifies identity risk analysis from across multiple datasets and criteria such as credential breaches and exposures, high sensitivity PII, critical data categories, PII leak records, and whether an individual’s identity shows up across various sources (e.g. leaks, breaches, infostealers).
  • Unified Personal Data Records: This widget allows analysts to see an individual’s level of public exposure by aggregating a variety of unique personal data types from across multiple PII exposure records and making them available in one central location.
  • Breach Timeline: Analysts can easily track every exposure signal, stealer hit, and external attacker telemetry record tied to an identity in a single timeline view. 
  • People Graph: This interactive visual widget provides analysts with the ‘exposure surface’ tied to an individual’s email via a graph that displays the most critical points of exposure along various attack paths.
  • Modeled Attack Scenarios: The platform automatically models potential attack scenarios (e.g. credential stuffing, stealer account takeover, sim swap, business email compromise, etc.) based on exposed data and attack telemetry with the specific attack path, confidence scoring for likelihood of attack, and defensive blocks for attack prevention.
  • Identity Location Map: Analysts can see the estimated geo-location on a map derived from breach metadata.
  • Linked Accounts: The platform surfaces all social media accounts tied to an individual’s identity record.

Additionally, analysts can leverage the platform’s Compromised Data Exposure Report, a one-click reporting feature that instantly generates identity leak incident reports for rapid sharing with stakeholders and more precise incident tracking. These reports illuminate exposed PII, password hashes, and login credentials, while providing automated risk scoring, assessments, and step-by-step remediation guidance.