Please confirm you are human
This browser or connection looks automated. Press and continuously hold the control for 3 seconds to enable Google-hosted web results and, when separately allowed, AI-assisted answers.
A successful check enables 100 search requests. Interactive access does not authorize scraping, systematic collection, or reuse of search output.
News
Dolphin X Stealer Uses AI to Rank High-Value Victims
2+ day, 16+ hour ago (218+ words) SOC Prime SOC Prime Bias: High Dolphin X Stealer Targets 300+ Apps and Profiles Users with AI Dolphin X is a newly identified Windows-based stealer and remote access trojan capable of targeting more than 300 applications, including browsers, cryptocurrency wallets, and DevOps…...
CVE-2026-0257 Exploitation Leads to Qilin Ransomware
2+ day, 22+ hour ago (270+ words) SOC Prime Bias: Critical Threat actors are exploiting a critical authentication bypass flaw in Palo Alto Networks GlobalProtect to obtain initial access. After entering the environment, the attackers deploy Qilin ransomware, often after stealing credentials and exfiltrating data. The resulting…...
Kimsuky Targets South Korean Groupware with Gomir
2+ day, 22+ hour ago (191+ words) SOC Prime Bias: Critical ENKI WhiteHat analyzed the campaign across 2025 and early 2026 and identified several malware strains developed in Go. The investigation showed how Kimsuky combined remote code execution on mail servers with social engineering to secure initial access. Analysts…...
Cruciferra Crypter Service Hides RATs and Infostealers
2+ day, 22+ hour ago (193+ words) SOC Prime SOC Prime Bias: High Cruciferra: Analyzing a Sophisticated Crypter Service Cruciferra is a sophisticated crypter service used by multiple unrelated cybercriminal groups to obfuscate a broad range of malware, including RATs and infostealers. It applies advanced defense-evasion techniques…...
CVE-2026-56164 & CVE-2026-56155 Zero-Days
1+ week, 2+ day ago (412+ words) Add to my AI research Exclusive to SOC Prime users For CVE-2026-56164 analysis, the key point is that Microsoft and outside reporting both describe the flaw as already exploited in real attacks against on-prem SharePoint. It is an elevation-of-privilege issue,…...
Turla Uses STOCKSTAY and Kazuar Backdoors for Espionage
1+ week, 4+ day ago (204+ words) SOC Prime SOC Prime Bias: Critical Turla (Secret Blizzard): STOCKSTAY and Kazuar Backdoors Explained Turla is a long-established, Russia-aligned APT group associated with the FSB and known for cyber-espionage operations against government and military targets. The group relies on custom…...
TON Blockchain LNK Attack Delivers a Node.js Backdoor
1+ week, 4+ day ago (216+ words) Multi-Stage LNK Attack Uses TON Blockchain to Deliver a Node.js Backdoor SOC Prime SOC Prime Bias: High Multi-Stage LNK Attack Uses TON Blockchain to Deliver a Node.js Backdoor A sophisticated multi-stage attack uses malicious LNK files delivered through…...
Fake Money Transfer Emails Deliver Remcos RAT
1+ week, 4+ day ago (298+ words) SOC Prime Bias: High Threat actors are sending phishing emails disguised as payment confirmation messages to deliver malicious XLS attachments. These files abuse CVE-2017-0199 to retrieve an HTA file, which then launches an obfuscated PowerShell script through WMI. In the…...
Fake Project Proposal Emails Deliver SnakeKeylogger
1+ week, 4+ day ago (294+ words) SOC Prime Bias: High Threat actors are distributing phishing emails disguised as urgent project proposals to deliver malware. The attack uses a compressed archive containing JavaScript malware, which then launches obfuscated PowerShell commands to deploy SnakeKeylogger. This infostealer gathers browser…...
ClickFix Banking Fraud Toolkit Targets Mexico
2+ week, 3+ day ago (148+ words) SOC Prime SOC Prime Bias: High ClickFix to Cash-Out: Breaking Down a Mexican Banking Fraud Toolkit REF6045 is an operator-assisted banking fraud campaign focused on the Mexican financial sector. It uses a ClickFix-style delivery method with fake CAPTCHA pages to convince…...