Please confirm you are human

This browser or connection looks automated. Press and continuously hold the control for 3 seconds to enable Google-hosted web results and, when separately allowed, AI-assisted answers.

A successful check enables 100 search requests. Interactive access does not authorize scraping, systematic collection, or reuse of search output.

Hold with a pointer, or hold Space or Enter.

News

SOC Prime
socprime.com > active-threats > dolphin-x-stealer-targets-300-apps-and-profiles-users-with-ai

Dolphin X Stealer Uses AI to Rank High-Value Victims

2+ day, 16+ hour ago   (218+ words) SOC Prime SOC Prime Bias: High Dolphin X Stealer Targets 300+ Apps and Profiles Users with AI Dolphin X is a newly identified Windows-based stealer and remote access trojan capable of targeting more than 300 applications, including browsers, cryptocurrency wallets, and DevOps…...

SOC Prime
socprime.com > active-threats > cve-2026-0257-exploitation-and-the-path-to-qilin-ransomware

CVE-2026-0257 Exploitation Leads to Qilin Ransomware

2+ day, 22+ hour ago   (270+ words) SOC Prime Bias: Critical Threat actors are exploiting a critical authentication bypass flaw in Palo Alto Networks GlobalProtect to obtain initial access. After entering the environment, the attackers deploy Qilin ransomware, often after stealing credentials and exfiltrating data. The resulting…...

SOC Prime
socprime.com > active-threats > new-gomir-variant-used-in-kimsuky-attack-on-south-korean-groupware-vendor

Kimsuky Targets South Korean Groupware with Gomir

2+ day, 22+ hour ago   (191+ words) SOC Prime Bias: Critical ENKI WhiteHat analyzed the campaign across 2025 and early 2026 and identified several malware strains developed in Go. The investigation showed how Kimsuky combined remote code execution on mail servers with social engineering to secure initial access. Analysts…...

SOC Prime
socprime.com > active-threats > cruciferra-analyzing-a-sophisticated-crypter-service

Cruciferra Crypter Service Hides RATs and Infostealers

2+ day, 22+ hour ago   (193+ words) SOC Prime SOC Prime Bias: High Cruciferra: Analyzing a Sophisticated Crypter Service Cruciferra is a sophisticated crypter service used by multiple unrelated cybercriminal groups to obfuscate a broad range of malware, including RATs and infostealers. It applies advanced defense-evasion techniques…...

SOC Prime
socprime.com > blog > cve-2026-56164-and-cve-2026-56155-analysis

CVE-2026-56164 & CVE-2026-56155 Zero-Days

1+ week, 2+ day ago   (412+ words) Add to my AI research Exclusive to SOC Prime users For CVE-2026-56164 analysis, the key point is that Microsoft and outside reporting both describe the flaw as already exploited in real attacks against on-prem SharePoint. It is an elevation-of-privilege issue,…...

SOC Prime
socprime.com > active-threats > turla-secret-blizzard-stockstay-and-kazuar-backdoors-explained

Turla Uses STOCKSTAY and Kazuar Backdoors for Espionage

1+ week, 4+ day ago   (204+ words) SOC Prime SOC Prime Bias: Critical Turla (Secret Blizzard): STOCKSTAY and Kazuar Backdoors Explained Turla is a long-established, Russia-aligned APT group associated with the FSB and known for cyber-espionage operations against government and military targets. The group relies on custom…...

SOC Prime
socprime.com > active-threats > multi-stage-lnk-attack-uses-ton-blockchain-to-deliver-a-node-js-backdoor

TON Blockchain LNK Attack Delivers a Node.js Backdoor

1+ week, 4+ day ago   (216+ words) Multi-Stage LNK Attack Uses TON Blockchain to Deliver a Node.js Backdoor SOC Prime SOC Prime Bias: High Multi-Stage LNK Attack Uses TON Blockchain to Deliver a Node.js Backdoor A sophisticated multi-stage attack uses malicious LNK files delivered through…...

SOC Prime
socprime.com > active-threats > phishing-emails-masquerading-as-money-transfer-confirmations

Fake Money Transfer Emails Deliver Remcos RAT

1+ week, 4+ day ago   (298+ words) SOC Prime Bias: High Threat actors are sending phishing emails disguised as payment confirmation messages to deliver malicious XLS attachments. These files abuse CVE-2017-0199 to retrieve an HTA file, which then launches an obfuscated PowerShell script through WMI. In the…...

Google News
socprime.com > active-threats > phishing-scam-trend-fake-project-proposal-emails

Fake Project Proposal Emails Deliver SnakeKeylogger

1+ week, 4+ day ago   (294+ words) SOC Prime Bias: High Threat actors are distributing phishing emails disguised as urgent project proposals to deliver malware. The attack uses a compressed archive containing JavaScript malware, which then launches obfuscated PowerShell commands to deploy SnakeKeylogger. This infostealer gathers browser…...

SOC Prime
socprime.com > active-threats > clickfix-to-cash-out-breaking-down-a-mexican-banking-fraud-toolkit

ClickFix Banking Fraud Toolkit Targets Mexico

2+ week, 3+ day ago   (148+ words) SOC Prime SOC Prime Bias: High ClickFix to Cash-Out: Breaking Down a Mexican Banking Fraud Toolkit REF6045 is an operator-assisted banking fraud campaign focused on the Mexican financial sector. It uses a ClickFix-style delivery method with fake CAPTCHA pages to convince…...