Summary: 2025/04/19 12:23

First reported date: 2010/08/25
Inquiry period : 2025/04/18 12:23 ~ 2025/04/19 12:23 (1 days), 25 search results

지난 7일 기간대비 -12% 낮은 트렌드를 보이고 있습니다.
지난 7일 기간대비 상승한 Top5 연관 키워드는
Malware Ransomware Campaign MWNEWS Operation 입니다.
악성코드 유형 Lumma Vidar RedLine Raccoon Sodinokibi 도 새롭게 확인됩니다.
공격기술 ClickFix 도 새롭게 확인됩니다.
기타 NTLM SMA Interlock multistage Tesla 등 신규 키워드도 확인됩니다.

 * 최근 뉴스기사 Top3:
    ㆍ 2025/04/19 Alarms sound over attacks via Microsoft NTLM vulnerability
    ㆍ 2025/04/19 HHS fines Guam hospital over ransomware attack, HIPAA violations
    ㆍ 2025/04/19 Attacks involving old SonicWall SMA100 vulnerability underway

Trend graph by period


Related keyword cloud
Top 100

# Trend Count Comparison
1Attack 25 ▼ -3 (-12%)
2Malware 14 ▲ 1 (7%)
3Report 7 ▼ -1 (-14%)
4Exploit 7 - 0 (0%)
5Ransomware 7 ▲ 2 (29%)
6Campaign 6 ▲ 3 (50%)
7target 6 ▼ -2 (-33%)
8MWNEWS 5 ▲ 1 (20%)
9Operation 5 ▲ 1 (20%)
10Vulnerability 4 ▲ 1 (25%)
11Phishing 3 ▼ -1 (-33%)
12United States 3 - 0 (0%)
13group 3 ▲ 2 (67%)
14China 3 - 0 (0%)
15NTLM 3 ▲ new
16SonicWall 2 ▲ 2 (100%)
17Russia 2 - 0 (0%)
18DDoS 2 ▲ 1 (50%)
19RCE 2 ▼ -3 (-150%)
20Telegram 2 ▲ 2 (100%)
21Kaspersky 2 - 0 (0%)
22Windows 2 - 0 (0%)
23Recorded Future 2 ▲ 2 (100%)
24Active 2 ▲ 2 (100%)
25gang 2 ▲ 2 (100%)
26Cisco 2 ▲ 2 (100%)
27SMA 2 ▲ new
28VPN 2 ▲ 1 (50%)
29intelligence 2 ▼ -1 (-50%)
30Threat 2 ▼ -1 (-50%)
31Interlock 2 ▲ new
32Dark 2 ▲ 1 (50%)
33Trojan 2 ▲ 1 (50%)
34Remcos 2 ▲ 2 (100%)
35Software 2 ▼ -1 (-50%)
36multistage 2 ▲ new
37Microsoft 2 - 0 (0%)
38ClickFix 2 ▲ new
39Palo Alto Networks 2 ▲ 1 (50%)
40powershell 2 ▲ 2 (100%)
41Xloader 2 ▲ 2 (100%)
42Chinese 2 ▲ 1 (50%)
43Government 2 - 0 (0%)
44Update 2 ▼ -3 (-150%)
45Lumma 1 ▲ new
46Vidar 1 ▲ new
47DarkWeb 1 ▲ 1 (100%)
48GameoverP2P 1 ▲ 1 (100%)
49Criminal 1 ▼ -1 (-100%)
50c&c 1 - 0 (0%)
51Stealer 1 - 0 (0%)
52RedLine 1 ▲ new
53Cryptocurrency 1 - 0 (0%)
54Tesla 1 ▲ new
55Raccoon 1 ▲ new
56HHS 1 ▲ new
57Agent 1 ▲ 1 (100%)
58Kali 1 ▲ 1 (100%)
59delivery 1 ▲ new
60INC 1 ▲ new
61Browser 1 - 0 (0%)
62Resilience 1 ▲ 1 (100%)
63Food 1 ▲ new
64Ahold 1 ▲ new
65Q2 1 ▲ new
66Mar 1 ▲ new
67leak 1 ▲ new
68hash 1 ▲ new
69APT28 1 ▲ 1 (100%)
70old 1 ▲ 1 (100%)
71Kit 1 ▲ new
72road 1 ▲ 1 (100%)
73CISO 1 ▲ new
74toll 1 ▲ 1 (100%)
75Smishing 1 ▲ 1 (100%)
76Google 1 - 0 (0%)
77North 1 ▲ new
78breach 1 - 0 (0%)
79ransomwarerelated 1 ▲ new
80RAT 1 - 0 (0%)
81Sodinokibi 1 ▲ new
82intrusion 1 ▲ new
83Chinalinked 1 ▲ new
84Billbug 1 ▲ new
85Delhaize 1 ▲ new
86HIPAA 1 ▲ new
87Email 1 ▼ -2 (-200%)
88Takedown 1 ▲ 1 (100%)
89Shops 1 ▲ new
90Controller 1 - 0 (0%)
91NetWireRC 1 - 0 (0%)
92adware 1 ▲ new
93detection 1 - 0 (0%)
94triggered 1 ▲ 1 (100%)
95key 1 - 0 (0%)
96incident 1 ▲ 1 (100%)
97real 1 ▲ 1 (100%)
98FBI 1 ▲ 1 (100%)
99offline 1 ▲ new
100BreachForums 1 ▲ 1 (100%)
Special keyword group
Top 5

Malware Type
Malware Type

This is the type of malware that is becoming an issue.


Keyword Average Label
Ransomware
7 (33.3%)
Trojan
2 (9.5%)
Remcos
2 (9.5%)
Xloader
2 (9.5%)
Lumma
1 (4.8%)
Attacker & Actors
Attacker & Actors

The status of the attacker or attack group being issued.


Keyword Average Label
APT28
1 (100%)
Attack technique
Technique

This is an attack technique that is becoming an issue.


Keyword Average Label
Exploit
7 (26.9%)
Campaign
6 (23.1%)
Phishing
3 (11.5%)
DDoS
2 (7.7%)
RCE
2 (7.7%)
Country & Company
Country & Company

This is a country or company that is an issue.


Keyword Average Label
United States
3 (11.5%)
China
3 (11.5%)
Russia
2 (7.7%)
Kaspersky
2 (7.7%)
Recorded Future
2 (7.7%)
Threat info
Last 5

SNS

(Total : 13)
  Total keyword

attack Malware Attacker Report Ransomware ClickFix Campaign China target Exploit VPN Telegram Backdoor Supply chain RCE Chinese APT MUSTANG PANDA Cobalt Strike Xloader Remcos Palo Alto Networks powershell Software Password Android Banking Operation FBI DDoS Trojan

No Title Date
1Cyber_OSINT @Cyber_O51NT
BreachForums is reportedly offline again, with claims of DDoS attacks by a group called Dark Storm, though experts urge skepticism amid speculation of another FBI seizure and ongoing chaos within the forum's operations. #Cybersecurity #BreachForums https://t.co/qtORDeDoXk
2025.04.18
2Cyber_OSINT @Cyber_O51NT
On April 12, 2025, CMC Group engineers experienced the onset of Vietnam's most notable ransomware attack, as network logs revealed an unfamiliar admin account probing hidden developer subnets. #CyberSecurity #VietnamCyberAttack https://t.co/J9g2I9tBAk
2025.04.18
3Cyber_OSINT @Cyber_O51NT
A recent multi-stage malware attack utilizes .JSE and PowerShell to deliver Agent Tesla, Remcos RAT, and XLoader, as noted by Palo Alto Networks' Saqib Khanzada, who highlights attackers' tactics to evade detection and ensure payload execution. https://t.co/i7vn5wZL9L
2025.04.18
4Cyber_OSINT @Cyber_O51NT
New stats reveal Android malware attacks reached 33.3 million in 2024, with adware leading at 35% of detections, while mobile banking Trojan incidents surged by 196%, highlighting the persistent and evolving threats in 2025. #AndroidMalware #Cybersecurity https://t.co/qL1dLQYFq4
2025.04.18
5Microsoft Threat Intelligence @MsftSecIntel
Threat actors have consistently exploited critical vulnerabilities in Exchange Server and SharePoint Server that enable them to gain a persistent foothold inside the target. Such attacks have been observed to lead to remote code execution, lateral movement, and exfiltration of
2025.04.18

Additional information

No data
No data
No data
No URL CC ASN Co Reporter Date
1http://95.214.55.202:3306/TomcatBypass/Command/Base64/a2lsbGFsbCAtOSBwYXJhaXNvLng4Njsga2lsbGFsbCAtOS...
attack shell TomcatByPass
PL PLMeverywhere sp. z o.o.abus3reports2024.05.14
2http://194.59.31.163:2411/TomcatBypass/Command/Base64/d2dldCAtTy0gaHR0cDovLzE5NC41OS4zMS4xNjMvbGkyLn...
attack shell TomcatByPass
US USabus3reports2024.05.14
Beta Service, If you select keyword, you can check detailed information.