RSS
Threat Research
STAC6405
infostealer
RMM
Phishing
Incident responders, s'il vous plait: Invites lead to odd malware events
A phishing campaign targeting multiple organizations led to RMM installations – but not much else (yet). A threat actor experimenting, or an access-as-a-service attack underway?
clickfix
Featured
GOLD FEATHER
human verification
qilin
Ransomware
StealC
I am not a robot: ClickFix used to deploy StealC and Qilin
MacOS
MacSync
Social engineering
Evil evolution: ClickFix and macOS infostealers
EDR killer
Threat Intelligence Executive Report – Volume 2025, Number 6
TamperedChef
EvilAI
Sophos X-Ops
TamperedChef serves bad ads with infostealers as the main course
Astaroth
Brazil
Guildma
WhatsApp
worm
WhatsApp compromise leads to Astaroth deployment
Sophos Insights
digital identity
Identity Threat Detection and Response
Information Stealers
Sophos ITDR
Infostealers: The silent doorway to identity attacks — and why proactive defense matters
MFA
multi-factor authentication
patching
Vulnerabilities
Threat Intelligence Executive Report – Volume 2025, Number 5
coyote
Powershell
selenium
WhatsApp Worm Targets Brazilian Banking Customers
AMOS
atomic stealer
Atomic macOS Stealer leads sensitive data theft on macOS