Release the RAVEN: Kibana Under Siege

August 13, 2026 | Karl Biron

Hunter

The Infrastructure Relay: Inside Multi-Stage Phishing Redirection Chains

August 12, 2026 | Karla Agregado

To stay ahead of evolving threats, LevelBlue utilizes a machine-learning-based ...

CNCMachineRMS: The Undocumented RAT At the End of a BabaDeda Chain

August 10, 2026 | Rodel Mendrez

This post is the result of an investigation into a case we worked on, in which ...

Beyond ‘Fake Updates’: From Application Store-Themed Phishing to Large-Scale Distribution of ScreenConnect

August 07, 2026 | King Orande and Cris Tomboc

The LevelBlue OpsCTI Team recently identified a large-scale phishing campaign ...

Release the RAVEN: Exploiting the Cracks

August 06, 2026 | Karl Biron

In Part 1, we went from a single open port to a complete map of the target. ...

Release the RAVEN: First Contact

August 05, 2026 | Karl Biron

You are mid-engagement. Nmap finishes its sweep and port 9200 lights up on a ...

Review of the July 2026 Cyberattacks Against U.S. Water and Wastewater Systems

August 04, 2026 | Nikita Kazymirskyi

In light of the water-sector activity described below, we've increased ...

Release the RAVEN: An Offensive Reconnaissance and Attack Tool on Vulnerable Elasticsearch Nodes

July 29, 2026 | Karl Biron

You have almost certainly interacted with Elasticsearch today. The search bar ...

LegacyHive: Hunting Windows Profile Initialization Abuse Through Offline Registry Manipulation

July 27, 2026 | Serhii Melnyk and Timmy Lister

Following GreenPlasma, YellowKey and MiniPlasma, as well as RoguePlanet and ...

LevelBlue TTP Briefing Q2 2026: Stolen Identities Outpace Defenses

July 23, 2026

Explore the latest tactics, techniques, and procedures (TTPs) our incident ...

Exploitarium: Inside the Archive Behind the Mass 0-Day Drop

July 21, 2026 | Serhii Melnyk

Coordinated vulnerability disclosures operate on a straightforward premise: the ...

LegacyHive: Nightmare-Eclipse’s Latest Zero-Day Drop with a Stripped PoC

July 20, 2026 | Pauline Bolaños

Vexed researcher Nightmare-Eclipse (aka Chaotic Eclipse, Dead Eclipse, and ...

Still Circling: Blind Eagle's Toolkit Keeps Evolving

July 17, 2026 | Serhii Melnyk

In June 2025, LevelBlue SpiderLabs published Tracing Blind Eagle to Proton66, ...

ClickFix on macOS: Blockchain-Powered Infostealer Hidden Inside Compromised Websites

July 16, 2026 | Rodel Mendrez

You're browsing a legitimate small business website. Before the page loads, a ...

Mitigating New Vulnerabilities with owLSM

July 13, 2026

Following the successful launch of owLSM, our first open-source project with ...

Hiding in the Chain: Multi-Stage LNK Attack Leveraging TON Blockchain to Deliver Node.JS Backdoor

July 09, 2026 | Nathaniel Morales

The LevelBlue Managed Threat Research team investigated a security alert in a ...

Open Sourcing Our Most Advanced Linux Security Engine: owLSM

July 09, 2026

We at LevelBlue company have decided to do something for the community, with ...

From Phishing to Persistence: A CrySome RAT Infection Chain Analysis

July 06, 2026 | Sean Shirley and Kyle Sopt

During a recent security alert, the LevelBlue MDR SOC successfully triaged and ...

AsyncRAT and Remcos Delivered in Multi-Stage Phishing Campaign

July 02, 2026 | Fernando Martinez Sidera

Over the past two weeks, LevelBlue SpiderLabs has been tracking an active ...

An Analysis of ValleyRAT Infection Campaigns from Fake Installers, Japanese Malicious Emails

June 30, 2026 | Hajime Takai

Key points LevelBlue has identified two distinct attack vectors associated with ...

Novel Java-Based QuimaRAT Targets Windows, macOS, and Linux

June 25, 2026 | Chen Aviani and Nikita Kazymirskyi

Remote access trojans (RATs) are legacy threats that continue to evolve ...

LokiBot After a Decade: An Analysis of a Recent LokiBot Campaign

June 24, 2026 | Dawid Nesterowicz

In Norse mythology, Loki, the god of mischief, has powerful and deceptive ...

Operation FlutterBridge: The FlutterShell macOS Backdoor

June 18, 2026 | Maor Gabay

Identified through macOS endpoint monitoring, the CL-CRI-1089 cluster, ...

RoguePlanet and GreatXML: Detecting Local Privilege Escalation and BitLocker Security Boundary Abuse

June 17, 2026 | Serhii Melnyk

Following our previous research, LevelBlue SpiderLabs continued monitoring a ...

Reversing NVIDIA’s CVE-2026-24190: How a Kernel Flaw Put Enterprise AI Clusters and Workstations at Risk

June 15, 2026 | Alon Bancic

Executive Summary: Bypassing Boundaries in Enterprise AI Infrastructure The ...

The Device Code Phishing Tsunami: What We’re Seeing in the Wild

June 09, 2026 | John Kevin Adriano

With contributions from Cris Tomboc.

macOS ClickFix Social Engineering Campaigns

June 04, 2026 | Maor Gabay

Overview The "ClickFix" threat landscape has undergone a significant ...

ClickFix Is Now Hiring: From Job Platform Impersonation to Python-Based RAT Delivery

June 04, 2026 | King Orande and Cris Tomboc

The LevelBlue OpsIntel CTI team examined the latest version of the ClickFix ...