❌

Normal view

There are new articles available, click to refresh the page.
Before yesterdayMain stream

Key Insights on SHADOW-AETHER-015 and Earth Preta from the 2025 MITRE ATT&CK Evaluation with TrendAI Vision Oneβ„’

12 January 2026 at 19:00
This blog discusses notable modern TTPs observed from SHADOW-AETHER-015 and Earth Preta, from TrendAIβ„’ Research monitoring and TrendAI Vision Oneβ„’ intelligence. These findings support the performance of TrendAIβ„’ in the 2025 MITRE ATT&CK Evaluations.

The Rise of Collaborative Tactics Among China-aligned Cyber Espionage Campaigns

Trendβ„’ Research examines the complex collaborative relationship between China-aligned APT groups via the new β€œPremier Pass-as-a-Service” model, exemplified by the recent activities of Earth Estries and Earth Naga.

Clone, Compile, Compromise: Water Curse’s Open-Source Malware Trap on GitHub

The Trend Microβ„’ Managed Detection and Response team uncovered a threat campaign orchestrated by an active group, Water Curse. The threat actor exploits GitHub, one of the most trusted platforms for open-source software, as a delivery channel for weaponized repositories.

Threat Intelligence Sweeping now supports container security telemetry data

Threat Intelligence Sweeping starts to support sweep container security telemetry data. Users can now use the TI tool to identify possible malicious activity in their container-based environments. The trigger events are visible in workbench alert.

Earth Lamia Develops Custom Arsenal to Target Multiple Industries

26 May 2025 at 20:00
Trendβ„’ Research has been tracking an active APT threat actor named Earth Lamia, targeting multiple industries in Brazil, India and Southeast Asia countries at least since 2023. The threat actor primarily exploits vulnerabilities in web applications to gain access to targeted organizations.

Earth Kurma APT Campaign Targets Southeast Asian Government, Telecom Sectors

24 April 2025 at 20:00
An APT group dubbed Earth Kurma is actively targeting government and telecommunications organizations in Southeast Asia using advanced malware, rootkits, and trusted cloud services to conduct cyberespionage.

❌
❌