# High Profile Threats

Unit 42 research category covering high-profile cyberthreats and vulnerabilities.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## Impersonating IT support: how threat actors turn a remote session into enterprise-wide access

DevFeed: [Impersonating IT support: how threat actors turn a remote session into enterprise-wide access](<https://devfeed.tech/articles/impersonating-it-support-how-threat-actors-turn-a-remote-session-into-enterprise-wide-access-7639.md>)

Original publisher: [Read original article](<https://www.microsoft.com/en-us/security/blog/2026/09/02/impersonating-it-support-threat-actors-turn-remote-session-into-enterprise-wide-access/>)

Author: Microsoft Security Research, Sagar Patil, Arlette Umuhire Sangwa, Jesse Birch and Ravikant Tiwari

Published: 2026-09-02T22:51:18Z

Content type: article

Language: en

Sources: [Microsoft Security Blog](<https://devfeed.tech/sources/microsoft-security-blog.md>)

Topics: [High Profile Threats](<https://devfeed.tech/topics/high-profile-threats.md>), [Node.js](<https://devfeed.tech/topics/node-js.md>)

Tags: [c2](<https://devfeed.tech/tags/c2.md>), [identity](<https://devfeed.tech/tags/identity.md>), [infrastructure](<https://devfeed.tech/tags/infrastructure.md>), [javascript](<https://devfeed.tech/tags/javascript.md>), [microsoft-teams](<https://devfeed.tech/tags/microsoft-teams.md>), [node-js](<https://devfeed.tech/tags/node-js.md>), [powershell](<https://devfeed.tech/tags/powershell.md>), [security](<https://devfeed.tech/tags/security.md>), [social-engineering](<https://devfeed.tech/tags/social-engineering.md>), [windows](<https://devfeed.tech/tags/windows.md>)

### AI overview

Microsoft analyzes an intrusion campaign in which attackers impersonate IT support through Microsoft Teams, obtain remote access, deploy a Node.js and JavaScript implant, and move laterally through enterprise systems. The article provides detection, mitigation, and hunting guidance.

### Source excerpt

Microsoft Threat Intelligence observed a human-operated intrusion campaign that abuses Microsoft Teams external collaboration to impersonate IT support, gain remote access, and deploy a Node.js-based implant. Learn how attackers move from social engineering to lateral movement using legitimate tools, and how Microsoft Defender helps detect and disrupt the activity. The post Impersonating IT support: how threat actors turn a remote session into enterprise-wide access appeared first on Microsoft Security Blog.

## TerminalFix campaign deploys a reverse tunnel through multistage intrusion

DevFeed: [TerminalFix campaign deploys a reverse tunnel through multistage intrusion](<https://devfeed.tech/articles/terminalfix-campaign-deploys-a-reverse-tunnel-through-multistage-intrusion-7636.md>)

Original publisher: [Read original article](<https://www.microsoft.com/en-us/security/blog/2026/08/28/terminalfix-campaign-deploys-reverse-tunnel-through-multistage-intrusion/>)

Author: Microsoft Security Research, Sagar Patil, Suriyaraj Natarajan and Parasharan Raghavan

Published: 2026-08-29T03:43:27Z

Content type: article

Language: en

Sources: [Microsoft Security Blog](<https://devfeed.tech/sources/microsoft-security-blog.md>)

Topics: [High Profile Threats](<https://devfeed.tech/topics/high-profile-threats.md>)

Tags: [analysis](<https://devfeed.tech/tags/analysis.md>), [c2](<https://devfeed.tech/tags/c2.md>), [clickfix](<https://devfeed.tech/tags/clickfix.md>), [cloudflare](<https://devfeed.tech/tags/cloudflare.md>), [microsoft](<https://devfeed.tech/tags/microsoft.md>), [persistence](<https://devfeed.tech/tags/persistence.md>), [powershell](<https://devfeed.tech/tags/powershell.md>), [python](<https://devfeed.tech/tags/python.md>), [ransomware](<https://devfeed.tech/tags/ransomware.md>), [security](<https://devfeed.tech/tags/security.md>), [windows](<https://devfeed.tech/tags/windows.md>)

### AI overview

Microsoft analyzes the TerminalFix ClickFix campaign, which uses a fake Cloudflare CAPTCHA to induce PowerShell execution and deploys a multi-stage intrusion chain. The chain includes DLL sideloading, steganographic payload delivery, Active Directory reconnaissance, persistence, and an encrypted reverse tunnel that can provide access into the compromised network.

### Source excerpt

Microsoft Threat Intelligence provides analysis of a ClickFix campaign that uses fake CAPTCHA prompts, DLL sideloading, and a reverse tunnel, with detections and hunting guidance. The post TerminalFix campaign deploys a reverse tunnel through multistage intrusion appeared first on Microsoft Security Blog.

## Cloudflare DDoS Threat Report H1 2026: 1 Tbps attacks soar as DNS floods and geopolitical tensions drive a new wave

DevFeed: [Cloudflare DDoS Threat Report H1 2026: 1 Tbps attacks soar as DNS floods and geopolitical tensions drive a new wave](<https://devfeed.tech/articles/cloudflare-ddos-threat-report-h1-2026-1-tbps-attacks-soar-as-dns-floods-and-geopolitical-tensions-drive-a-new-wave-113.md>)

Original publisher: [Read original article](<https://blog.cloudflare.com/ddos-threat-report-2026-h1/>)

Author: Cloudforce One

Published: 2026-08-11T13:00:00Z

Content type: article

Language: en

Sources: [Cloudflare Blog](<https://devfeed.tech/sources/cloudflare-blog.md>)

Topics: [DDoS](<https://devfeed.tech/topics/ddos.md>), [Cloudflare](<https://devfeed.tech/topics/cloudflare.md>), [Threat Research](<https://devfeed.tech/topics/threat-research.md>), [Cloudforce One](<https://devfeed.tech/topics/cloudforce-one.md>), [Network](<https://devfeed.tech/topics/network.md>), [data](<https://devfeed.tech/topics/data.md>), [Cybercrime](<https://devfeed.tech/topics/cybercrime.md>), [High Profile Threats](<https://devfeed.tech/topics/high-profile-threats.md>)

Tags: [analysis](<https://devfeed.tech/tags/analysis.md>), [attacks](<https://devfeed.tech/tags/attacks.md>), [cloudflare](<https://devfeed.tech/tags/cloudflare.md>), [cloudforce-one](<https://devfeed.tech/tags/cloudforce-one.md>), [data](<https://devfeed.tech/tags/data.md>), [ddos](<https://devfeed.tech/tags/ddos.md>), [dns](<https://devfeed.tech/tags/dns.md>), [drive](<https://devfeed.tech/tags/drive.md>), [global](<https://devfeed.tech/tags/global.md>), [government](<https://devfeed.tech/tags/government.md>), [industry](<https://devfeed.tech/tags/industry.md>), [iran](<https://devfeed.tech/tags/iran.md>), [media](<https://devfeed.tech/tags/media.md>), [network](<https://devfeed.tech/tags/network.md>), [radar](<https://devfeed.tech/tags/radar.md>), [streaming](<https://devfeed.tech/tags/streaming.md>), [threat-report](<https://devfeed.tech/tags/threat-report.md>)

### AI overview

Cloudflare's H1 2026 DDoS Threat Report analyzes attacks from January through June 2026. It highlights a 519% quarter-over-quarter increase in attacks exceeding 1 Tbps, a shift toward DNS and CLDAP reflection and amplification vectors, and the influence of geopolitical events on attack patterns. The report also covers attack volumes, an April peak, and the possible impact of Operation PowerOFF.

### Source excerpt

In the first half of 2026, Cloudflare detected a 519% surge in hyper-volumetric DDos attacks across its network. These attacks were driven heavily by DNS and CLDAP reflection vectors. This report breaks down how major geopolitical conflicts reshaped the global cyber threat landscape.

## Cyber readiness for SMBs: Getting the basics right

DevFeed: [Cyber readiness for SMBs: Getting the basics right](<https://devfeed.tech/articles/cyber-readiness-for-smbs-getting-the-basics-right-8330.md>)

Original publisher: [Read original article](<https://www.welivesecurity.com/en/business-security/cyber-readiness-smbs-getting-basics-right/>)

Author: Phil Muncaster

Published: 2026-07-03T12:36:41Z

Content type: article

Language: en

Sources: [WeLiveSecurity](<https://devfeed.tech/sources/welivesecurity.md>)

Topics: [High Profile Threats](<https://devfeed.tech/topics/high-profile-threats.md>), [vulnerability](<https://devfeed.tech/topics/vulnerability.md>), [passwords](<https://devfeed.tech/topics/passwords.md>), [AI, ML & Data Engineering](<https://devfeed.tech/topics/ai-ml-data-engineering.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [business-security](<https://devfeed.tech/tags/business-security.md>), [cybercrime](<https://devfeed.tech/tags/cybercrime.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [generative-ai](<https://devfeed.tech/tags/generative-ai.md>), [malware](<https://devfeed.tech/tags/malware.md>), [phishing](<https://devfeed.tech/tags/phishing.md>), [ransomware](<https://devfeed.tech/tags/ransomware.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>)

### AI overview

The article argues that SMBs should prioritize familiar security gaps such as phishing, unpatched vulnerabilities, missed alerts, and reused passwords, even as AI helps attackers improve lures and reconnaissance. It says truly AI-powered malware remains uncommon and has not played a significant role in incidents observed by ESET's MDR service.

### Source excerpt

AI is changing cybercrime, but SMB cyber readiness still largely depends on closing the familiar gaps

## ESET takes part in Operation Endgame to disrupt Amadey and Stealc

DevFeed: [ESET takes part in Operation Endgame to disrupt Amadey and Stealc](<https://devfeed.tech/articles/eset-takes-part-in-operation-endgame-to-disrupt-amadey-and-stealc-8364.md>)

Original publisher: [Read original article](<https://www.welivesecurity.com/en/eset-research/eset-takes-part-operation-endgame-disrupt-amadey-stealc/>)

Author: Jakub Tomanek Tomáš Procházka

Published: 2026-06-24T12:35:24Z

Content type: article

Language: en

Sources: [WeLiveSecurity](<https://devfeed.tech/sources/welivesecurity.md>)

Topics: [ESET research](<https://devfeed.tech/topics/eset-research.md>), [Malware](<https://devfeed.tech/topics/malware.md>), [Threat Research](<https://devfeed.tech/topics/threat-research.md>), [Cybercrime](<https://devfeed.tech/topics/cybercrime.md>), [C2](<https://devfeed.tech/topics/c2.md>), [High Profile Threats](<https://devfeed.tech/topics/high-profile-threats.md>), [Encryption](<https://devfeed.tech/topics/encryption.md>), [data](<https://devfeed.tech/topics/data.md>), [Statistics](<https://devfeed.tech/topics/statistics.md>)

Tags: [analysis](<https://devfeed.tech/tags/analysis.md>), [data](<https://devfeed.tech/tags/data.md>), [encryption](<https://devfeed.tech/tags/encryption.md>), [eset-research](<https://devfeed.tech/tags/eset-research.md>), [maas](<https://devfeed.tech/tags/maas.md>), [malware](<https://devfeed.tech/tags/malware.md>), [network](<https://devfeed.tech/tags/network.md>), [research](<https://devfeed.tech/tags/research.md>)

### AI overview

ESET Research describes its contribution to Operation Endgame, a coordinated global effort that disrupted the Amadey botnet and Stealc infostealer. The article covers infrastructure tracking, technical and statistical analysis, malware configuration data, command-and-control servers, encryption keys, campaign identifiers, and affiliate-level activity within the malware-as-a-service ecosystem.

### Source excerpt

ESET researchers assisted in the global disruption of the Amadey botnet and Stealc infostealer, providing technical analysis, infrastructure tracking, and affiliate-level insights

## Protecting legacy OT systems against modern cyberthreats

DevFeed: [Protecting legacy OT systems against modern cyberthreats](<https://devfeed.tech/articles/protecting-legacy-ot-systems-against-modern-cyberthreats-8346.md>)

Original publisher: [Read original article](<https://www.welivesecurity.com/en/critical-infrastructure/protecting-legacy-ot-systems-modern-threats/>)

Author: Tomáš Foltýn

Published: 2026-06-17T08:45:00Z

Content type: article

Language: en

Sources: [WeLiveSecurity](<https://devfeed.tech/sources/welivesecurity.md>)

Topics: [High Profile Threats](<https://devfeed.tech/topics/high-profile-threats.md>), [incident](<https://devfeed.tech/topics/incident.md>)

Tags: [attacks](<https://devfeed.tech/tags/attacks.md>), [authentication](<https://devfeed.tech/tags/authentication.md>), [critical-infrastructure](<https://devfeed.tech/tags/critical-infrastructure.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [incident](<https://devfeed.tech/tags/incident.md>), [logging](<https://devfeed.tech/tags/logging.md>), [manufacturing](<https://devfeed.tech/tags/manufacturing.md>), [networks](<https://devfeed.tech/tags/networks.md>), [production](<https://devfeed.tech/tags/production.md>), [security](<https://devfeed.tech/tags/security.md>), [update](<https://devfeed.tech/tags/update.md>)

### AI overview

Legacy operational technology in manufacturing can become a cybersecurity blind spot as industrial control systems connect to enterprise networks. The article highlights weak authentication, limited logging, insecure defaults, and difficult updates as risks that can lead to operational disruption.

### Source excerpt

Many manufacturing plants depend on OT systems that stay in service for many years. That long run can hide significant cybersecurity risks.

## ESET APT Activity Report Q4 2025-Q1 2026

DevFeed: [ESET APT Activity Report Q4 2025-Q1 2026](<https://devfeed.tech/articles/eset-apt-activity-report-q4-2025-q1-2026-8362.md>)

Original publisher: [Read original article](<https://www.welivesecurity.com/en/eset-research/eset-apt-activity-report-q4-2025-q1-2026/>)

Author: Jean-Ian Boutin

Published: 2026-05-28T08:45:00Z

Content type: article

Language: en

Sources: [WeLiveSecurity](<https://devfeed.tech/sources/welivesecurity.md>)

Topics: [High Profile Threats](<https://devfeed.tech/topics/high-profile-threats.md>)

Tags: [apt](<https://devfeed.tech/tags/apt.md>), [china](<https://devfeed.tech/tags/china.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [eset-research](<https://devfeed.tech/tags/eset-research.md>), [iran](<https://devfeed.tech/tags/iran.md>), [virustotal](<https://devfeed.tech/tags/virustotal.md>)

### AI overview

ESET's report summarizes selected APT activity from October 2025 through March 2026, including China-aligned espionage, activity targeting government and strategic-technology entities, and changes in Iran-aligned activity during the war in Iran.

### Source excerpt

An overview of the activities of selected APT groups investigated and analyzed by ESET Research in Q4 2025 and Q1 2026

## A rigged game: ScarCruft compromises gaming platform in a supply-chain attack

DevFeed: [A rigged game: ScarCruft compromises gaming platform in a supply-chain attack](<https://devfeed.tech/articles/a-rigged-game-scarcruft-compromises-gaming-platform-in-a-supply-chain-attack-8381.md>)

Original publisher: [Read original article](<https://www.welivesecurity.com/en/eset-research/rigged-game-scarcruft-compromises-gaming-platform-supply-chain-attack/>)

Author: Filip Jurčacko

Published: 2026-05-05T08:55:27Z

Content type: article

Language: en

Sources: [WeLiveSecurity](<https://devfeed.tech/sources/welivesecurity.md>)

Topics: [Threat Research](<https://devfeed.tech/topics/threat-research.md>), [backdoor](<https://devfeed.tech/topics/backdoor.md>), [LineageOS](<https://devfeed.tech/topics/lineageos.md>), [Windows](<https://devfeed.tech/topics/windows.md>), [High Profile Threats](<https://devfeed.tech/topics/high-profile-threats.md>), [C++](<https://devfeed.tech/topics/c-plus-plus.md>), [Shell](<https://devfeed.tech/topics/shell.md>), [Python](<https://devfeed.tech/topics/python.md>), [Ruby](<https://devfeed.tech/topics/ruby.md>)

Tags: [analysis](<https://devfeed.tech/tags/analysis.md>), [android](<https://devfeed.tech/tags/android.md>), [china](<https://devfeed.tech/tags/china.md>), [cloud](<https://devfeed.tech/tags/cloud.md>), [data](<https://devfeed.tech/tags/data.md>), [eset-research](<https://devfeed.tech/tags/eset-research.md>), [gaming](<https://devfeed.tech/tags/gaming.md>), [government](<https://devfeed.tech/tags/government.md>), [logging](<https://devfeed.tech/tags/logging.md>), [platform](<https://devfeed.tech/tags/platform.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>), [voice](<https://devfeed.tech/tags/voice.md>), [windows](<https://devfeed.tech/tags/windows.md>)

### AI overview

ESET researchers describe a ScarCruft supply-chain attack that trojanized Windows and Android components of a Yanbian-themed gaming platform. The BirdCall backdoor supports espionage capabilities including collecting data and documents, screenshots, and voice recordings.

### Source excerpt

ESET researchers have investigated an ongoing attack by the ScarCruft APT group that targets the Yanbian region via backdoor-laced Windows and Android games

## This month in security with Tony Anscombe - March 2026 edition

DevFeed: [This month in security with Tony Anscombe - March 2026 edition](<https://devfeed.tech/articles/this-month-in-security-with-tony-anscombe-march-2026-edition-8426.md>)

Original publisher: [Read original article](<https://www.welivesecurity.com/en/videos/month-security-tony-anscombe-march-2026/>)

Author: Editor

Published: 2026-03-31T08:27:18Z

Content type: news

Language: en

Sources: [WeLiveSecurity](<https://devfeed.tech/sources/welivesecurity.md>)

Topics: [High Profile Threats](<https://devfeed.tech/topics/high-profile-threats.md>)

Tags: [attacks](<https://devfeed.tech/tags/attacks.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [phishing](<https://devfeed.tech/tags/phishing.md>), [ransomware](<https://devfeed.tech/tags/ransomware.md>), [resilience](<https://devfeed.tech/tags/resilience.md>), [security](<https://devfeed.tech/tags/security.md>), [video](<https://devfeed.tech/tags/video.md>), [windows](<https://devfeed.tech/tags/windows.md>)

### AI overview

A monthly cybersecurity video roundup covers a reported attack on Stryker, ransomware data theft, changes to Instagram message encryption, and the takedown of the Tycoon 2FA phishing platform.

### Source excerpt

The past four weeks have seen a slew of new cybersecurity wake-up calls that showed why every organization needs a well-thought-out cyber-resilience plan

## Security Leadership Master Class 7 : Contrarian takes

DevFeed: [Security Leadership Master Class 7 : Contrarian takes](<https://devfeed.tech/articles/security-leadership-master-class-7-contrarian-takes-39496.md>)

Original publisher: [Read original article](<https://www.philvenables.com/post/security-leadership-master-class-7-contrarian-takes>)

Author: Phil Venables

Published: 2025-12-27T15:12:43Z

Content type: article

Language: en

Sources: [Risk and Cyber](<https://devfeed.tech/sources/risk-and-cyber.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [benchmarking](<https://devfeed.tech/topics/benchmarking.md>), [High Profile Threats](<https://devfeed.tech/topics/high-profile-threats.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>)

Tags: [benchmarking](<https://devfeed.tech/tags/benchmarking.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [leadership](<https://devfeed.tech/tags/leadership.md>), [security](<https://devfeed.tech/tags/security.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

The article's final installment discusses contrarian perspectives on security leadership, arguing that cybersecurity benchmarking should focus on control effectiveness and outcomes rather than inputs such as budgets. It also considers adversarial strategy and responses to recurring waves of vulnerabilities.

### Source excerpt

This is the final of the series grouping together sets of prior posts into a particular theme. Security Leadership Master Class 1 : Leveling up your leadership Security Leadership Master Class 2 : Dealing with the board and other executives Security Leadership Master Class 3 : Building a security program Security Leadership Master Class 4 : Enhancing/refreshing a security program Security Leadership Master Class 5 : Getting hired and doing hiring Security Leadership Master Class 6 : When...