Log inSign up
Gen Threat Labs
583 posts
Gen Threat Labs profile banner
@GenThreatLabs

Gen Threat Labs

@GenThreatLabs
A global network of #cybersecurity researchers at Gen, protecting nearly 500M people through our Cyber Safety brands - @Norton, @Avast, @LifeLock & more.
Prague, Czech Republic
gendigital.com/blog/insights
Joined May 2017
26
Following
4,724
Followers
RepliesRepliesRepostsRepostsMediaMediaArticlesArticles

Log in or sign up for X

See what’s happening and join the conversation

Continue with phone
or
Log in with username or email
Terms·Privacy·Cookies·Accessibility·Ads Info·© 2026 X Corp.
  • @GenThreatLabs
    Gen Threat Labs
    @GenThreatLabs
    Aug 26
    🇨🇳 #APT24 aka BADAUDIO remains active. The group recently compromised part of a 🇹🇼 Taiwanese advertising supply chain to deliver obfuscated #FingerprintJS2 profiling code across popular news and fiction sites, including CZBooks and Taisounds. Visitors are silently fingerprinted
  • @GenThreatLabs
    Gen Threat Labs
    @GenThreatLabs
    Aug 14
    A WMI subscription named "Realtek" started a 12 KB backdoor at 19:50, and it never exited. It read its C2 domain by counting spaces in a fake desktop.ini, then called a domain its operator stopped paying for in July 2021. It kept trying for 11 months. Read more ->
    A 12 KB Backdoor Hid Its C2 Domain in desktop.ini Whitespace
    From gendigital.com
    4
  • @GenThreatLabs
    Gen Threat Labs
    @GenThreatLabs
    Aug 7
    We identified a large-scale Spanish-language phishing campaign producing ~1k unique personalized PDF lures within 24 hours. Targets: SMBs across 🇪🇸 Spain, 🇲🇽 Mexico, 🇨🇱 Chile, 🇵🇪 Peru, and 🇦🇷 Argentina. C2: 10[.]196[.]252[.]46[.]host[.]secureserver[.]net/pdf PDF gen: Python
  • @GenThreatLabs
    Gen Threat Labs
    @GenThreatLabs
    Aug 7
    When was the last time you got rickrolled? 🪩🕺 We were starting to think malware authors had lost all sense of humor, but then we found this sample that runs whatever PowerShell command a Spotify playlist is named. And that playlist turns out to have rather refined taste,
  • @GenThreatLabs
    Gen Threat Labs
    @GenThreatLabs
    Aug 6
    Spotted a phishing campaign impersonating "Jochen Schweizer Corporate Solutions GmbH" — fake PDF with an RFP invitation → CAPTCHA → fake Microsoft login → credential harvest. Best part: the obfuscated JS on the phishing page uses comments straight from a BBQ menu: /*