ThreatChain Blog

Security research, threat analysis, and decentralized intelligence insights from our research team.

Research Malware May 22, 2026 8 min read

DDoSAgent Sample Detected: phantom.mpsl

Your security tools might have missed this one. DDoSAgent is actively targeting networks right now — here's what you need to know before it hits yours. Full IOCs, attack chain, and defensive guidance from ThreatChain Research.

Read More
Research Malware May 21, 2026 8 min read

AgentTesla Sample Detected: copia del pago anticipado.exe

That email attachment your coworker just opened? It's copying every password they've ever saved. Right now. Full IOCs, attack chain, and defensive guidance from ThreatChain Research.

Read More
Research Malware May 10, 2026 8 min read

QuasarRAT Sample Detected: 7z2600-x32.exe

It's open-source on GitHub. It's also on thousands of infected machines right now, giving attackers full remote control. Full IOCs, attack chain, and defensive guidance from ThreatChain Research.

Read More
Research Malware May 10, 2026 8 min read

Cobalt Strike Sample Detected: 申请项目同行评议意见反馈信.exe

Your security tools might have missed this one. Cobalt Strike is actively targeting networks right now — here's what you need to know before it hits yours. Full IOCs, attack chain, and defensive guidance from ThreatChain Research.

Read More
Research Malware May 09, 2026 8 min read

Vidar Sample Detected: file

That 'free software' download just exfiltrated every password, cookie, and autofill entry on your machine in under 5 seconds. Full IOCs, attack chain, and defensive guidance from ThreatChain Research.

Read More
Research Malware May 08, 2026 8 min read

AsyncRAT Sample Detected: Telegram (1).exe

Open-source. Free. And in the hands of thousands of attackers who use it to watch your every move through your own webcam. Full IOCs, attack chain, and defensive guidance from ThreatChain Research.

Read More
Research Malware May 08, 2026 8 min read

RemcosRAT Sample Detected: DHL Shipment Details.xls

For $58 on a hacking forum, anyone can buy full remote control of your computer. Camera, keyboard, files — everything. Full IOCs, attack chain, and defensive guidance from ThreatChain Research.

Read More
Research Malware May 07, 2026 8 min read

Amadey Sample Detected: file

It doesn't steal your data — it opens the door for everything else. Ransomware, stealers, miners. This loader delivers them all. Full IOCs, attack chain, and defensive guidance from ThreatChain Research.

Read More
Research Malware May 07, 2026 8 min read

NanoCore Sample Detected: ee88.exe

An attacker is reading your keystrokes, watching your screen, and downloading your files. The RAT that infected you cost $25. Full IOCs, attack chain, and defensive guidance from ThreatChain Research.

Read More
Research Malware May 06, 2026 8 min read

Formbook Sample Detected: Purchase Order 350088.exe

Someone on your team opened an Excel file 10 minutes ago. Their browser passwords, email credentials, and keystrokes are already being sent to a server in Eastern Europe. Full IOCs, attack chain, and defensive guidance from ThreatChain Research.

Read More
Research Malware May 05, 2026 8 min read

Mirai Sample Detected: luxzz.mpsl

Your home router might be attacking websites right now and you'd never know. Millions are already compromised. Full IOCs, attack chain, and defensive guidance from ThreatChain Research.

Read More
Research Malware May 05, 2026 8 min read

PhantomStealer Sample Detected: PO 283974863 -R0-S - 0908273.exe

Your security tools might have missed this one. PhantomStealer is actively targeting networks right now — here's what you need to know before it hits yours. Full IOCs, attack chain, and defensive guidance from ThreatChain Research.

Read More
Research Malware May 04, 2026 8 min read

XoriumStealer Sample Detected: file

Your security tools might have missed this one. XoriumStealer is actively targeting networks right now — here's what you need to know before it hits yours. Full IOCs, attack chain, and defensive guidance from ThreatChain Research.

Read More
Research Malware May 04, 2026 8 min read

GuLoader Sample Detected: Purchase Order.exe

Your security tools might have missed this one. GuLoader is actively targeting networks right now — here's what you need to know before it hits yours. Full IOCs, attack chain, and defensive guidance from ThreatChain Research.

Read More
Research Malware May 03, 2026 8 min read

RustyStealer Sample Detected: file

Your security tools might have missed this one. RustyStealer is actively targeting networks right now — here's what you need to know before it hits yours. Full IOCs, attack chain, and defensive guidance from ThreatChain Research.

Read More
Research Malware May 03, 2026 8 min read

Gafgyt Sample Detected: armv5l.SNOOPY

Your security tools might have missed this one. Gafgyt is actively targeting networks right now — here's what you need to know before it hits yours. Full IOCs, attack chain, and defensive guidance from ThreatChain Research.

Read More
Research Malware May 01, 2026 8 min read

LimeRAT Sample Detected: cec.co.com

Your security tools might have missed this one. LimeRAT is actively targeting networks right now — here's what you need to know before it hits yours. Full IOCs, attack chain, and defensive guidance from ThreatChain Research.

Read More
Research Malware May 01, 2026 8 min read

ValleyRAT Sample Detected: FlClash-0.8.92-amd64.exe

Your security tools might have missed this one. ValleyRAT is actively targeting networks right now — here's what you need to know before it hits yours. Full IOCs, attack chain, and defensive guidance from ThreatChain Research.

Read More
Research Malware April 30, 2026 8 min read

AgentTesla Sample Detected: Nota de credito A12345-045_20260403_pdf.scr.exe

That email attachment your coworker just opened? It's copying every password they've ever saved. Right now. Full IOCs, attack chain, and defensive guidance from ThreatChain Research.

Read More
Research Malware April 30, 2026 8 min read

NanoCore Sample Detected: u888.exe

An attacker is reading your keystrokes, watching your screen, and downloading your files. The RAT that infected you cost $25. Full IOCs, attack chain, and defensive guidance from ThreatChain Research.

Read More
Research Malware April 29, 2026 8 min read

CountLoader Sample Detected: cx-programmer 9.1 free download full.exe

Your security tools might have missed this one. CountLoader is actively targeting networks right now — here's what you need to know before it hits yours. Full IOCs, attack chain, and defensive guidance from ThreatChain Research.

Read More
Research Malware April 29, 2026 8 min read

ConnectWise Sample Detected: support.client.exe

Your security tools might have missed this one. ConnectWise is actively targeting networks right now — here's what you need to know before it hits yours. Full IOCs, attack chain, and defensive guidance from ThreatChain Research.

Read More
Research Malware April 28, 2026 8 min read

Mirai Sample Detected: arm64

Your home router might be attacking websites right now and you'd never know. Millions are already compromised. Full IOCs, attack chain, and defensive guidance from ThreatChain Research.

Read More
Research Malware April 28, 2026 8 min read

AsyncRAT Sample Detected: 8a87aae368cd9817f313ece0e4bb52568017c01e245b7883b03db4bb03d80a1a

Open-source. Free. And in the hands of thousands of attackers who use it to watch your every move through your own webcam. Full IOCs, attack chain, and defensive guidance from ThreatChain Research.

Read More
Research Malware April 27, 2026 8 min read

Smoke Loader Sample Detected: file

Your security tools might have missed this one. Smoke Loader is actively targeting networks right now — here's what you need to know before it hits yours. Full IOCs, attack chain, and defensive guidance from ThreatChain Research.

Read More
Research Malware April 27, 2026 8 min read

Vidar Sample Detected: file

That 'free software' download just exfiltrated every password, cookie, and autofill entry on your machine in under 5 seconds. Full IOCs, attack chain, and defensive guidance from ThreatChain Research.

Read More
Research Malware April 26, 2026 8 min read

Amadey Sample Detected: file

It doesn't steal your data — it opens the door for everything else. Ransomware, stealers, miners. This loader delivers them all. Full IOCs, attack chain, and defensive guidance from ThreatChain Research.

Read More
Research Malware April 26, 2026 8 min read

WeedHack Sample Detected: krypton.1.21.11 (2).jar

Your security tools might have missed this one. WeedHack is actively targeting networks right now — here's what you need to know before it hits yours. Full IOCs, attack chain, and defensive guidance from ThreatChain Research.

Read More
Research Malware April 25, 2026 8 min read

Formbook Sample Detected: 06EWFQ0K.ps1

Someone on your team opened an Excel file 10 minutes ago. Their browser passwords, email credentials, and keystrokes are already being sent to a server in Eastern Europe. Full IOCs, attack chain, and defensive guidance from ThreatChain Research.

Read More
Research Malware April 25, 2026 8 min read

RustyStealer Sample Detected: Setup.exe

Your security tools might have missed this one. RustyStealer is actively targeting networks right now — here's what you need to know before it hits yours. Full IOCs, attack chain, and defensive guidance from ThreatChain Research.

Read More
Research Malware April 24, 2026 8 min read

RemcosRAT Sample Detected: Purchase_Order_2455.JS

For $58 on a hacking forum, anyone can buy full remote control of your computer. Camera, keyboard, files — everything. Full IOCs, attack chain, and defensive guidance from ThreatChain Research.

Read More
Research Malware April 24, 2026 8 min read

SnappyClient Sample Detected: YRJKHYWK.msi

Your security tools might have missed this one. SnappyClient is actively targeting networks right now — here's what you need to know before it hits yours. Full IOCs, attack chain, and defensive guidance from ThreatChain Research.

Read More
Research Malware April 23, 2026 8 min read

CoinMiner Sample Detected: file

Your CPU is at 100% and your electric bill spiked. Someone is mining crypto on your machine and keeping the profit. Full IOCs, attack chain, and defensive guidance from ThreatChain Research.

Read More
Research Malware April 23, 2026 8 min read

Njrat Sample Detected: b649944f79f7f0e8a1c550f92190015ce473b8841f8c1.exe

Built in 2013. Still infecting machines in 2026. This RAT refuses to die because it still works. Full IOCs, attack chain, and defensive guidance from ThreatChain Research.

Read More
Research Malware April 22, 2026 8 min read

ConnectWise Sample Detected: ScreenConnect.ClientSetup.exe

Your security tools might have missed this one. ConnectWise is actively targeting networks right now — here's what you need to know before it hits yours. Full IOCs, attack chain, and defensive guidance from ThreatChain Research.

Read More
Research Malware April 22, 2026 8 min read

Gafgyt Sample Detected: SH4

Your security tools might have missed this one. Gafgyt is actively targeting networks right now — here's what you need to know before it hits yours. Full IOCs, attack chain, and defensive guidance from ThreatChain Research.

Read More
Research Malware April 21, 2026 8 min read

DarkComet Sample Detected: Microsoft.exe

Your security tools might have missed this one. DarkComet is actively targeting networks right now — here's what you need to know before it hits yours. Full IOCs, attack chain, and defensive guidance from ThreatChain Research.

Read More
Research Malware April 21, 2026 8 min read

Socks5Systemz Sample Detected: file

Your security tools might have missed this one. Socks5Systemz is actively targeting networks right now — here's what you need to know before it hits yours. Full IOCs, attack chain, and defensive guidance from ThreatChain Research.

Read More
Research Malware April 20, 2026 8 min read

Mirai Sample Detected: Space.x86_64

Your home router might be attacking websites right now and you'd never know. Millions are already compromised. Full IOCs, attack chain, and defensive guidance from ThreatChain Research.

Read More
DeFi Hacks Research April 20, 2026 6 min read

$292 Million Vanished in Hours. Then $9 Billion Ran for the Exit.

Attackers drained $292M in rsETH from Kelp DAO via a LayerZero bridge exploit, triggering $9B in outflows from Aave. Plain-English breakdown of how the bridge was broken and what it means if you hold any yield-bearing wrapper token.

Read More
Research Malware April 17, 2026 8 min read

ValleyRAT Sample Detected: 35300F285F5B7A573B38E1EFCD9230E2.exe

Your security tools might have missed this one. ValleyRAT is actively targeting networks right now — here's what you need to know before it hits yours. Full IOCs, attack chain, and defensive guidance from ThreatChain Research.

Read More
Research Malware April 17, 2026 8 min read

Gh0stRAT Sample Detected: lest-latest-0.12.4.exe

Your security tools might have missed this one. Gh0stRAT is actively targeting networks right now — here's what you need to know before it hits yours. Full IOCs, attack chain, and defensive guidance from ThreatChain Research.

Read More
Research Malware April 16, 2026 8 min read

Vidar Sample Detected: file

That 'free software' download just exfiltrated every password, cookie, and autofill entry on your machine in under 5 seconds. Full IOCs, attack chain, and defensive guidance from ThreatChain Research.

Read More
Research Malware April 16, 2026 8 min read

RemcosRAT Sample Detected: Preinterest.exe

For $58 on a hacking forum, anyone can buy full remote control of your computer. Camera, keyboard, files — everything. Full IOCs, attack chain, and defensive guidance from ThreatChain Research.

Read More
Research Malware April 15, 2026 8 min read

DattoRMM Sample Detected: TrueView.exe

Your security tools might have missed this one. DattoRMM is actively targeting networks right now — here's what you need to know before it hits yours. Full IOCs, attack chain, and defensive guidance from ThreatChain Research.

Read More
Research Malware April 15, 2026 8 min read

SantaStealer Sample Detected: file

Your security tools might have missed this one. SantaStealer is actively targeting networks right now — here's what you need to know before it hits yours. Full IOCs, attack chain, and defensive guidance from ThreatChain Research.

Read More
Research Malware April 14, 2026 8 min read

DiscordRAT Sample Detected: RedTiger-Tools-main-2.0.exe

Your security tools might have missed this one. DiscordRAT is actively targeting networks right now — here's what you need to know before it hits yours. Full IOCs, attack chain, and defensive guidance from ThreatChain Research.

Read More
Research Malware April 14, 2026 8 min read

Smoke Loader Sample Detected: file

Your security tools might have missed this one. Smoke Loader is actively targeting networks right now — here's what you need to know before it hits yours. Full IOCs, attack chain, and defensive guidance from ThreatChain Research.

Read More
Research Malware April 13, 2026 8 min read

RatonRAT Sample Detected: xxx.exe

Your security tools might have missed this one. RatonRAT is actively targeting networks right now — here's what you need to know before it hits yours. Full IOCs, attack chain, and defensive guidance from ThreatChain Research.

Read More
Research Malware April 13, 2026 8 min read

OffLoader Sample Detected: file

You downloaded one file. In the background, it silently installed three more programs you never asked for. Full IOCs, attack chain, and defensive guidance from ThreatChain Research.

Read More
Research Malware April 12, 2026 8 min read

SalatStealer Sample Detected: file

Your security tools might have missed this one. SalatStealer is actively targeting networks right now — here's what you need to know before it hits yours. Full IOCs, attack chain, and defensive guidance from ThreatChain Research.

Read More
Research Malware April 12, 2026 8 min read

RustyStealer Sample Detected: file

Your security tools might have missed this one. RustyStealer is actively targeting networks right now — here's what you need to know before it hits yours. Full IOCs, attack chain, and defensive guidance from ThreatChain Research.

Read More
Research Malware April 11, 2026 8 min read

Mirai Sample Detected: ciubuc_ppc

Your home router might be attacking websites right now and you'd never know. Millions are already compromised. Full IOCs, attack chain, and defensive guidance from ThreatChain Research.

Read More
Research Malware April 11, 2026 8 min read

Expiro Sample Detected: file

Your security tools might have missed this one. Expiro is actively targeting networks right now — here's what you need to know before it hits yours. Full IOCs, attack chain, and defensive guidance from ThreatChain Research.

Read More
Research Malware April 08, 2026 8 min read

CVE-2026-39337: Church Management Software Flaw Gives Attackers Complete Server Control

Your security tools might have missed this one. CVE-2026-39337 is actively targeting networks right now — here's what you need to know before it hits yours. Full IOCs, attack chain, and defensive guidance from ThreatChain Research.

Read More
Research Malware April 08, 2026 8 min read

AsyncRAT: The Silent Spy That Gives Attackers Full Control of Your Computer

Open-source. Free. And in the hands of thousands of attackers who use it to watch your every move through your own webcam. Full IOCs, attack chain, and defensive guidance from ThreatChain Research.

Read More
Research Malware April 07, 2026 8 min read

ACRStealer: The Hidden Threat Disguised as a Google Verification File

Your security tools might have missed this one. ACRStealer is actively targeting networks right now — here's what you need to know before it hits yours. Full IOCs, attack chain, and defensive guidance from ThreatChain Research.

Read More
Research Malware April 07, 2026 8 min read

CVE-2026-34208: JavaScript Sandbox Library Can't Keep Attackers Out

What CVE-2026-34208 is, how it works, and how to defend against it. Full IOCs, attack chain, and defensive guidance from ThreatChain Research.

Read More
Research Malware April 07, 2026 8 min read

That Fake Purchase Order in Your Inbox? It Might Be Formbook Stealing Every Keystroke You Type

A commodity stealer hiding in phishing attachments. Here's the full picture. Full IOCs, attack chain, and defensive guidance from ThreatChain Research.

Read More
Research Malware April 06, 2026 8 min read

Claude Code Source Leak: How One Packaging Mistake Created a Hacker Feeding Frenzy

What Supply Chain Attack is, how it works, and how to defend against it. Full IOCs, attack chain, and defensive guidance from ThreatChain Research.

Read More
Research Malware April 06, 2026 8 min read

Vidar: The Silent Thief Hiding Inside That Free Software Download

An info-stealer that doubles as a loader. Full breakdown inside. Full IOCs, attack chain, and defensive guidance from ThreatChain Research.

Read More
Research Malware April 06, 2026 8 min read

That "Payment Wire" Email Attachment? It's a Trojan Wearing Trusted Software as a Disguise

What ConnectWise is, how it works, and how to defend against it. Full IOCs, attack chain, and defensive guidance from ThreatChain Research.

Read More
Research Malware April 06, 2026 8 min read

DCRat: The Cheap, Dangerous Malware That Lets Anyone Spy on Your Computer for $5

A modular RAT that's been around for years and keeps evolving. Latest tricks inside. Full IOCs, attack chain, and defensive guidance from ThreatChain Research.

Read More
Research Malware April 06, 2026 8 min read

RedLine Stealer: The Password Thief Hiding in a 98-Kilobyte File

The most prolific credential stealer of the year. Here's how to catch it. Full IOCs, attack chain, and defensive guidance from ThreatChain Research.

Read More
Research Malware April 05, 2026 8 min read

Your Computer Could Be Mining Cryptocurrency for Strangers Right Now — Here's How to Tell

Cryptojacking malware quietly burning your electricity and CPU. Here's how to detect it. Full IOCs, attack chain, and defensive guidance from ThreatChain Research.

Read More
WEEKLY REPORT Research April 05, 2026 8 min read

ThreatChain Weekly: Chrome Zero-Day Hits KEV, WordPress Plugins Under Siege, and 4.4M Threats in 7 Days — Week of April 5, 2026

ThreatChain's weekly roundup of the cybersecurity landscape. Critical CVEs, emerging malware trends, and what to patch this week.

Read More
WEEKLY REPORT Research April 05, 2026 8 min read

ThreatChain Weekly: Chrome Zero-Day Hits KEV, WordPress Plugins Under Siege, and 2.8M New Phishing Domains — Week of April 5, 2026

ThreatChain's weekly roundup of the cybersecurity landscape. Critical CVEs, emerging malware trends, and what to patch this week.

Read More
Research Malware April 05, 2026 8 min read

Why Your Router Might Be Quietly Attacking Websites Right Now — And You'd Never Know

In-depth analysis of the Mirai malware family from the ThreatChain research team. Full IOCs, attack chain breakdown, and defensive recommendations.

Read More
Research Malware April 04, 2026 8 min read

Inside OffLoader: A GCleaner-Dropped Payload Slipping Past 95% of AV Engines

In-depth analysis of the OffLoader malware family from the ThreatChain research team. Full IOCs, attack chain breakdown, and defensive recommendations.

Read More
Breaking Malware April 4, 2026 8 min read

Boatnet: Inside the LZRD Mirai Variant Flooding IoT Devices Right Now

A new wave of Mirai-based malware is actively compromising routers, cameras, and DVRs worldwide. Fresh samples uploaded to MalwareBazaar today target ARM and x86 IoT devices via CVE-2024-6047 command injection in GeoVision hardware. Full IOCs, attack chain analysis, and defensive recommendations inside.

Read More
Malware April 1, 2026 9 min read

How to Check If a File Is Malware: Free Methods That Actually Work (2026)

Downloaded a suspicious file? Before you open it, here is exactly how to check whether it is malicious using free hash-based detection, VirusTotal, and ThreatChain's decentralized threat database of 2.6 million known threats.

Read More
Crypto Scams March 28, 2026 8 min read

Is This Crypto Wallet a Scam? How to Check Any Wallet Address (2026)

Before you send crypto to any address, learn how to verify it is legitimate. We cover wallet scam tactics, red flags to spot, and how to use ThreatChain's database of 2,530 known scam wallets to protect yourself.

Read More
Hacks & Exploits March 22, 2026 11 min read

The Biggest Crypto Hacks of 2026 (So Far): What Happened and How to Stay Safe

From the Bybit breach to the Radiant Capital exploit, we break down the largest crypto hacks of 2025-2026, explain how each happened in plain language, and show you how to check if your funds were affected.

Read More
Education March 15, 2026 10 min read

What Is Threat Intelligence? A Beginner's Guide for 2026

Threat intelligence is how organizations stay ahead of attackers. This guide explains the four types, where data comes from, and why decentralized community-driven platforms like ThreatChain are changing the game.

Read More
Earn March 10, 2026 8 min read

How to Earn Crypto Doing Security Research: $THREAT Token Guide

Security researchers can now earn real crypto by submitting threat intelligence. Learn how the $THREAT token works, what you earn per submission, and how to become a validator staking 10K tokens.

Read More
Free: 5 scans + 100 lookups/day | Pro: $4.99/day or $96.99/mo Upgrade