Sign in

Netskope

@netskope.com
34 followers 8 following 36 posts

Netskope, a leader in modern security and networking, addresses the needs of both security and networking teams by providing optimized access and real-time, context-based security for people, devices, and data anywhere they go. www.netskope.com

PostsRepliesMedia
Netskope @netskope.com · 17/06/2026
Netskope Threat Labs discovered a new ClickFix campaign targeting macOS users. This latest campaign is more sophisticated than the last one and built to bypass the OS-level controls meant to stop it. Know what to look for: www.netskope.com/blog/macos-c...
netskope.com
macOS ClickFix Lures Deploy AppleScript Stealer & Persistent RAT
In April 2026, Netskope Threat Labs reported a ClickFix campaign delivering an AppleScript-based infostealer to macOS users, pilfering sensitive data
010
Netskope @netskope.com · 01/05/2026
The Intercom TypeScript Library intercom-client@7.0.4 has been compromised and uses a classic drop-and-execute attack pattern to run an infostealer that harvests GitHub Credentials. ⬇️ Read the analysis to learn how it works and get IOCs: www.netskope.com/blog/shai-hu...
netskope.com
Shai-Hulud resurfaces: intercom-client@7.0.4 harvesting Github credentials
Summary The Intercom TypeScript Library intercom-client@7.0.4 (published at 2026-04-30 at 14:41:04.098Z) has been compromised and uses a classic
020
Netskope @netskope.com · 06/04/2026
Netskope Threat Labs tracks a new ClickFix campaign that delivers a NodeJS-based infostealer to Windows users via malicious MSI installers. Read the full breakdown of the campaign and get a rare look into the attacker’s management interface and backend API logic. www.netskope.com/blog/from-cl...
netskope.com
From ClickFix to MaaS: Exposing a Modular Windows RAT and Its Admin Panel
Summary Netskope Threat Labs is tracking a new ClickFix campaign that targets Windows users. ClickFix became a prominent delivery vector in early 2025 for
010
Netskope @netskope.com · 03/03/2026
🏥 The 2026 Netskope Threat Labs Healthcare report reveals that while genAI adoption is increasing across the healthcare sector, regulated data exposure remains the defining risk shaping healthcare security strategies. More key findings ⏬ www.netskope.com/resources/th...
netskope.com
Threat Labs Report: Healthcare 2026
Learn how organizations in the Healthcare sector are tackling the evolving cybersecurity landscape, including malware, genAI, and data security.
000
Netskope @netskope.com · 12/02/2026
Netskope Threat Labs is monitoring an active phishing campaign that exploits the high-frequency nature of virtual meetings. Get a breakdown of the lures attackers are using and the payload in our latest blog: www.netskope.com/blog/attacke...
netskope.com
Attackers Weaponize Signed RMM Tools via Zoom, Meet, & Teams Lures
Summary Netskope Threat Labs is tracking several phishing campaigns that weaponize fake meeting invites for various video conference applications,
010
Netskope @netskope.com · 06/02/2026
Netskope Threat Labs identified a new campaign where malicious Bing ads are redirecting users to tech support scams. Read our latest blog for key findings and tips for avoiding these scams. www.netskope.com/blog/malicio...
netskope.com
Malicious Bing Ads Lead to Widespread Azure Tech Support Scams
Summary Starting on February 2 at around 16:00 UTC, Netskope Threat Labs was alerted to a spike of users across 48 different organizations clicking on
010
Netskope @netskope.com · 03/02/2026
🇯🇵 The 2026 Netskope Threat Labs Japan report explores recent trends in the adoption and governance of generative AI applications, enterprise AI platforms, API usage, cloud app activity, and data policy violations across Japan. Read the report: www.netskope.com/resources/th...
netskope.com
Netskope Threat Labs Report: Japan 2026
Learn how organizations in the Japan region are tackling the evolving cybersecurity landscape, including malware, genAI, and data security.
030
Netskope @netskope.com · 06/01/2026
The Netskope Cloud and Threat Report: 2026 is out. Take a look back at the most significant trends of 2025 and get a preview of the evolving threat landscape for 2026. www.netskope.com/resources/cl...
netskope.com
Cloud and Threat Report: 2026
Learn how organizations are tackling the evolving cybersecurity landscape, including malware, genAI, AI Agents, and data security.
010
Netskope @netskope.com · 23/10/2025
The new, open-source RedTiger infostealer has recently emerged in the wild, primarily targeting victims’ Discord accounts, Roblox credentials, browser data , and cryptocurrency wallet files. Get Netskope Threat Labs' analysis of RedTiger: www.netskope.com/blog/redtige...
netskope.com
RedTiger: New Red Teaming Tool in the Wild Targeting Gamers and Discord Accounts
Summary Gamers are a hot target for infostealers these days. This blog post is the second we have published this month about an infostealer targeting
010
Netskope @netskope.com · 22/10/2025
😱 A creeper just snuck into your storage room! 😱 Netskope Threat Labs discovered a new, multi-function Python RAT targeting gamers via Minecraft. ⛏️ Mine the full analysis: www.netskope.com/blog/new-pyt...
netskope.com
New Python RAT Targets Gamers via Minecraft
Summary During threat hunting activities, Netskope discovered a new, multi-function Python RAT that leverages the Telegram Bot API as a command and
010
Netskope @netskope.com · 08/08/2025
Netskope Threat Labs released a new open-source tool that detects supply chain attacks. Learn how BEAM (Behavioral Evaluation of Application Metrics) works and how to get access to this new tool. www.netskope.com/blog/netskop...
netskope.com
Netskope BEAM: Open Source Detector for Supply Chain Compromise
Netskope Threat Labs is pleased to announce the release of a new open-source tool that detects supply chain attacks. Our new tool, Behavioral Evaluation
010
Netskope @netskope.com · 05/08/2025
New Cloud and Threat Report from Netskope Threat Labs dives deep into Shadow AI and Agentic AI, offering crucial insights to help organizations shed light on the shadows along the way. Read the report: www.netskope.com/resources/re...
netskope.com
Cloud and Threat Report: Shadow AI and Agentic AI 2025
GenAI adoption is surging, bringing new SaaS apps, genAI platforms, and on-premises AI tools and agents. Uncover shadow AI and mitigate risks with this report.
010
Netskope @netskope.com · 10/06/2025
🤔 To block or not to block Grok? For 29% of enterprises, there is no question. Read Netskope Threat Labs' latest blog post on Grok’s rise in popularity, how organizations have responded, and recommendations for organizations looking to limit its use. www.netskope.com/blog/to-grok...
netskope.com
To Grok or Not To Grok: For 29% of Enterprises...There Is No Question
Grok is a chatbot developed by Elon Musk’s xAI. It was initially released to select individuals in November 2023 and became generally available to all X
010
Netskope @netskope.com · 02/06/2025
🚨 New Phishing Alert 🚨 Scammers are targeting Navy Federal Credit Union customers using Glitch-hosted pages, Telegram, and fake CAPTCHAs. Read the full analysis from Netskope Threat Labs: www.netskope.com/blog/glitch-...
netskope.com
Glitch-hosted Phishing Uses Telegram & Fake CAPTCHAs to Target Navy Federal Credit Union Customers
Summary From January to April 2025, Netskope Threat Labs tracked a three-fold increase in traffic to phishing pages created on the Glitch platform. These
010
Netskope @netskope.com · 30/05/2025
Don't get caught in Scattered Spider's web! 🕸️ Our latest blog breaks down how this financially motivated adversary group's TTPs and shares recommendations for Netskope customers. www.netskope.com/blog/netskop...
netskope.com
Netskope Threat Coverage: Scattered Spider
The adversary group commonly referred to as Scattered Spider is also tracked as UNC3944, Muddled Libra, Octo Tempest, Starfraud, Scatter Swine, 0ktapus,
010
Netskope @netskope.com · 28/05/2025
⚠️ Think twice before clicking on that dream job offer. New PureHVNC RAT campaign is preying on job seekers with fake offers from fashion and beauty brands. Get details on the infection chain and the methods used to lure victims and deliver the PureHVNC RAT. www.netskope.com/blog/purehvn...
netskope.com
PureHVNC RAT Using Fake High-level Job Offers from Fashion and Beauty Brands
Summary In recent months, the Netskope Threat Labs team has observed several different campaigns delivering the PureHVNC RAT and its plugins. In 2024, the
010
Netskope @netskope.com · 27/05/2025
🌍 The 2025 Netskope Threat Labs Europe report analyzes 3 major cybersecurity risk trends affecting organizations across Europe: 1️⃣ How malware is being distributed 2️⃣ The growing adoption of genAI tools 3️⃣ Rising data policy violations Read the report: www.netskope.com/resources/th...
netskope.com
Threat Labs Report: Europe 2025
Gain insights into how organizations in Europe are addressing evolving cybersecurity risks, including malware distribution, genAI, and data security.
010
Netskope @netskope.com · 07/05/2025
🚨 Netskope Threat Labs has uncovered new “DOGE Big Balls” ransomware tools in the wild. Get a detailed analysis of the payloads we found during our investigation. www.netskope.com/blog/new-dog...
netskope.com
New DOGE Big Balls Ransomware Tools in the Wild
Summary During the Netskope Threat Labs hunting activities, we came across a payload that led us to a multi-stage chain involving several custom
001
Netskope @netskope.com · 04/04/2025
Netskope Threat Labs discovered a new drive-by download campaign abusing fake CAPTCHA and CloudFlare Turnstile to deliver LegionLoader payload. Get a detailed overview of the entire infection chain. www.netskope.com/blog/new-eva...
netskope.com
New Evasive Campaign Delivers LegionLoader via Fake CAPTCHA & CloudFlare Turnstile
Starting February 2025, Netskope Threat Labs has tracked and reported on multiple phishing and malware campaigns targeting victims searching for PDF
010
Netskope @netskope.com · 26/03/2025
🚨 New Netskope Threat Labs research reveals a 30x increase in data sent to #genAI apps by enterprise users in the last year, increasing volume of sensitive data exposure. Read the 2025 Generative AI Cloud and Threat Report for top trends: www.netskope.com/netskope-thr...
netskope.com
Cloud and Threat Report - Generative AI 2025
GenAI adoption soars, but security risks rise. Discover top trends & effective controls in our 2025 Generative AI Cloud & Threat Report.
040
Netskope @netskope.com · 21/03/2025
[3/3] hxxps://user.fm/files/v2-a519782c0795bd8697c4a39edbbac1c5/Demand hxxps://user.fm/files/v2-6a29a73ac0bc7a49c5808920871a218d/Letter hxxps://user.fm/files/v2-6a29a73ac0bc7a49c5808920871a218d/Letter%20of%20Demand.HTML hxxps://morganholdinged.com/newyear5.php
020
Netskope @netskope.com · 21/03/2025
[2/3] IoCs: 76f1f4b59819576fc7f30f040ccbbc8f 563c09471c7ace59cd87a1f0338adfe3 hxxps://user.fm/files/v2-a519782c0795bd8697c4a39edbbac1c5/Demand%20Letter.HTML
110
Netskope @netskope.com · 21/03/2025
[1/3] Netskope Threat Labs observed multiple phishing pages being sent via Fastmail. The pages are tricking victims to log into a fake Office 365 page in order to access a fake payment document. Once the victim insert the credentials and press "View Payment" the credentials are sent to the attacker.
110
Netskope @netskope.com · 11/03/2025
Netskope Threat Labs analyzes Elysium, a variant of the Ghost (Cring) ransomware family, demonstrating how it works and how it encrypts the affected systems. www.netskope.com/blog/analyzi...
netskope.com
Analyzing Elysium, a Variant of the Ghost (Cring) Ransomware Family
Summary In February 2025, the Federal Bureau of Investigation (FBI), Cybersecurity and Infrastructure Security Agency (CISA), and the Multi-State
010
Netskope @netskope.com · 06/03/2025
🏦 Read the new Netskope Threat Labs Report for strategic, actionable intelligence on the most significant #cybersecurity risks that financial services organizations face and get recommendations on how to protect against these threats. www.netskope.com/netskope-thr...
netskope.com
Netskope Threat Labs Report: Financial Services 2025
Gain insights into how organizations in financial services are addressing evolving cybersecurity risks, including social engineering, personal app, and generative AI risk.
010
Netskope @netskope.com · 27/02/2025
Netskope Threat Labs found that attackers have been distributing malicious PDFs with fake CAPTCHAs across 260+ domains and 4,000+ keywords to steal credit card data and deliver Lumma Stealer malware. Get the details: www.netskope.com/blog/fake-ca...
netskope.com
Fake CAPTCHAs, Malicious PDFs, SEO Traps Leveraged for User Manual Searches
Summary On February 12, 2025, Netskope Threat Labs reported a widespread phishing campaign using fake CAPTCHA images via Webflow CDN to trick victims
010
Netskope @netskope.com · 14/02/2025
Telegram is being abused as command and control (C2) channel for a new Golang backdoor. Get details on the malware features and how it interacts with Telegram to receive commands and send results to it. www.netskope.com/blog/telegra...
netskope.com
Telegram Abused as C2 Channel for New Golang Backdoor
Summary As part of Netskope Threat Labs hunting activities, we came across an IoC being shared by other researchers and decided to take a closer look at
000
Netskope @netskope.com · 12/02/2025
🚨 New widespread phishing campaign abuses Webflow, SEO, and fake CAPTCHAs to steal credit card information and commit financial fraud. Get the analysis from Netskope Threat Labs www.netskope.com/blog/new-phi... #ThreatIntel #ThreatResearch #cybersecurity
netskope.com
New Phishing Campaign Abuses Webflow, SEO, and Fake CAPTCHAs
Summary Netskope Threat Labs is tracking a widespread phishing campaign affecting hundreds of Netskope customers and thousands of users. The campaign aims
000
Netskope @netskope.com · 03/02/2025
🧵 [2/2] IoC: bestoflifeyou[.]duckdns[.]org #phishing #infosec #threatintel
000
Netskope @netskope.com · 03/02/2025
🧵 [1/2] Netskope Threat Labs observed a Duck DNS URL used to host a fake CAPTCHA page that redirects to a website disguised as Orange, a french Telecom company. The page asks for Orange user's credentials and contains a malicious JS script to exfiltrate the inserted data via Telegram API. #phishing
120
Netskope @netskope.com · 29/01/2025
New Netskope Threat Labs Report on organizations operating in Canada shows 3.3x year-over-year increase in #GenAI app users, causing a proportional rise in the amount of sensitive data sent to genAI apps. More on the top cyber risks facing organizations in Canada: www.netskope.com/netskope-thr...
netskope.com
Netskope Threat Labs Report: Canada 2025
Gain insights into how organizations in Canada are addressing evolving cybersecurity risks, including social engineering, personal app, and generative AI risk.
000
Netskope @netskope.com · 23/01/2025
🚨 Netskope Threat Labs observed a new malware campaign using fake CAPTCHAs to deliver Lumma Stealer. Get the details on the latest campaign and the evasion techniques targeting Windows users worldwide. www.netskope.com/blog/lumma-s...
netskope.com
Lumma Stealer: Fake CAPTCHAs & New Techniques to Evade Detection
Summary In January, Netskope Threat Labs observed a new malware campaign using fake CAPTCHAs to deliver Lumma Stealer. Lumma is a malware that works in
010
Netskope @netskope.com · 14/01/2025
The first Security Visionaries episode of 2025 kicks off with a conversation with Ben Morris, Group Head of Cyber Security for @worldrugby.bsky.social, about the intersection between cyber and physical security when it comes to major events. 🎧 Listen: www.netskope.com/resources/po...
000
Netskope @netskope.com · 07/01/2025
🆕 Netskope Cloud and Threat Report shows phishing attempts are increasingly successful, with enterprise employees falling victim nearly 3X more in 2024 than in 2023. Get the latest research on risks organizations face and the strategies they use to manage risks. www.netskope.com/netskope-thr...
netskope.com
Cloud and Threat Report - January 2025
Gain insights into how organizations manage evolving risks, including social engineering risk, personal app risk, generative AI risk, and adversarial risk.
000
Netskope @netskope.com · 18/12/2024
In this episode of the Security Visionaries podcast, host Max Havey and guest @rcanzanese.bsky.social, Director of Netskope Threat Labs, dive into threat trends from the past year, including AI-enabled threats, deepfakes, and nation-state attacks. 🎧 Listen now: www.netskope.com/resources/po...
041
Netskope @netskope.com · 13/12/2024
⚠️ Netskope discovers side-loaded #backdoor targeting Thai officials. Get an analysis of the infection chain and dive deep into the backdoor we've dubbed "Yokai." www.netskope.com/blog/new-yok... #ThreatResearch #cybersecurity
netskope.com
New Yokai Side-loaded Backdoor Targets Thai Officials
Summary DLL side-loading is a popular technique used by threat actors to execute malicious payloads under the umbrella of a benign, usually legitimate,
020