Sign in

Netskope Threat Labs

@netskopethreatlabs.com
11 followers 0 following 67 posts

Official account for Netskope Threat Labs. Delivering actionable intelligence, research, and real-time insights surfaced from the Netskope platform to help defenders stay ahead of evolving cloud and web threats. netskope.com/netskope-threat-labs

PostsRepliesMedia
Netskope Threat Labs @netskopethreatlabs.com · 02/10/2026
Stat of the week: DLP events flagging sensitive data exposed publicly in SaaS apps rose 6% week over week. The exposure spans cloud storage, collaboration, webmail, dev tools, CRM, and GenAI apps, where a single public link makes internal data reachable by anyone.
000
Netskope Threat Labs @netskopethreatlabs.com · 01/10/2026
Vini Egerland has been tracking the Underground campaign: A crypto-drain operation drains victims' exchange accounts. An injected Vidar-class stealer drives Chrome/Edge from rotating fronted /api/machine gates. It has already stolen ~$100K on-chain.
110
Netskope Threat Labs @netskopethreatlabs.com · 30/09/2026
Unruy click-fraud infrastructure picked up new redirect domains. go-us8.gobridges[.]xyz and go-us8.linkhop[.]click, registered the same day in July at the same registrar, joined established go-us8.* hosts on 74.50.88[.]154. Three Unruy downloader samples communicate with that IP.
110
Netskope Threat Labs @netskopethreatlabs.com · 28/09/2026
Stat of the week: 295 distinct domains tied to command and control, and malware distribution, turned up in enterprise traffic Netskope saw this week, down 12% from 335 the week before. Hundreds of live C2 domains a week is the steady state. #C2 #threatintel
120
Netskope Threat Labs @netskopethreatlabs.com · 24/09/2026
A fake security locker has been circulating using Google Ads to lure victims into clicking. We have seen clicks across more than 619 organization from 250 campaigns, 284 sites hosting the ads, and 457 domains hosting the content. www.netskope.com/blog/a-fake-...
010
Netskope Threat Labs @netskopethreatlabs.com · 23/09/2026
ClearFake payload delivery endpoint in use within a day of its registration. Delivery: rehearsal-b[.]com/4qX0LB/tm/oPpE/. ClearFake reads its loader config from BNB Smart Chain contract storage (EtherHiding)
010
Netskope Threat Labs @netskopethreatlabs.com · 17/09/2026
Stat of the week: 85.6% of this week's prompt injection alerts related to Anthropic's Claude, out of 18 other apps.
110
Netskope Threat Labs @netskopethreatlabs.com · 15/09/2026
ClickFix lures are running off a .beer TLD cluster. aleverifocation[.]beer went into use a day after registration, taking Win+R paste victim checkins at /api.php?s=<token>&_v=<build>. Its IP 178.16.52[.]101 hosts 10+ fake fingerprint/verification/ID pages.
110
Netskope Threat Labs @netskopethreatlabs.com · 10/09/2026
Unruy/Cycler click fraud is running C2 inside AWS: Amazon Registrar, EC2, Route 53, CloudFront fronting the payload host. euob.northwavepoint[.]com (CloudFront, JS payloads) and obseu.northwavepoint[.]com (EC2, /ct click tracker). JS payloads are served only under /sxp/i/<md5>.js.
110
Netskope Threat Labs @netskopethreatlabs.com · 07/09/2026
Stat of the week: 85% of malware-flagged package downloads Netskope Threat Labs saw last week came from Chrome extensions (crx). Most package supply chain monitoring stops where most of the volume is. #supplychain
110
Netskope Threat Labs @netskopethreatlabs.com · 03/09/2026
John Carlo Marquez's latest blog details a growing trend of more than 5,400 compromised websites leveraging the EtherHiding technique and a new campaign that abuses WebRTC to create a covert C2 channel. #EtherHiding #Malware www.netskope.com/blog/malware...
netskope.com
Malware on the Blockchain: An Ongoing Campaign's New WebRTC Twist
EtherHiding, a technique that uses blockchain smart contracts as takedown-resistant payload storage, has been seen across more than 5,400 compromised
010
Netskope Threat Labs @netskopethreatlabs.com · 02/09/2026
Jan Michael Alcantara has been tracking NodeStealer for years. The latest variant he analyzed received an AI-assisted upgrade to include more spyware capabilities #malware www.netskope.com/blog/python-...
netskope.com
Python NodeStealer: AI-Assisted to Full Spyware
Since 2023, Netskope Threat Labs has been tracking the Python-based NodeStealer, an infostealer targeting sensitive browser data and Facebook user, and
010
Netskope Threat Labs @netskopethreatlabs.com · 02/09/2026
Domains named after plant and place: tamarisknave[.]co, sycamoreitinerary[.]co, yarrowalcove[.]net. Eight of them sit on one Hetzner VPS, each SOA record pointing at the same Proton Mail address. The late-July .top wave rotated off, .net and .co replaced it.
110
Netskope Threat Labs @netskopethreatlabs.com · 31/08/2026
Malware is resolving its C2 through the Polygon blockchain as of 2 days ago. An eth_call to a verified contract named extractor returns the domain vg5sgxv[.]lol from getServerURL(), ABI-encoded.
curl command pipes into python to decode and extract command and control domain.
110
Netskope Threat Labs @netskopethreatlabs.com · 31/08/2026
A WordPress mass-compromise campaign runs a malicious Service Worker that strips CSP and resolves its ClickFix payload from a Base smart contract. The 9-step chain decodes to the Amatera stealer. See full blog post: www.netskope.com/blog/etherhi...
netskope.com
EtherHiding in the Browser: ClickFix Chain Ends in Amatera
Netskope Threat Labs has been tracking a WordPress mass-compromise campaign affecting hundreds of sites. On each one, a rogue must-use plugin registers a
110
Netskope Threat Labs @netskopethreatlabs.com · 18/08/2026
EVM, Solana, and TON all use the same blockchain approach to dead drop resolvers. Netskope's Vinicius Egerland breaks down how it works and what you can do about it. www.netskope.com/blog/blockch...
netskope.com
Blockchain Dead Drop Resolvers Explained
A dead drop resolver (DDR) is any mechanism where malware fetches its command and control (C2) address at runtime from a third-party,
020
Netskope Threat Labs @netskopethreatlabs.com · 18/08/2026
Netskope observed outbound traffic consistent with malware resolving C2 via BNB Smart Chain contract storage (EtherHiding). The read goes to a public BSC testnet RPC node, so there is no actor domain to blocklist, and testnet contracts draw less scrutiny than mainnet.
210
Netskope Threat Labs @netskopethreatlabs.com · 14/08/2026
Stat of the week: 15 distinct cloud apps carried C2 traffic in Netskope telemetry this week, up from 13 last week. Ten are mainstream collaboration and productivity SaaS: Google Drive, OneDrive, SharePoint, Gmail, JIRA, Salesforce. New to the list this week: ChatGPT. #C2 #SaaS
130
Netskope Threat Labs @netskopethreatlabs.com · 11/08/2026
The Chrome extension "AI Sidebar with DeepSeek AI" was removed from the Chrome Web Store in Jan 26 for stealing AI conversation content. In July 26 it resumed delivering updates: it monetizes its install base by affiliate link and suppresses navigation to ChatGPT. www.netskope.com/blog/ai-side...
netskope.com
AI Sidebar Extension Monetizes Its Own Updates
The Chrome extension "AI Sidebar with DeepSeek AI" that Google removed from the Chrome Web Store in January 2026 for stealing AI conversation content
110
Netskope Threat Labs @netskopethreatlabs.com · 07/08/2026
Stat of the week: Netskope saw 4,995 distinct SHA-256s for one JS malware family, up 47% WoW from 3,393. JS:Trojan.Cryxos.16527, obfuscated JS with browser redirect lures, is repacked so often that nearly every hit is a new hash. Hash-based blocking decays by the day. #malware #JavaScript
110
Netskope Threat Labs @netskopethreatlabs.com · 04/08/2026
Shai Hulud: A poisoned npm package wave hardcodes no C2. The stealer issues an eth_call to an Ethereum smart contract that returns the current exfiltration host at runtime.
210
Netskope Threat Labs @netskopethreatlabs.com · 04/08/2026
A PDF factory has parked 12,700+ FakeCaptcha lures on Webflow's CDN, indexed by Google. The blog post provides a deep dive into a long-lived TDS that sells the qualifying clicks to several buyers, including the Legion Loader malware downloader. www.netskope.com/blog/fake-ca...
netskope.com
Fake CAPTCHA, Real Business: Traffic Distribution for Hire
A single PDF factory has stamped out more than 12,700 structurally similar FakeCaptcha documents and parked them on Webflow's content delivery network,
111
Netskope Threat Labs @netskopethreatlabs.com · 31/07/2026
Tycoon2FA puts a Cloudflare Turnstile bot check in front of fake Microsoft OAuth authorize endpoints, so scanners stop at the gate while human targets carry on to credential and session token capture. Netskope detections of the pattern rose 78% week over week. #phishing #AiTM
Image for draft 3mrwu7j5v4c2y
110
Netskope Threat Labs @netskopethreatlabs.com · 29/07/2026
Roughly 140 compromised legitimate websites, mostly Spanish, French and Italian small-business and regional media, were serving an injected fake googletagmanager.js, reportedly presenting a ClickFix lure
110
Netskope Threat Labs @netskopethreatlabs.com · 29/07/2026
heatherkiln[.]top registered at ~08:00 UTC was already being requested from hundreds of enterprise endpoints that same day, then went quiet 35 hours later. Netskope observed /router/admin-bundle.js, named to pass as a router admin UI bundle.
110
Netskope Threat Labs @netskopethreatlabs.com · 24/07/2026
TroyDen's Lure Factory continues to exploit AI hype. Lures trick engineers through fake "Portable Offline LLM" repo that - this again delivers a Prometheus Lua payload. Actor split the LuaJIT runtime into stub and DLL, evading the PE rule. @joshnck traces C2 to a Polygon dead drop.
Image for draft 3mrf4mst5ys2q
110
Netskope Threat Labs @netskopethreatlabs.com · 23/07/2026
Active phishing wave impersonating Polish marketplaces Allegro and OLX. The multi-brand kit redirects automated scanners to the real site and serves pixel-perfect login clones to human visitors. ~600 DGA-style .lol domains observed. #phishing
Image for draft 3mrcuy3a7ws2t
110
Netskope Threat Labs @netskopethreatlabs.com · 22/07/2026
Taking a look back at the many malicious World Cup scams, including fake FIFA job posting phishing pages. www.netskope.com/blog/world-c...
010
Netskope Threat Labs @netskopethreatlabs.com · 17/06/2026
The latest ClickFix attack targeting macOS users bypasses OS-level controls meant to mitigate such threats and deploys an infostealer. www.netskope.com/blog/macos-c...
010
Netskope Threat Labs @netskopethreatlabs.com · 16/06/2026
We have been tracking a steady stream of malicious nvim plugins of the past 90 days, all exhibiting the same behavior: - Hosted on GitHub - Contain a renamed LuaJIT interpreter - Prometheus-obfuscated Lua script High-overlap payloads suggests a commodity threat we will continue to see.
110
Netskope Threat Labs @netskopethreatlabs.com · 11/06/2026
AI Agents and the OAuth trust problem: How the authorization model already fails at scale, why AI agents make it exponentially worse, and what enterprises can do about it today. www.netskope.com/blog/ai-agen...
netskope.com
AI Agents and the OAuth Trust Problem at Scale
At Infosecurity Europe 2026, Netskope Threat Labs presented research on how OAuth authorization abuse has evolved from third-party supply chain breaches
010
Netskope Threat Labs @netskopethreatlabs.com · 08/06/2026
Europe Threat Report 2026 - Regulated data drives risk - 59% of violation involve regulated data - AI adoption is near-universal, but governance lags, with 43% still using personal AI apps - Threats on trusted platforms - GitHub and OneDrive remain popular vectors www.netskope.com/resources/th...
netskope.com
Netskope Threat Labs Report: Europe 2026
Learn how organizations in Europe are tackling the evolving cybersecurity landscape, including malware, AI, and data security.
010
Netskope Threat Labs @netskopethreatlabs.com · 14/05/2026
The latest round of Shai-Hulud npm worms hit tanstack/history and more than 50 other packages. www.netskope.com/blog/shai-hu...
netskope.com
Shai-Hulud-Style npm Worm Hits @tanstack
The npm packages @tanstack/history (1.161.9, 1.161.12) and more than 50 other packages across the @tanstack, @mistralai, @uipath, @squawk, and safe-action
000