Sign in

Netskope Threat Labs

@threatlabs.netskope.com
11 followers 0 following 68 posts

Official account for Netskope Threat Labs. Delivering actionable intelligence, research, and real-time insights surfaced from the Netskope platform to help defenders stay ahead of evolving cloud and web threats.

PostsRepliesMedia
Netskope Threat Labs @threatlabs.netskope.com · 11h
🎉 Vini Egerland, Threat Researcher at @threatlabs.netskope.com, is joining BSides Barcelona 2026 with: “Hunting Blockchain Dead-Drop Resolvers in Enterprise Traffic.” See full schedule: bsides.barcelona/schedule
010
Netskope Threat Labs @threatlabs.netskope.com · 02/10/2026
Stat of the week: DLP events flagging sensitive data exposed publicly in SaaS apps rose 6% week over week. The exposure spans cloud storage, collaboration, webmail, dev tools, CRM, and GenAI apps, where a single public link makes internal data reachable by anyone.
000
Netskope Threat Labs @threatlabs.netskope.com · 01/10/2026
IOCs: github.com/netskopeoss/...
000
Netskope Threat Labs @threatlabs.netskope.com · 01/10/2026
Full blog: threatlabs.netskope.com/blog/2026/09...
100
Netskope Threat Labs @threatlabs.netskope.com · 01/10/2026
Vini Egerland has been tracking the Underground campaign: A crypto-drain operation drains victims' exchange accounts. An injected Vidar-class stealer drives Chrome/Edge from rotating fronted /api/machine gates. It has already stolen ~$100K on-chain.
110
Netskope Threat Labs @threatlabs.netskope.com · 30/09/2026
Shared IP: 74.50.88[.]154. Older cluster hosts (registered July 2025): go-us8.r2g[.]click, go-us8.redirpath[.]info. The Unruy samples communicating with that IP inject into IEXPLORE.EXE, hijack browser search, and persist through a Run key.
001
Netskope Threat Labs @threatlabs.netskope.com · 30/09/2026
Unruy click-fraud infrastructure picked up new redirect domains. go-us8.gobridges[.]xyz and go-us8.linkhop[.]click, registered the same day in July at the same registrar, joined established go-us8.* hosts on 74.50.88[.]154. Three Unruy downloader samples communicate with that IP.
110
Netskope Threat Labs @threatlabs.netskope.com · 28/09/2026
Stat of the week: 295 distinct domains tied to command and control, and malware distribution, turned up in enterprise traffic Netskope saw this week, down 12% from 335 the week before. Hundreds of live C2 domains a week is the steady state. #C2 #threatintel
120
Netskope Threat Labs @threatlabs.netskope.com · 24/09/2026
A fake security locker has been circulating using Google Ads to lure victims into clicking. We have seen clicks across more than 619 organization from 250 campaigns, 284 sites hosting the ads, and 457 domains hosting the content. www.netskope.com/blog/a-fake-...
010
Netskope Threat Labs @threatlabs.netskope.com · 23/09/2026
ClearFake payload delivery endpoint in use within a day of its registration. Delivery: rehearsal-b[.]com/4qX0LB/tm/oPpE/. ClearFake reads its loader config from BNB Smart Chain contract storage (EtherHiding)
010
Netskope Threat Labs @threatlabs.netskope.com · 17/09/2026
Prompt injection detection runs in Netskope AI Guardrails, on Real-Time Protection policies, inspecting prompts and responses inline between Agents and LLMs.
000
Netskope Threat Labs @threatlabs.netskope.com · 17/09/2026
Stat of the week: 85.6% of this week's prompt injection alerts related to Anthropic's Claude, out of 18 other apps.
110
Netskope Threat Labs @threatlabs.netskope.com · 15/09/2026
IOCs aleverifocation[.]beer 178.16.52[.]101 00ad7d5e13df939402c6a4df3cd2e5c0f2d4a0aa97b6cb30396cd4dd66f9ebcd 039cd25a042b4f9ac9b75a07ec99be23250aec2734088f2701c06789be94abda
000
Netskope Threat Labs @threatlabs.netskope.com · 15/09/2026
ClickFix lures are running off a .beer TLD cluster. aleverifocation[.]beer went into use a day after registration, taking Win+R paste victim checkins at /api.php?s=<token>&_v=<build>. Its IP 178.16.52[.]101 hosts 10+ fake fingerprint/verification/ID pages.
110
Netskope Threat Labs @threatlabs.netskope.com · 10/09/2026
Netskope NG SWG blocks callbacks to both active subdomains inline as Malicious Site. Win32 EXEs beaconing to this infrastructure named TrojanDownloader:Win32/Unruy / Trojan-Clicker.Win32.Cycler. They drop to C:\Windows\ as wmpscfgs.exe or iexplore.exe to blend with Windows components.
000
Netskope Threat Labs @threatlabs.netskope.com · 10/09/2026
Unruy/Cycler click fraud is running C2 inside AWS: Amazon Registrar, EC2, Route 53, CloudFront fronting the payload host. euob.northwavepoint[.]com (CloudFront, JS payloads) and obseu.northwavepoint[.]com (EC2, /ct click tracker). JS payloads are served only under /sxp/i/<md5>.js.
110
Netskope Threat Labs @threatlabs.netskope.com · 07/09/2026
Stat of the week: 85% of malware-flagged package downloads Netskope Threat Labs saw last week came from Chrome extensions (crx). Most package supply chain monitoring stops where most of the volume is. #supplychain
110
Netskope Threat Labs @threatlabs.netskope.com · 03/09/2026
John Carlo Marquez's latest blog details a growing trend of more than 5,400 compromised websites leveraging the EtherHiding technique and a new campaign that abuses WebRTC to create a covert C2 channel. #EtherHiding #Malware www.netskope.com/blog/malware...
netskope.com
Malware on the Blockchain: An Ongoing Campaign's New WebRTC Twist
EtherHiding, a technique that uses blockchain smart contracts as takedown-resistant payload storage, has been seen across more than 5,400 compromised
010
Netskope Threat Labs @threatlabs.netskope.com · 02/09/2026
Jan Michael Alcantara has been tracking NodeStealer for years. The latest variant he analyzed received an AI-assisted upgrade to include more spyware capabilities #malware www.netskope.com/blog/python-...
netskope.com
Python NodeStealer: AI-Assisted to Full Spyware
Since 2023, Netskope Threat Labs has been tracking the Python-based NodeStealer, an infostealer targeting sensitive browser data and Facebook user, and
010
Netskope Threat Labs @threatlabs.netskope.com · 02/09/2026
We posted one of the late-July .top domains on this host at the time. Same VPS, same registrar, same naming scheme, new TLDs, so the pattern is trackable: plant or shrub name plus an architectural or location noun. bsky.app/profile/nets...
000
Netskope Threat Labs @threatlabs.netskope.com · 02/09/2026
Netskope NG SWG categorizes the cluster as Malicious Site and blocks it at access. Multiple js served. e.g. tamarisknave[.]co serves /logout/oauth-schema.js, it can load unsigned image into the LSASS Process. Registered late August and still resolving. Shared host 178.156.232[.]136.
100
Netskope Threat Labs @threatlabs.netskope.com · 02/09/2026
Domains named after plant and place: tamarisknave[.]co, sycamoreitinerary[.]co, yarrowalcove[.]net. Eight of them sit on one Hetzner VPS, each SOA record pointing at the same Proton Mail address. The late-July .top wave rotated off, .net and .co replaced it.
110
Netskope Threat Labs @threatlabs.netskope.com · 31/08/2026
Polygon calls cost a fraction of a cent, so continuous C2 lookups stay cheap and blend into ordinary JSON-RPC traffic to public endpoints. Hunting: outbound eth_call POSTs from a non-browser client such as okhttp.
000
Netskope Threat Labs @threatlabs.netskope.com · 31/08/2026
Contract: 0xA3a603F8a454a9c905b4c579Bb72628F7C15C2A0 (Polygon, chainid 137) Deployer: 0x363AeAF1F67f1FB7ABdDC3f9806a301f1C64AbE3 Selectors: 0x2686ecea getServerURL(), 0xd75d1ba6 setServerURL(string) C2: vg5sgxv[.]lol
100
Netskope Threat Labs @threatlabs.netskope.com · 31/08/2026
Malware is resolving its C2 through the Polygon blockchain as of 2 days ago. An eth_call to a verified contract named extractor returns the domain vg5sgxv[.]lol from getServerURL(), ABI-encoded.
curl command pipes into python to decode and extract command and control domain.
110
Netskope Threat Labs @threatlabs.netskope.com · 31/08/2026
The first Service Worker and on-blockchain C2 convergence we have observed. Chain also includes: a MP3/HTA polyglot, a fileless PowerShell stage, the Emmenhtal loader, and a steganographic jpg on a legitimate CDN. #ClickFix #EtherHiding #IoC Graph in VirusTotal: www.virustotal.com/graph/gd501f...
000
Netskope Threat Labs @threatlabs.netskope.com · 31/08/2026
A WordPress mass-compromise campaign runs a malicious Service Worker that strips CSP and resolves its ClickFix payload from a Base smart contract. The 9-step chain decodes to the Amatera stealer. See full blog post: www.netskope.com/blog/etherhi...
netskope.com
EtherHiding in the Browser: ClickFix Chain Ends in Amatera
Netskope Threat Labs has been tracking a WordPress mass-compromise campaign affecting hundreds of sites. On each one, a rogue must-use plugin registers a
110
Netskope Threat Labs @threatlabs.netskope.com · 18/08/2026
EVM, Solana, and TON all use the same blockchain approach to dead drop resolvers. Netskope's Vinicius Egerland breaks down how it works and what you can do about it. www.netskope.com/blog/blockch...
netskope.com
Blockchain Dead Drop Resolvers Explained
A dead drop resolver (DDR) is any mechanism where malware fetches its command and control (C2) address at runtime from a third-party,
020
Netskope Threat Labs @threatlabs.netskope.com · 18/08/2026
Netskope IPS blocks the outbound read inline (MALWARE-CNC Outbound BSC eth_call JSON-RPC, possible EtherHiding C2 resolution). Endpoint observed: bsc-testnet-dataseed.bnbchain[.]org, legitimate BNB Chain infrastructure. Hunt the eth_call pattern, not the host.
000
Netskope Threat Labs @threatlabs.netskope.com · 18/08/2026
On VirusTotal this week: fresh EtherHiding-tagged HTML/JS/HTA files labeled as ClickFix lures. Technique dates to ClearFake (2023). Delivery changed, the resolution mechanism did not. We reported Ethereum and Polygon variants in July and August, so this is recurring tradecraft, not an experiment.
000
Netskope Threat Labs @threatlabs.netskope.com · 18/08/2026
Netskope observed outbound traffic consistent with malware resolving C2 via BNB Smart Chain contract storage (EtherHiding). The read goes to a public BSC testnet RPC node, so there is no actor domain to blocklist, and testnet contracts draw less scrutiny than mainnet.
210
Netskope Threat Labs @threatlabs.netskope.com · 14/08/2026
The apps themselves are not compromised. They are being used as the channel. The appeal is not stealthy tooling. It is a domain already allowlisted, valid TLS, and no fresh infrastructure to burn.
000
Netskope Threat Labs @threatlabs.netskope.com · 14/08/2026
Stat of the week: 15 distinct cloud apps carried C2 traffic in Netskope telemetry this week, up from 13 last week. Ten are mainstream collaboration and productivity SaaS: Google Drive, OneDrive, SharePoint, Gmail, JIRA, Salesforce. New to the list this week: ChatGPT. #C2 #SaaS
130
Netskope Threat Labs @threatlabs.netskope.com · 11/08/2026
Ext. ID: "inhcgfpbfdjbjogdfjbclgolkmhnooop" IoCs: github.com/netskopeoss/...
000
Netskope Threat Labs @threatlabs.netskope.com · 11/08/2026
The Chrome extension "AI Sidebar with DeepSeek AI" was removed from the Chrome Web Store in Jan 26 for stealing AI conversation content. In July 26 it resumed delivering updates: it monetizes its install base by affiliate link and suppresses navigation to ChatGPT. www.netskope.com/blog/ai-side...
netskope.com
AI Sidebar Extension Monetizes Its Own Updates
The Chrome extension "AI Sidebar with DeepSeek AI" that Google removed from the Chrome Web Store in January 2026 for stealing AI conversation content
110
Netskope Threat Labs @threatlabs.netskope.com · 07/08/2026
The churn is in the packing: the obfuscation layer is regenerated per delivery while the redirect chain stays recognisable.
000
Netskope Threat Labs @threatlabs.netskope.com · 07/08/2026
Stat of the week: Netskope saw 4,995 distinct SHA-256s for one JS malware family, up 47% WoW from 3,393. JS:Trojan.Cryxos.16527, obfuscated JS with browser redirect lures, is repacked so often that nearly every hit is a new hash. Hash-based blocking decays by the day. #malware #JavaScript
110
Netskope Threat Labs @threatlabs.netskope.com · 04/08/2026
Payload SHA256 9fc2570b7cef51c1b8df116d144d11ff4096357be7d2c4c6367cfc2509cf1bcc, exfil to npm-cache[.]com/router. Netskope Advanced Threat Protection scored it malicious on behavior alone. npm install --ignore-scripts stops the preinstall hook that starts the chain.
000
Netskope Threat Labs @threatlabs.netskope.com · 04/08/2026
The tarball ships no binary. A preinstall hook downloads a signed Bun runtime from GitHub, runs an obfuscated JS stealer under it, then deletes the runtime. Roughly 10 seconds from install to encrypted exfiltration: SSH keys, AWS creds, gh tokens, 17-region SSM and Secrets Manager, Vault.
100
Netskope Threat Labs @threatlabs.netskope.com · 04/08/2026
Shai Hulud: A poisoned npm package wave hardcodes no C2. The stealer issues an eth_call to an Ethereum smart contract that returns the current exfiltration host at runtime.
210
Netskope Threat Labs @threatlabs.netskope.com · 04/08/2026
Netskope blocks the lure PDFs at download and the TDS infrastructure at the network layer, with sandbox coverage for rotated variants.
000
Netskope Threat Labs @threatlabs.netskope.com · 04/08/2026
IOCs available: github.com/netskopeoss/...
100
Netskope Threat Labs @threatlabs.netskope.com · 04/08/2026
A PDF factory has parked 12,700+ FakeCaptcha lures on Webflow's CDN, indexed by Google. The blog post provides a deep dive into a long-lived TDS that sells the qualifying clicks to several buyers, including the Legion Loader malware downloader. www.netskope.com/blog/fake-ca...
netskope.com
Fake CAPTCHA, Real Business: Traffic Distribution for Hire
A single PDF factory has stamped out more than 12,700 structurally similar FakeCaptcha documents and parked them on Webflow's content delivery network,
111
Netskope Threat Labs @threatlabs.netskope.com · 31/07/2026
The Turnstile gate is also why URL reputation and crawler-based checks come back clean. Worth hunting: a Microsoft OAuth path served from a non-Microsoft host behind a bot check. Netskope Threat Protection IPS detects the pattern inline.
000
Netskope Threat Labs @threatlabs.netskope.com · 31/07/2026
Host pictured: login.av7551[.]com. KnowBe4 ThreatLabs published a breakdown of this infrastructure: x.com/Kb4Threatlab...
100
Netskope Threat Labs @threatlabs.netskope.com · 31/07/2026
Host pictured: login.av7551[.]com. KnowBe4 ThreatLabs published a breakdown of this infrastructure x.com/Kb4Threatlab...
000
Netskope Threat Labs @threatlabs.netskope.com · 31/07/2026
The Turnstile gate is also why URL reputation and crawler-based checks come back clean. Worth hunting: a Microsoft OAuth path served from a non-Microsoft host behind a bot check. Netskope Threat Protection IPS detects the pattern inline.
100
Netskope Threat Labs @threatlabs.netskope.com · 31/07/2026
Tycoon2FA puts a Cloudflare Turnstile bot check in front of fake Microsoft OAuth authorize endpoints, so scanners stop at the gate while human targets carry on to credential and session token capture. Netskope detections of the pattern rose 78% week over week. #phishing #AiTM
Image for draft 3mrwu7j5v4c2y
110
Netskope Threat Labs @threatlabs.netskope.com · 30/07/2026
Fair point, and worth stating plainly: shared edge, agreed. Those resolutions were pivot context, not indicators. What carried the signal was the gap: domain registered Jul 20, first requests in enterprise traffic Jul 23.
110
Netskope Threat Labs @threatlabs.netskope.com · 29/07/2026
Downstream is unconfirmed by Netskope. A VirusTotal community comment reports a ClickFix prompt and PowerShell dropper: www.virustotal.com/gui/domain/a...
virustotal.com
000