Visualização normal

Antes de ontemSpiderLabs Blog

Still Circling: Inside the Operator Behind Blind Eagle's GitHub Loader

28 de Agosto de 2026, 11:00

This is a collaborative follow-up to our original post, developed jointly with Emmanuel C., a security researcher not affiliated with LevelBlue, who contributed additional infrastructure and tooling findings based on an analysis of the same GitHub staging account.

  • ✇SpiderLabs Blog
  • Energy Disruption in UK Critical Infrastructure and the Growing OT Cyber Threat Nikita Kazymirskyi
    A cyber incident affecting a small UK electricity generator in July 2026 resulted in several days of operational unavailability and triggered a government and NCSC response. UK authorities confirmed that the event posed no threat to the wider grid and caused no customer outages. Media reporting described the affected asset as a small gas-fired peaking plant of approximately 15 MW, although the operator, location, technical architecture, and exact attack path remain undisclosed.
     

Energy Disruption in UK Critical Infrastructure and the Growing OT Cyber Threat

25 de Agosto de 2026, 12:27

A cyber incident affecting a small UK electricity generator in July 2026 resulted in several days of operational unavailability and triggered a government and NCSC response. UK authorities confirmed that the event posed no threat to the wider grid and caused no customer outages. Media reporting described the affected asset as a small gas-fired peaking plant of approximately 15 MW, although the operator, location, technical architecture, and exact attack path remain undisclosed.

Cloud Sync Root RegistrationShieldBreak: Hunting Windows Defender Remediation Abuse and Cloud Files Hijacking

19 de Agosto de 2026, 12:40

Following GreenPlasma, YellowKey and MiniPlasma, RoguePlanet and GreatXML, and LegacyHive, the Nightmare-Eclipse disclosure actor has published ShieldBreak — its latest Windows proof of concept (PoC) released shortly after Microsoft's August 2026 Patch Tuesday.

  • ✇SpiderLabs Blog
  • Release the RAVEN: Destruction and Discipline Karl Biron
    In Part 4, we stole every document from every index, planted a rogue superuser account, created credential-independent API keys, and planted three persistence mechanisms that survive password rotations. Everything was logged. Now we answer two final questions: how much worse could it get, and how do we put everything back?
     

Release the RAVEN: Destruction and Discipline

18 de Agosto de 2026, 13:53

In Part 4, we stole every document from every index, planted a rogue superuser account, created credential-independent API keys, and planted three persistence mechanisms that survive password rotations. Everything was logged. Now we answer two final questions: how much worse could it get, and how do we put everything back?

Release the RAVEN: Data Heist and Persistence

14 de Agosto de 2026, 10:13

We have access through port 9200. We have code execution through port 5601. Reconnaissance is complete, CVEs have been exploited, and Kibana has been compromised. Over the past three posts, we proved that we could get in. Now we prove what happens after.

  • ✇SpiderLabs Blog
  • Release the RAVEN: Kibana Under Siege Karl Biron
    In Parts 1 and 2, every command targeted port 9200. Every exploit, every reconnaissance query, every credential test hit the Elasticsearch REST API directly. But Elasticsearch rarely operates alone. Sitting alongside it on most deployments is Kibana, the visualization and management interface, quietly serving dashboards on port 5601 with its own API surface, plugin architecture, and history of critical vulnerabilities.
     

Release the RAVEN: Kibana Under Siege

13 de Agosto de 2026, 10:36

In Parts 1 and 2, every command targeted port 9200. Every exploit, every reconnaissance query, every credential test hit the Elasticsearch REST API directly. But Elasticsearch rarely operates alone. Sitting alongside it on most deployments is Kibana, the visualization and management interface, quietly serving dashboards on port 5601 with its own API surface, plugin architecture, and history of critical vulnerabilities.

  • ✇SpiderLabs Blog
  • The Infrastructure Relay: Inside Multi-Stage Phishing Redirection Chains Karla Agregado
    To stay ahead of evolving threats, LevelBlue utilizes a machine-learning-based URL scanner that constantly evaluates the digital landscape. We closely monitor VirusTotal for instances where LevelBlue acts as the sole detection layer — a crucial tactic for spotting new phishing campaigns early. In this blog, we will unpack several notable phishing campaigns discovered through this method.
     

The Infrastructure Relay: Inside Multi-Stage Phishing Redirection Chains

12 de Agosto de 2026, 10:42

To stay ahead of evolving threats, LevelBlue utilizes a machine-learning-based URL scanner that constantly evaluates the digital landscape. We closely monitor VirusTotal for instances where LevelBlue acts as the sole detection layer — a crucial tactic for spotting new phishing campaigns early. In this blog, we will unpack several notable phishing campaigns discovered through this method.

Beyond ‘Fake Updates’: From Application Store-Themed Phishing to Large-Scale Distribution of ScreenConnect

7 de Agosto de 2026, 10:10

The LevelBlue OpsCTI Team recently identified a large-scale phishing campaign leveraging a new social engineering method to deploy unauthorized ConnectWise ScreenConnect clients. Rather than relying on conventional phishing pages, the campaign recreates convincing software update and installation alerts by impersonating the Microsoft Store and Apple App Store while reproducing the look and behavior of trusted applications through dynamic modal dialogs and other interactive web elements. The campaign impersonates trusted software and services, including Google Meet, Adobe Acrobat, Microsoft Teams, Zoom, Docusign, Secure Access Manager, Blue Mountain, Paperless Post, and other popular applications.

  • ✇SpiderLabs Blog
  • Release the RAVEN: Exploiting the Cracks Karl Biron
    In Part 1, we went from a single open port to a complete map of the target. Version, topology, indices, secrets, credentials, privilege structure — all of it documented, all of it ready to be weaponized. Reconnaissance is finished. Now we find out what breaks.
     

Release the RAVEN: Exploiting the Cracks

6 de Agosto de 2026, 11:00

In Part 1, we went from a single open port to a complete map of the target. Version, topology, indices, secrets, credentials, privilege structure — all of it documented, all of it ready to be weaponized. Reconnaissance is finished. Now we find out what breaks.

  • ✇SpiderLabs Blog
  • Release the RAVEN: First Contact Karl Biron
    You are mid-engagement. Nmap finishes its sweep and port 9200 lights up on a host. Elasticsearch. You know it matters. You know the client's logging pipeline, search infrastructure, or analytics platform probably flow through it. But what do you actually know about this cluster? Right now, nothing. No version, no configuration, no indication of whether it is locked down or wide open.
     

Release the RAVEN: First Contact

5 de Agosto de 2026, 12:11

You are mid-engagement. Nmap finishes its sweep and port 9200 lights up on a host. Elasticsearch. You know it matters. You know the client's logging pipeline, search infrastructure, or analytics platform probably flow through it. But what do you actually know about this cluster? Right now, nothing. No version, no configuration, no indication of whether it is locked down or wide open.

Review of the July 2026 Cyberattacks Against U.S. Water and Wastewater Systems

4 de Agosto de 2026, 10:20

In light of the water-sector activity described below, we've increased monitoring for related indicators of compromise across our client environments. Please contact your LevelBlue account team with questions specific to your environment.

  • ✇SpiderLabs Blog
  • Release the RAVEN: An Offensive Reconnaissance and Attack Tool on Vulnerable Elasticsearch Nodes Karl Biron
    You have almost certainly interacted with Elasticsearch today. The search bar on your company's internal wiki. The autocomplete on the e-commerce site where you ordered lunch. The log aggregation dashboard your SOC team stares at for eight hours straight. The recommendation engine that just served you this article. Elasticsearch is the invisible infrastructure behind modern search, and it processes some of the most sensitive data an organization possesses, including access logs, customer records
     

Release the RAVEN: An Offensive Reconnaissance and Attack Tool on Vulnerable Elasticsearch Nodes

29 de Julho de 2026, 16:22

You have almost certainly interacted with Elasticsearch today. The search bar on your company's internal wiki. The autocomplete on the e-commerce site where you ordered lunch. The log aggregation dashboard your SOC team stares at for eight hours straight. The recommendation engine that just served you this article. Elasticsearch is the invisible infrastructure behind modern search, and it processes some of the most sensitive data an organization possesses, including access logs, customer records, financial transactions, and authentication events. It knows where your users click, what they search for, and when they log in.

LegacyHive: Hunting Windows Profile Initialization Abuse Through Offline Registry Manipulation

27 de Julho de 2026, 11:07

Following GreenPlasma, YellowKey and MiniPlasma, as well as RoguePlanet and GreatXML, the Nightmare-Eclipse disclosure actor has published LegacyHive, its latest Windows proof-of-concept (PoC) released shortly after Microsoft's July 2026 Patch Tuesday.

LevelBlue TTP Briefing Q2 2026: Stolen Identities Outpace Defenses

23 de Julho de 2026, 11:00

Explore the latest tactics, techniques, and procedures (TTPs) our incident response (IR) experts are actively facing in the quarterly TTP Briefing, a report built on frontline threat intelligence from our global incident response investigations across LevelBlue during Q2 2026.

  • ✇SpiderLabs Blog
  • LegacyHive: Nightmare-Eclipse’s Latest Zero-Day Drop with a Stripped PoC Pauline Bolaños
    Vexed researcher Nightmare-Eclipse (aka Chaotic Eclipse, Dead Eclipse, and MSNightmare) released his ninth unpatched Windows vulnerability called LegacyHive. This latest bug drop is a Local Privilege Escalation (LPE) vulnerability affecting Windows User Profile, a component responsible for loading and unloading Windows user profiles. When exploited, LegacyHive can enable attackers to load other users’ hives and gain access to application data and Windows Explorer history, among others.
     

LegacyHive: Nightmare-Eclipse’s Latest Zero-Day Drop with a Stripped PoC

20 de Julho de 2026, 09:35

Vexed researcher Nightmare-Eclipse (aka Chaotic Eclipse, Dead Eclipse, and MSNightmare) released his ninth unpatched Windows vulnerability called LegacyHive. This latest bug drop is a Local Privilege Escalation (LPE) vulnerability affecting Windows User Profile, a component responsible for loading and unloading Windows user profiles. When exploited, LegacyHive can enable attackers to load other users’ hives and gain access to application data and Windows Explorer history, among others.

  • ✇SpiderLabs Blog
  • Still Circling: Blind Eagle's Toolkit Keeps Evolving Serhii Melnyk
    In June 2025, LevelBlue SpiderLabs published Tracing Blind Eagle to Proton66, in which we assessed with high confidence that Blind Eagle (also tracked as APT-C-36, APT-Q-98, TAG-144, AguilaCiega), a threat actor focused on Latin America, had moved part of its VBScript delivery infrastructure onto the Russian bulletproof hosting provider Proton66. A year later, we're still tracking this cluster closely, and the group hasn't slowed down. If anything, it has kept building.
     

Still Circling: Blind Eagle's Toolkit Keeps Evolving

17 de Julho de 2026, 10:57

In June 2025, LevelBlue SpiderLabs published Tracing Blind Eagle to Proton66, in which we assessed with high confidence that Blind Eagle (also tracked as APT-C-36, APT-Q-98, TAG-144, AguilaCiega), a threat actor focused on Latin America, had moved part of its VBScript delivery infrastructure onto the Russian bulletproof hosting provider Proton66. A year later, we're still tracking this cluster closely, and the group hasn't slowed down. If anything, it has kept building.

ClickFix on macOS: Blockchain-Powered Infostealer Hidden Inside Compromised Websites

16 de Julho de 2026, 10:43

You're browsing a legitimate small business website. Before the page loads, a familiar Cloudflare box appears: "Verify you are human." It asks you to open Terminal, paste a code, and press Enter. You've seen this before. You follow the steps. The page loads normally.

  • ✇SpiderLabs Blog
  • Mitigating New Vulnerabilities with owLSM
    Following the successful launch of owLSM, our first open-source project with more than 250 GitHub stars as of writing, we are now launching a blog series to explore the project's practical applications, capabilities, and value.
     
❌
❌