Discover the latest articles and insights on Dark Atlas
September 08, 2026
23 min read
Executive summary Hagaseca is an Android malware cluster associated with exposed Android Debug Bridge (ADB) services. This analysis examines the Hagaseca Android RAT loader known as THost9. RAT stands for remote access trojan. A RAT can let an attacker control an infected device remotely. The loader hides executable code inside an Android application package (APK). ...
September 01, 2026
28 min read
DragonForce is more than a ransomware name. It is a ransomware service ecosystem that affiliates can use to deploy different lockers and intrusion tools. This analysis focuses on one verified DragonForce Windows locker. The sample is a 32-bit Windows executable. It can encrypt local files, encrypt accessible SMB shares, remove shadow copies, stop selected processes, ...
July 29, 2026
26 min read
Executive summary Device code phishing turns a legitimate OAuth sign-in workflow into a remote authorization ceremony for an attacker-controlled client. The victim does not type a password into a fake page. They may never visit a look-alike Microsoft domain. Instead, the attacker starts a real OAuth 2.0 Device Authorization Grant, sends the victim its short ...
July 19, 2026
21 min read
Executive Summary APT42 continues to refine a familiar operating model, making it harder to detect and easier to scale. Three developments define the current picture. SpearSpecter combined prolonged WhatsApp engagement, Windows search-ms and WebDAV abuse, and a substantially expanded TAMECAT backdoor. APT42 also incorporated generative AI into target research, persona and pretext development, translation, malware engineering, debugging, code generation, ...
July 08, 2026
11 min read
Executive Summary The arrest and extradition of an alleged Scattered Spider member drew attention for more than the charges themselves. The most revealing detail appeared inside the court documents: Microsoft telemetry associated with a Global Device Identifier, or GDID, helped investigators connect online activity to a specific Windows installation. According to the complaint, Microsoft records ...
June 24, 2026
38 min read
Executive Summary LoaderClient is a Minecraft-based malware loader linked to the WeedHack Malware-as-a-Service campaign. It is distributed as a malicious Minecraft Fabric mod and is designed to steal Minecraft session data, including display name, account UUID, and live Microsoft OAuth access tokens. What makes LoaderClient especially notable is its command and control architecture. Instead of ...
June 09, 2026
32 min read
Overview The enterprise threat landscape in 2026 has been reshaped by the rapid ascent of “The Gentlemen” — a Ransomware-as-a-Service (RaaS) operation tracked by Microsoft Threat Intelligence as Storm-2697 and by other security research firms under the alias LARVA-368. Since its emergence in mid-2025, this financially motivated syndicate has scaled faster than any other ransomware group on record, ...
June 02, 2026
43 min read
Modern supply chain intrusions are attacks that compromise trusted software development systems, including CI/CD pipelines, package registries, GitHub repositories, developer tools, and cloud environments. Instead of attacking one organization directly, threat actors abuse trusted dependencies, automation workflows, and stolen developer credentials to spread across entire software ecosystems. TeamPcP History TeamPCP (also tracked as PCPcat, DeadCatx3, ...
May 03, 2026
15 min read
Introduction Attribution in cyber threat intelligence has long been built around the concept of persistent adversary groups commonly labeled as Advanced Persistent Threats (APTs). These designations, widely used by organizations such as MITRE and leading threat intelligence vendors, attempt to cluster malicious activity under unified identities based on observed behaviors, infrastructure, and tooling. However, this ...