<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Threat-Research on CuraSec</title><link>https://curasec.metacog.co.kr/tags/threat-research/</link><description>Recent content in Threat-Research on CuraSec</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Wed, 02 Sep 2026 15:05:08 +0000</lastBuildDate><atom:link href="https://curasec.metacog.co.kr/tags/threat-research/index.xml" rel="self" type="application/rss+xml"/><item><title>CrowdStrike Details Sality P2P Botnet Disruption Operation</title><link>https://curasec.metacog.co.kr/insights/2026-09-02-peer-pressure-inside-the-sality-botnet-disruption-operation/</link><pubDate>Wed, 02 Sep 2026 15:05:08 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-09-02-peer-pressure-inside-the-sality-botnet-disruption-operation/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Learn:&lt;/strong> Sality is a long-lived Windows malware family; no new CVEs or patch action indicated. Worth reviewing for any infrastructure hardening lessons from the disruption operation.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Learn:&lt;/strong> A disruption retrospective on a known P2P botnet improves understanding of Sality&amp;rsquo;s architecture and TTPs, but no enrichment signals suggest fresh IOCs or active targeting requiring an immediate hunt.&lt;/li>
&lt;li>&lt;strong>Leader — Skip&lt;/strong>&lt;/li>
&lt;/ul></description></item><item><title>SANS ISC: Malicious PE file compiler statistics overview</title><link>https://curasec.metacog.co.kr/insights/2026-08-28-some-malicious-pe-stats-thu-aug-27th/</link><pubDate>Fri, 28 Aug 2026 21:21:40 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-28-some-malicious-pe-stats-thu-aug-27th/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>SOC/IR — Learn:&lt;/strong> Compiler and PE header metadata distributions across malicious samples can inform triage heuristics; useful background for analysts who build or tune static detection rules, but yields no immediate detection action.&lt;/li>
&lt;li>&lt;strong>Leader — Skip&lt;/strong>&lt;/li>
&lt;/ul></description></item><item><title>Unit 42: State of AI-Enabled Malware August 2026 Report</title><link>https://curasec.metacog.co.kr/insights/2026-08-25-the-state-of-ai-enabled-malware-august-2026-from-brand-abuse/</link><pubDate>Tue, 25 Aug 2026 11:39:54 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-25-the-state-of-ai-enabled-malware-august-2026-from-brand-abuse/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Learn:&lt;/strong> Research on AI-authored malware and agentic execution techniques is worth reviewing to understand how these threats interact with build/CI environments, but no exploited CVEs or supply-chain IOCs are present requiring immediate action.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Plan:&lt;/strong> Unit 42&amp;rsquo;s analysis of AI-enabled malware TTPs — including brand abuse lures and agentic execution chains — is worth translating into behavioral detection tuning this quarter; review the report for any new evasion patterns to add to endpoint analytics rules.&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> This report provides useful benchmarking data on the maturation of AI-assisted threats, suitable for future board deck context on the AI threat landscape, but requires no immediate leadership action.&lt;/li>
&lt;/ul></description></item><item><title>Synthetic Identity Fraud Techniques Extending to Machine Identities</title><link>https://curasec.metacog.co.kr/insights/2026-07-23-how-synthetic-identity-fraud-is-coming-for-machine-identitie/</link><pubDate>Thu, 23 Jul 2026 12:47:45 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-07-23-how-synthetic-identity-fraud-is-coming-for-machine-identitie/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Learn:&lt;/strong> Explores how synthetic identity creation techniques may apply to non-human identities (service accounts, API keys, certificates); worth understanding when designing machine identity lifecycle controls and anomaly detection for credential provisioning.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Learn:&lt;/strong> Provides conceptual framing for a novel identity-abuse pattern that could inform triage of anomalous machine-identity activity, but no IOCs, TTPs, or detection-ready detail are present in this item.&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> Signals an emerging risk category around machine identity governance that may warrant a future policy review, but no immediate action, breach event, or regulatory trigger is present.&lt;/li>
&lt;/ul></description></item><item><title>TuxBot v3: LLM-Assisted IoT Botnet With Amateurish Results</title><link>https://curasec.metacog.co.kr/insights/2026-07-16-tuxbot-v3-evolution-shows-signs-of-llm-assisted-iot-botnet-d/</link><pubDate>Thu, 16 Jul 2026 12:18:39 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-07-16-tuxbot-v3-evolution-shows-signs-of-llm-assisted-iot-botnet-d/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Learn:&lt;/strong> No KEV, EPSS, or PoC signals; the botnet appears incomplete given the developer left AI safety disclaimers in the code. Worth noting as evidence that LLM-generated malware is maturing unevenly — no patching or configuration action warranted today.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Learn:&lt;/strong> No IOCs, active campaign, or ATT&amp;amp;CK-mappable TTPs are surfaced in this disclosure. Useful context that LLM tooling is entering adversary development workflows, but there is nothing actionable to hunt or detect from this item alone.&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> Early evidence that threat actors are experimenting with LLM-assisted malware development, even if clumsily — relevant background for AI-risk discussions at the leadership level, but no immediate board action or vendor exposure to assess.&lt;/li>
&lt;/ul></description></item></channel></rss>