#ThreatLabZ
AI is breaking VPN. VPN too slow to react.
www.cio.com/article/4149...
AI machine speed is breaking VPN security
Key Findings from the Threatlabz 2026 VPN Risk Report
www.cio.com
September 27, 2026 at 3:02 AM
Another supply chain attack... this one at Okendo Reviews, a product review widget used on more than 18k online stores

A threat actor known as SmartApeSG added malicious JS code to prompt users with a ClickFix window

www.zscaler.com/blogs/securi...
SmartApeSG Supply Chain Attack Targets Okendo | ThreatLabz
ThreatLabz identified a SmartApeSG-linked supply chain attack that targeted the Okendo Reviews widget impacting thousands of e-commerce sites.
www.zscaler.com
June 21, 2026 at 8:45 PM
#AI: Zscaler ThreatLabz has published a research paper on malicious websites that impersonate legitimate services and use Indirect Prompt Injection to poison SEO & manipulate AI Agents & AI-driven workflows - a fascinating read:
#AISecurity
👇
www.zscaler.com/blogs/securi...
Indirect Prompt Injection Targets AI Agents | ThreatLabz
ThreatLabz details indirect prompt injection hidden in malicious webpages meant to mislead AI agents performing tasks.
www.zscaler.com
July 8, 2026 at 8:16 AM
Zscaler ThreatLabz revealed operations targeting #Tibetans, leveraging the Dalai Lama’s 90th birthday through tactics such as strategic web compromises, DLL sideloading vulnerabilities, & the deployment of Ghost RAT and PhantomNet backdoors. @zscalerinc.bsky.social

www.zscaler.com/blogs/securi...
China-nexus APT Targets the Tibetan Community | ThreatLabz
China-nexus APT campaign leverages DLL sideloading, multi-stage infection chains, and low-level APIs to deploy Ghost RAT and PhantomNet backdoors against Tibetan targets.
www.zscaler.com
July 24, 2025 at 11:05 AM
Fraudulent Google ads and fast-changing redirects are being used to impersonate Ledger, collect secret recovery phrases, and steal wallet credentials via fake verification pages. #Ledger #GoogleAds #Phishing
Threat Actors Use Google Ads To Target Ledger Users
ThreatLabz found a phishing campaign using fraudulent Google ads and fast-changing Vercel redirects to impersonate Ledger and steal users’ secret recovery phrases. The campaign sent victims through Google Cloud Storage and Google Sites, then used a fake device-verification flow to collect wallet credentials. #Ledger #GoogleAds #GoogleCloudStorage #Vercel #GoogleSites
www.hendryadrian.com
September 25, 2026 at 10:45 PM
Zscaler has spotted a new malware loader named CoffeeLoader, used in the wild since September of last year. The malware was used together and appears to bear similarities with SmokeLoader.

www.zscaler.com/blogs/securi...
CoffeeLoader: A Brew of Stealthy Techniques | ThreatLabz
CoffeeLoader is a new malware loader that employs stealthy techniques including call stack spoofing, sleep obfuscation, and Windows fibers to evade detection.
www.zscaler.com
March 29, 2025 at 10:13 PM
Zscaler has published a technical report on HijackLoader (IDAT Loader, GhostPulse) and its recent changes, such as its new call stack spoofing module, anti-VM module, and support for scheduled task persistence

www.zscaler.com/blogs/securi...
New HijackLoader Evasion Tactics | ThreatLabz
Learn how HijackLoader has introduced call stack spoofing and new modules to improve its evasion and anti-analysis capabilities.
www.zscaler.com
April 1, 2025 at 10:31 AM
Edgecution: Malicious Edge Extension Backdoor | ThreatLabz

Zscaler ThreatLabz has been monitoring ransomware operations that align with tactics p

Read more: https://www.zscaler.com/blogs/security-research/payouts-king-ransomware-initial-access-broker-deploys-new-edgecution
June 24, 2026 at 7:00 AM
www.zscaler.com/blogs/securi... - Nice writeup by zscaler on some COLDRIVER malware. I'm talking about this stuff at #FTSCon in a few weeks and will have lots more details there.
COLDRIVER Adds BAITSWITCH and SIMPLEFIX | ThreatLabz
The Russia-linked group COLDRIVER targeted dissidents and their supporters using a ClickFix technique, resulting in the deployment of BAITSWITCH and SIMPLEFIX.
www.zscaler.com
September 26, 2025 at 2:45 PM
Today in the SUN we feature an article from @zscalerinc.bsky.social on managers being prime targets for ransomware attacks.

Read more below:
www.zscaler.com/blogs/securi...

#cybersecurity
@andyjabbour.bsky.social
Ransomware Victims Research | ThreatLabz
Zscaler ThreatLabz examines the employees targeted in a real-world ransomware attack, including the roles and business functions most common among the victims.
www.zscaler.com
August 7, 2026 at 5:04 PM
Vidar stealer string obfuscation has evolved from XOR and ChaCha20 to a per-build virtual machine and custom stream cipher, complicating static analysis and deobfuscation. #Vidar #ThreatLabz #Zscaler
Vidar Adds Virtual Machine And Custom Stream Ciphers For String Obfuscation
Zscaler ThreatLabz tracked Vidar’s string obfuscation as it evolved from XOR and ChaCha20 into a per-build virtual machine and custom stream cipher designed to frustrate static analysis. The report details how these changes affect deobfuscation, shows example VM opcodes and ARX/ChaCha-based cipher logic, and includes Zscaler detections for Vidar. #Vidar #Zscaler #ThreatLabz
www.hendryadrian.com
September 22, 2026 at 12:00 PM
Dark Angels ransomware receives record-breaking $75 million ransom

www.bleepingcomputer.com/news/securit...

> A Fortune 50 company paid a record-breaking $75 million ransom payment to the Dark Angels ransomware gang, according to a report by Zscaler ThreatLabz.
Dark Angels ransomware receives record-breaking $75 million ransom
A Fortune 50 company paid a record-breaking $75 million ransom payment to the Dark Angels ransomware gang, according to a report by Zscaler ThreatLabz.
www.bleepingcomputer.com
July 30, 2024 at 9:10 PM
Zscaler ThreatLabz provides a technical analysis of Abyssos, a new modular remote administration tool (RAT) written in C++ that supports a variety of features including credential theft, file exfiltration, and remote access via VNC. www.zscaler.com/blogs/securi...
August 11, 2026 at 8:39 AM
DanaBot had a HeartBleed-like bug for three years

Leaked all the juicy stuff, such as threat actor usernames, IP addresses, private keys, and loads more

www.zscaler.com/blogs/securi...
DanaBleed: DanaBot C2 Server Memory Leak Bug | ThreatLabz
A flaw in DanaBot's C2 server code caused a memory leak that we named "DanaBleed", exposing sensitive data and offering researchers a look into DanaBot’s operations.
www.zscaler.com
June 10, 2025 at 11:40 AM
Great article from Zscaler ThreatLabz about RevC2 and Venom Loader

If you don't know about ThreatLabz, check their website and github with interesting ressources: github.com/ThreatLabz/

www.zscaler.com/blogs/securi...

#Malware #IoC #Blueteam #Detection #CyberSecurity #Infosec #Zscaler #hacking
Unveiling RevC2 and Venom Loader
Zscaler ThreatLabz discovered two new malware families, RevC2 & Venom Loader, deployed using Venom Spider MaaS Tools.
www.zscaler.com
December 4, 2024 at 9:21 AM
Zscaler ThreatLabz collaborated with TibCERT to investigate two campaigns targeting the Tibetan community. Operation GhostChat & Operation PhantomPrayers relied on multi-stage infection chains to deploy the Ghost RAT and PhantomNet backdoors, respectively. www.zscaler.com/blogs/securi...
July 24, 2025 at 9:00 AM
Unveiling #RevC2 and #Venom Loader
Unveiling RevC2 and Venom Loader
Zscaler ThreatLabz discovered two new malware families, RevC2 & Venom Loader, deployed using Venom Spider MaaS Tools.
buff.ly
December 2, 2024 at 7:35 PM