The eSentire Blog

Threat Response Unit

3 M

Six Days Ahead: How eSentire Detected NetScaler Exploitation Before the Industry Caught Up

On April 2, 2026, eSentire’s Threat Response Unit (TRU) identified active exploitation attempts targeting Citrix…

READ NOW →

TRU Positive/Bulletin

34 M

Multi-Stage SEO Poisoning Campaign Targets Chinese-Speaking Developers with Kong RAT

What did we find?In March 2026, eSentire's Threat Response Unit detected a sophisticated multi-stage malware…

READ NOW →

AI/ML

7 M

eSentire in the Age of AI-Driven Threats

Last month, Anthropic disclosed that its Claude Mythos model had autonomously discovered thousands of zero-day…

READ NOW →

TRU Positive/Bulletin

35 M

STX RAT: A new RAT in 2026 with Infostealer Capabilities

What did we find?In late February 2026, eSentire's Threat Response Unit (TRU) observed an attempted delivery of a…

READ NOW →

TRU Positive/Bulletin

9 M

Tycoon 2FA Infrastructure Update: Threat Actors Adapt Following Global Coalition Takedown

What did we find?Following the organized global coalition takedown of Tycoon 2FA phishing infrastructure led by…

READ NOW →

TRU Positive/Bulletin

16 M

EtherRAT & SYS_INFO Module: C2 on Ethereum (EtherHiding), Target Selection, CDN-Like Beacons

What did we find?In March 2026, eSentire's Threat Response Unit (TRU) detected EtherRAT in a customer's…

READ NOW →

TRU Positive/Bulletin

9 M

MuddyWater APT + Tsundere Botnet: EtherHiding the C2

What did we find?In March 2026, eSentire's Threat Response Unit (TRU) investigated an open-directory web server…

READ NOW →

TRU Positive/Bulletin

24 M

North Korean APT Malware Analysis: DEV#POPPER RAT and OmniStealer (Everyday I'm Shufflin')

What did we find?In February 2026, eSentire's Threat Response Unit (TRU) detected DEV#POPPER, a sophisticated…

READ NOW →

Threat Response Unit

3 M

Microsoft Announces Disruption of Tycoon 2FA in Coordination with Industry Partners

March 4, 2026 – Today, Microsoft announced they took action to disrupt and coordinate seizure of infrastructure…

READ NOW →

Threat Response Unit

6 M

How Cybercriminals Customized Attacks for Five Industries in 2025

In 2025, identity-related cybercrime scaled rapidly with the expansion of "as-a-Service" models. Offering…

READ NOW →

TRU Positive/Bulletin

22 M

Tenant from Hell: Prometei's Unauthorized Stay in Your Windows Server

What did we find? In January 2026, eSentire's Threat Response Unit (TRU) detected a malicious command attempting…

READ NOW →

Threat Response Unit

30 M

Weaponized in China, Deployed in India: The SyncFuture Espionage Targeted Campaign

What did we find? In early December 2025, the eSentire Threat Response Unit (TRU) identified an ongoing…

READ NOW →
Page
of 18