RSS Amplifier

Blog

Seqrite Labs

Cybersecurity Research & Threat Intelligence

seqrite.comSource feed ↗10 posts

Live Last read · last published · next check

Written by

Latest posts

What Is Digital Risk Management and Why Does Your Business Need It?

Digital transformation has changed the way businesses operate. Organisations now depend on cloud applications, digital platforms, connected devices, third-party vendors, social media, and online customer channels to deliver products and services. While these technologies create new growth opportunities, they also expand the organisation’s digital risk landscape. A single exposed asset, compromised…

Operation QUICSILVER: China-Nexus Actor Targets Myanmar Diplomats via VHD-Delivered Go Backdoor

Contents Introduction Key Targets Industries Affected Geographical focus Infection Chain Campaign Timeline Initial Findings Looking into the Decoy Document Technical Analysis Stage 1 – LNK-Based Initial Access Stage 2 – Split Payload Reconstruction via ftp Script Stage 3 – QUICAgent Implant – Go-Based Backdoor Infrastructure & Attribution Conclusion SEQRITE Protection Indicators of Compromise…

Brand Protection in Cybersecurity: Protecting Businesses from Digital Threats

A brand is more than a logo, website, or trademark. It represents the trust customers place in a business, the reputation it has built, and the digital experiences associated with its name. Today, that trust can be compromised without attackers ever breaching the company’s internal network. Cybercriminals increasingly exploit trusted brands to conduct phishing attacks, […] The post Brand…

What Is the DPDP Act 2025? Key Rules, Compliance Requirements, and Business Impact

What Is the DPDP Act 2025? Key Rules, Compliance Requirements, and Business Impact If you’ve been hearing the term “DPDP Act 2025” a lot lately and feeling slightly out of the loop, you’re not alone. Almost every business owner, IT head, and compliance manager in India is asking some version of the same question right […] The post What Is the DPDP Act 2025? Key Rules, Compliance Requirements, and…

How Digital Risk Management Services Strengthen Enterprise Cybersecurity

In today’s hyperconnected world, organizations face cyber threats that extend far beyond their internal networks. Attackers target brands through phishing websites, leaked credentials, exposed assets, social media impersonation, and third-party vulnerabilities. These risks can damage an organization’s reputation, disrupt operations, and lead to financial losses long before traditional security…

Abusing Trusted Business Workflows: A Multi-Stage Phantom Stealer Campaign

Contents Introduction Campaign Overview Initial Access Infection Chain Technical Analysis Stage 1: Initial Delivery (Archive→JavaScript) Stage 2: PowerShell Loader1 Analysis Stage 3: PowerShell Loader2 Analysis Stage 4 – Phantom Stealer v3.5.0: Data Harvesting and Exfiltration Campaign Attribution Conclusion IOC’s Seqrite Detection Coverage- MITRE Attack Tactics, Techniques, and Procedures (TTP’s)…

EDR vs EPP: Why Endpoint Protection Alone Isn’t Enough in 2026

27 seconds. That’s the fastest time on record for an attacker to break into an endpoint and start moving laterally through a network. The average across all attacks in 2025 was 29 minutes, a 65% jump in speed over the year before. Somewhere in that window, a purely preventive tool has already lost the race, […] The post EDR vs EPP: Why Endpoint Protection Alone Isn’t Enough in 2026 appeared first…

Behind the Refund: From GST Phishing to Remcos RAT Through a Multi-Stage .NET Infection Chain

Introduction Seqrite Labs recently identified a malware distribution campaign that abused the credibility of government institutions to increase infection success rates. The threat actors impersonated legitimate government departments and distributed malicious emails disguised as official notifications related to taxation, refunds, compliance requirements, and regulatory matters. By leveraging…

How to Evaluate Digital Risk Protection Vendors and Companies

Cyber threats no longer stop at the network perimeter. Today, attackers target brands wherever they have a digital presence, websites, social media, mobile apps, email, cloud platforms, and even the dark web. From phishing websites and fake social media profiles to credential leaks and domain impersonation, these attacks can erode customer trust, disrupt business operations, […] The post How to…

Operation ShadowRecruit: A Recruitment-Themed Malware Campaign Leveraging ControlR and Google Sheets to Target Indian Job Seekers

Contents Introduction Key Targets Industries Affected Geographical focus Infection Chain Initial Findings Looking into the Decoy Document Technical Analysis Stage 1 – Initial Infection through LNK file Stage 2 – PowerShell Downloader Analysis Stage 3 – The .NET Dropper – Document.exe Analysis Stage 4 – Decoy Delivery and SheetAgent RAT Analysis Infrastructure & Attribution Conclusion […] The post…