illustration of robot holding a shield with text AI

How GenAI risks continue to impact security posture

Generative AI (GenAI) tools are transforming the way people work. They assist organizations in creating personalized content quickly. They also help streamline supply chains, automate decision-making, and facilitate agile business processes.  In ...
illustration of fishing line catching browser window

EvilProxy Phishing Attack Strikes Indeed

Executive Summary Menlo Labs recently identified a phishing campaign targeting executives in senior level roles across various industries, but primarily Banking and Financial services, Insurance providers, Property Management and Real Estate, and ...
illustration of fishing line catching browser window

EvilProxy Phishing Attack Strikes Indeed

Executive Summary Menlo Labs recently identified a phishing campaign targeting executives in senior level roles across various industries, but primarily Banking and Financial services, Insurance providers, Property Management and Real Estate, and ...
Illustration of computer window with key unlocking padlock, thief stealing credit cards, and text XeGroup

Not your average Joe: An analysis of the XeGroup’s attack techniques

Disclaimer: Menlo Labs has informed the appropriate law enforcement agencies on the intelligence presented in this report. Executive Summary XeGroup is a hacking group that has been active since at least 2013 ...
illustration of hacker holding many masks

The many faces of the IcedID attack kill chain

Executive Summary The Menlo Labs Team noticed some very interesting and seemingly overlapping IcedID campaigns over the past couple of months. IcedID is a modular trojan that made its appearance in 2017, ...
illustration of discord logo connected to malware

PureCrypter targets government entities through Discord

Executive Summary Menlo Labs has uncovered an unknown threat actor that’s leveraging an evasive threat campaign distributed via Discord that features the PureCrypter downloader and targets government entities. The PureCrypter campaign uses ...
illustration of masked man injecting office template with camouflaged liquid beside a magnifying glass containing the north korean flag

Template injection attacks part 3: Following the bread crumbs to North Korea

Executive Summary During October 2022, the Menlo Labs research team posted details on camouflaged template injection documents that contained a decimal IP address or used an obscure URL format to fetch the ...

Join us (Virtually) at Security BSides Dublin on March 27

March already? How did that happen so quickly? We’re excited that Krishnan Subramanian, a Staff Security Researcher at Menlo Labs, will be presenting at the Security BSides Dublin virtual conference on March ...