Petah Tikva, Israel
2009
  |  By Adi Bleih
XWorm is a versatile modular malware that presents a multifaceted threat landscape. This malware can be employed for various malicious purposes, including remote access, data theft, ransomware delivery, and botnet creation. Despite being relatively new in the cyber threat landscape, XWorm has rapidly gained notoriety, largely due to its association with the DDGroup cybercrime group, renowned for its utilization of advanced malware techniques.
  |  By Adi Bleih
SalatStealer is a Go-based infostealer family first observed in August 2026, built for x86 Windows environments and focused on credential theft. Its documented capabilities include stealing authentication credentials, hiding executing code, and degrading security software.
  |  By Adi Bleih
MovieReaper is a malware family first observed in September 2026 that combines remote-access trojan and loader functionality in a modular, multi-stage framework. It targets x86-64 systems and is built to reach remote machines, install additional components, persist across reboots, and exfiltrate data while resisting analysis through anti-sandbox, anti-VM, and AV-evasion features.
  |  By Adi Bleih
Noodle RAT—also known as ANGRYREBEL or Nood RAT—is a modular remote access trojan (RAT) with dual versions for Windows and Linux, actively used by Chinese-speaking threat actors since at least mid-2016. It was previously misclassified as variants of Gh0st RAT or Rekoobe but is now recognized as a unique backdoor family.
  |  By Adi Bleih
DarkTortilla is a sophisticated and adaptable.NET-based crypter, active since at least August 2015, known for delivering a range of malicious software, including prevalent information stealers and remote access trojans like AgentTesla, AsyncRat, NanoCore, and RedLine.
  |  By sophiakl
Originating in early 2023, Pikabot emerged as a significant malware loader. Over the past year, ThreatLabz has diligently monitored its development and operational methods. Notably, there was a surge in Pikabot’s usage in the latter part of 2023, attributed to a BlackBasta ransomware affiliate adopting Pikabot post the FBI-led Qakbot takedown. However, Pikabot’s activity ceased shortly after Christmas 2023, with version 1.1.19 marking its endpoint.
  |  By Adi Bleih
PoshC2 version 6.0, an open-source command and control framework, is notable for its robust capabilities in managing compromised hosts. Accompanying its release, a comprehensive list of Indicators of Compromise (IoCs) and a dedicated GitHub repository have been provided. These resources are designed to assist cybersecurity teams in detecting PoshC2, especially when deployed with its default settings, which less sophisticated attackers often utilize.
  |  By Adi Bleih
Ghost RAT (Remote Access Trojan) is a type of sophisticated malicious software that operates covertly, enabling unauthorized remote access and control of a victim’s computer system. Often deployed with malicious intent by cybercriminals, Ghost RATs are designed to evade detection and provide the attacker with a range of powerful capabilities, such as data theft, system manipulation, and surveillance.
  |  By Adi Bleih
Security analysts have noticed a trend among threat actors shifting towards adopting a novel open-source command and control (C2) framework called Havoc as an alternative to paid solutions like Cobalt Strike and Brute Ratel. Developed in the C language and introduced in 2022, Havoc’s Main branch received updates in 2023.
  |  By Adi Bleih
SparkKitty is a newly uncovered cross-platform information stealer, designed to exfiltrate sensitive data—particularly cryptocurrency wallet seed phrases—by leveraging advanced optical character recognition (OCR) techniques on both Android and iOS devices. The malware, discovered by Kaspersky in early 2024 and publicly detailed in June 2025, appears to be a direct evolution of a previous stealer known as SparkCat.
Check Point Agentic Exposure Validation (AEV) uses AI agents to reason like an attacker across your external footprint. It correlates your assets with live threat intelligence, exploit research, and attacker behavior, and tells you, in minutes, what's actually exploitable and what isn't. No assumptions. No noise. Evidence-backed findings your team can act on immediately.
Exposure Management isn’t just a buzzword; it’s the future of cybersecurity. Attackers move fast, exploiting misconfigurations, leaked credentials, and control gaps before patch cycles even start. Traditional tools give you dashboards and alerts, but visibility without action is just noise.
The question isn’t if something goes wrong, it’s whether you can fix it fast enough….. This is why we built Check Point Exposure Management.
  |  By Cyberint
Safe Remediation is the process of turning validated exposure insights into coordinated, non-disruptive fixes across security controls ensuring teams can reduce risk quickly without breaking production. More specifically, Safe Remediation includes: Validation before enforcement Remediation without downtime Automated, coordinated action across controls Preemptive blocking of attacker infrastructure Safe-by-design automation Safe Remediation ensures that exposures are fixed quickly, automatically, and without operational risk – turning detection into trusted, validated action.
  |  By Cyberint
See how customers can query our MCP server to sift through their threat intelligence and get contextual answers immediately.
  |  By Cyberint
CTEM, introduced by Gartner, was designed to address a critical gap in traditional vulnerability management: the broken flow between detection and remediation. While reports and alerts pile up, exposures often remain unresolved, leaving organizations at risk. CTEM organizes this process into five stages—Scoping, Discovery, Prioritization, Validation, and Mobilization—bringing structure to chaos. Technically, it’s a framework because Gartner never mandated a single solution to deliver all stages. Most vendors only cover one or two.
  |  By Cyberint
When Attack Surface Management (ASM) stops at discovery, teams drown in alerts, CVE lists, and noise. What’s exposed isn’t the same as what’s actively being weaponized—and without prioritization or built-in remediation, risk piles up fast. Exposure Management (EM) closes that gap. It merges threat intelligence, vulnerability context, and safe-by-design remediation into one continuous loop. Instead of “scan → report → wait,” EM delivers.
  |  By Cyberint
See Active Exposure Validation Discovery Context and more.
  |  By Cyberint
Meet Check Point's latest Acquisition Infinity External Risk Management.

Best-in-class managed intelligence suite. We help you identify emerging threats, verify your security posture, and respond effectively to reduce their impact.

CyberInt's Managed Detection and Response services span globally and include some of the top finance, retail and telecommunication organizations. Allowing our customers to combat and respond to advanced cyber threats that would normally go unnoticed by standard security controls, while protecting their brand, digital assets and customers.

Solutions:

  • Threat Intelligence: Real-time monitoring of threats in the deep, dark and open web such as phishing and malware campaigns, brute-force and credential stuffing threats, data leakage, including personal identifiable information (PII), and fraudulent activity.
  • Digital Risk: Digital footprint discovery and ongoing monitoring of organizations’ cloud and external facing assets. Ensuring visibility into assets with severity-based prioritization of issues to address, highlighting related threats, vulnerabilities, and weaknesses.
  • Threat Hunting: Driven by Cyberint proprietary intelligence and custom detections service provides continuous hunt for threats across the IT and infrastructure. Leveraging 3rd party EDR-agnostic technology and SOAR, we deploy proprietary automated playbooks to contain and mitigate threats within minutes.
  • Cybersecurity Assessment: Testing applications and infrastructure’s resilience to cyberattacks, to identify weaknesses and loopholes in your security posture.

Intelligence-driven Detection & Response. Leveraging threat intelligence suite, threat hunting and threat mitigation and response services.