The early transfer into Task Scheduler explains the privilege model: subsequent components inherit its SYSTEM token. The deployment DLL starts the RAT from memory while separately writing a persistent ...
The top endpoint security vendors in 2026 are the established leaders in endpoint protection platforms (EPP) and endpoint detection and response (EDR): CrowdStrike, Microsoft, SentinelOne, and Palo ...
Access practical and actionable anti-ransomware, exposure management and automated moving target defense insights and ...
RevStealer is a Windows information stealer delivered inside a trojanized Electron desktop application that impersonates legitimate software. Morphisec Threat Labs observed it distributed through ...
Endpoint Detection and Response (EDR) fundamentally changed enterprise cybersecurity. For the past decade, EDR platforms have given security teams unprecedented visibility into endpoint activity, ...
Most enterprise security stacks today are built around detection and response capabilities, identifying threats, generating alerts, and responding as quickly as possible. But modern ransomware attacks ...
AI is no longer just a productivity tool. It’s a weapon. Threat actors are using AI to automate reconnaissance, generate polymorphic malware, accelerate exploit development, and bypass traditional ...
As the geopolitical landscape continues to evolve, Morphisec Threat Labs is bringing technical focus to threats that have gone under-analyzed. Pay2Key, an Iranian-attributed ransomware group, has not ...
Hey folks in the threat hunting world – it looks like our coverage of the Noodlophile infostealer has struck a nerve with its creators. Back in May 2025, Morphisec first uncovered this sneaky piece of ...
Ransomware isn’t slowing down. It’s scaling, adapting, and finding new ways to slip past defenses that many organizations still trust implicitly. The Ransomware Reality Check 2026 infographic paints a ...
Attackers are no longer relying on phishing emails or malicious documents to compromise organizations. They’ve shifted their focus to something far more powerful…the trust developers place in ...
When Malware Hides in Plain Sight: How Morphisec Blocked a Tuoni C2 Attack Before It Became a Breach
Cybercriminals no longer just launch ransomware. They infiltrate quietly, blend in, harvest credentials, and wait (sometimes for months) before striking. That’s exactly what Morphisec Threat Labs ...
Some results have been hidden because they may be inaccessible to you
Show inaccessible results