<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" href="https://feeds.fortinet.com/feedblitz_rss.xslt"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/"  version="2.0" xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0"><channel><title>FortiGuard Labs Threat Research</title><description>Official blog feed of Fortinet</description><link>https://www.fortinet.com/bin/fortinet/allblogsrss?search=threat-research</link><lastBuildDate>Thu, 13 Aug 2026 13:04:22 +0000</lastBuildDate><pubDate>Thu, 13 Aug 2026 13:04:22 +0000</pubDate>
<meta xmlns="http://www.w3.org/1999/xhtml" name="robots" content="noindex" />
<item>
<feedburner:origLink>https://www.fortinet.com/blog/threat-research/multi-functional-linux-botnet-evooo1bot</feedburner:origLink><title>Multi-Functional Linux Botnet “Evooo1Bot”</title><description><![CDATA[FortiGuard Labs analyzes Evooo1Bot, a modular Linux botnet targeting internet-facing devices with DDoS, SSH attacks, CVE exploits, and SOCKS relays<div style="clear:both;padding-top:0.2em;"><a title="Like on Facebook" href="https://feeds.fortinet.com/_/28/967797734/fortinet/blog/threat-research"><img height="20" src="https://assets.feedblitz.com/i/fblike20.png" style="border:0;margin:0;padding:0;"></a>&#160;<a title="Pin it!" href="https://feeds.fortinet.com/_/29/967797734/fortinet/blog/threat-research,"><img height="20" src="https://assets.feedblitz.com/i/pinterest20.png" style="border:0;margin:0;padding:0;"></a>&#160;<a title="Post to X.com" href="https://feeds.fortinet.com/_/24/967797734/fortinet/blog/threat-research"><img height="20" src="https://assets.feedblitz.com/i/x.png" style="border:0;margin:0;padding:0;"></a>&#160;<a title="Subscribe by email" href="https://feeds.fortinet.com/_/19/967797734/fortinet/blog/threat-research"><img height="20" src="https://assets.feedblitz.com/i/email20.png" style="border:0;margin:0;padding:0;"></a>&#160;<a title="Subscribe by RSS" href="https://feeds.fortinet.com/_/20/967797734/fortinet/blog/threat-research"><img height="20" src="https://assets.feedblitz.com/i/rss20.png" style="border:0;margin:0;padding:0;"></a>&nbsp;&#160;</div>]]>
</description><link>https://feeds.fortinet.com/~/967797734/0/fortinet/blog/threat-research~MultiFunctional-Linux-Botnet-%e2%80%9cEvoooBot%e2%80%9d</link><pubDate>Thu, 13 Aug 2026 13:00:00 +0000</pubDate><content:encoded><![CDATA[<p>FortiGuard Labs analyzes Evooo1Bot, a modular Linux botnet targeting internet-facing devices with DDoS, SSH attacks, CVE exploits, and SOCKS relays</p><Img align="left" border="0" height="1" width="1" alt="" style="border:0;float:left;margin:0;padding:0;width:1px!important;height:1px!important;" hspace="0" src="https://feeds.fortinet.com/~/i/967797734/0/fortinet/blog/threat-research">
<div style="clear:both;padding-top:0.2em;"><a title="Like on Facebook" href="https://feeds.fortinet.com/_/28/967797734/fortinet/blog/threat-research"><img height="20" src="https://assets.feedblitz.com/i/fblike20.png" style="border:0;margin:0;padding:0;"></a>&#160;<a title="Pin it!" href="https://feeds.fortinet.com/_/29/967797734/fortinet/blog/threat-research,"><img height="20" src="https://assets.feedblitz.com/i/pinterest20.png" style="border:0;margin:0;padding:0;"></a>&#160;<a title="Post to X.com" href="https://feeds.fortinet.com/_/24/967797734/fortinet/blog/threat-research"><img height="20" src="https://assets.feedblitz.com/i/x.png" style="border:0;margin:0;padding:0;"></a>&#160;<a title="Subscribe by email" href="https://feeds.fortinet.com/_/19/967797734/fortinet/blog/threat-research"><img height="20" src="https://assets.feedblitz.com/i/email20.png" style="border:0;margin:0;padding:0;"></a>&#160;<a title="Subscribe by RSS" href="https://feeds.fortinet.com/_/20/967797734/fortinet/blog/threat-research"><img height="20" src="https://assets.feedblitz.com/i/rss20.png" style="border:0;margin:0;padding:0;"></a>&nbsp;&#160;</div>]]>
</content:encoded><guid isPermaLink="false">tag:feedblitz.com,2026-08-13:52270/https://feeds.fortinet.com/~/967797734/0/fortinet/blog/threat-research/cd08e52dbb5afb9b1418fbe06ef6097f</guid></item>
<item>
<feedburner:origLink>https://www.fortinet.com/blog/threat-research/quickfox-supply-chain-attack-used-to-deploy-fdmtp-implant</feedburner:origLink><title>QuickFox Supply Chain Attack Used to Deploy FDMTP Implant</title><description><![CDATA[The FortiGuard Labs Incident Response team analyzes a QuickFox supply chain attack that used trojanized Windows installers, selective targeting, and an evolving FDMTP implant<div style="clear:both;padding-top:0.2em;"><a title="Like on Facebook" href="https://feeds.fortinet.com/_/28/966214247/fortinet/blog/threat-research"><img height="20" src="https://assets.feedblitz.com/i/fblike20.png" style="border:0;margin:0;padding:0;"></a>&#160;<a title="Pin it!" href="https://feeds.fortinet.com/_/29/966214247/fortinet/blog/threat-research,"><img height="20" src="https://assets.feedblitz.com/i/pinterest20.png" style="border:0;margin:0;padding:0;"></a>&#160;<a title="Post to X.com" href="https://feeds.fortinet.com/_/24/966214247/fortinet/blog/threat-research"><img height="20" src="https://assets.feedblitz.com/i/x.png" style="border:0;margin:0;padding:0;"></a>&#160;<a title="Subscribe by email" href="https://feeds.fortinet.com/_/19/966214247/fortinet/blog/threat-research"><img height="20" src="https://assets.feedblitz.com/i/email20.png" style="border:0;margin:0;padding:0;"></a>&#160;<a title="Subscribe by RSS" href="https://feeds.fortinet.com/_/20/966214247/fortinet/blog/threat-research"><img height="20" src="https://assets.feedblitz.com/i/rss20.png" style="border:0;margin:0;padding:0;"></a>&nbsp;&#160;</div>]]>
</description><link>https://feeds.fortinet.com/~/966214247/0/fortinet/blog/threat-research~QuickFox-Supply-Chain-Attack-Used-to-Deploy-FDMTP-Implant</link><pubDate>Tue, 4 Aug 2026 13:00:00 +0000</pubDate><content:encoded><![CDATA[<p>The FortiGuard Labs Incident Response team analyzes a QuickFox supply chain attack that used trojanized Windows installers, selective targeting, and an evolving FDMTP implant</p><Img align="left" border="0" height="1" width="1" alt="" style="border:0;float:left;margin:0;padding:0;width:1px!important;height:1px!important;" hspace="0" src="https://feeds.fortinet.com/~/i/966214247/0/fortinet/blog/threat-research">
<div style="clear:both;padding-top:0.2em;"><a title="Like on Facebook" href="https://feeds.fortinet.com/_/28/966214247/fortinet/blog/threat-research"><img height="20" src="https://assets.feedblitz.com/i/fblike20.png" style="border:0;margin:0;padding:0;"></a>&#160;<a title="Pin it!" href="https://feeds.fortinet.com/_/29/966214247/fortinet/blog/threat-research,"><img height="20" src="https://assets.feedblitz.com/i/pinterest20.png" style="border:0;margin:0;padding:0;"></a>&#160;<a title="Post to X.com" href="https://feeds.fortinet.com/_/24/966214247/fortinet/blog/threat-research"><img height="20" src="https://assets.feedblitz.com/i/x.png" style="border:0;margin:0;padding:0;"></a>&#160;<a title="Subscribe by email" href="https://feeds.fortinet.com/_/19/966214247/fortinet/blog/threat-research"><img height="20" src="https://assets.feedblitz.com/i/email20.png" style="border:0;margin:0;padding:0;"></a>&#160;<a title="Subscribe by RSS" href="https://feeds.fortinet.com/_/20/966214247/fortinet/blog/threat-research"><img height="20" src="https://assets.feedblitz.com/i/rss20.png" style="border:0;margin:0;padding:0;"></a>&nbsp;&#160;</div>]]>
</content:encoded><guid isPermaLink="false">tag:feedblitz.com,2026-08-04:52270/https://feeds.fortinet.com/~/966214247/0/fortinet/blog/threat-research/57af71a04bbe215034ee2e464bc350b8</guid></item>
<item>
<feedburner:origLink>https://www.fortinet.com/blog/threat-research/inside-a-trickbot-variant-using-dns-tunneling-for-c2</feedburner:origLink><title>Inside a TrickBot Variant Using DNS Tunneling for C2</title><description><![CDATA[FortiGuard Labs analyzes a TrickBot variant that uses DNS tunneling for C2 communication, modular execution, and employs persistence and obfuscation techniques<div style="clear:both;padding-top:0.2em;"><a title="Like on Facebook" href="https://feeds.fortinet.com/_/28/961655441/fortinet/blog/threat-research"><img height="20" src="https://assets.feedblitz.com/i/fblike20.png" style="border:0;margin:0;padding:0;"></a>&#160;<a title="Pin it!" href="https://feeds.fortinet.com/_/29/961655441/fortinet/blog/threat-research,"><img height="20" src="https://assets.feedblitz.com/i/pinterest20.png" style="border:0;margin:0;padding:0;"></a>&#160;<a title="Post to X.com" href="https://feeds.fortinet.com/_/24/961655441/fortinet/blog/threat-research"><img height="20" src="https://assets.feedblitz.com/i/x.png" style="border:0;margin:0;padding:0;"></a>&#160;<a title="Subscribe by email" href="https://feeds.fortinet.com/_/19/961655441/fortinet/blog/threat-research"><img height="20" src="https://assets.feedblitz.com/i/email20.png" style="border:0;margin:0;padding:0;"></a>&#160;<a title="Subscribe by RSS" href="https://feeds.fortinet.com/_/20/961655441/fortinet/blog/threat-research"><img height="20" src="https://assets.feedblitz.com/i/rss20.png" style="border:0;margin:0;padding:0;"></a>&nbsp;&#160;</div>]]>
</description><link>https://feeds.fortinet.com/~/961655441/0/fortinet/blog/threat-research~Inside-a-TrickBot-Variant-Using-DNS-Tunneling-for-C</link><pubDate>Wed, 22 Jul 2026 13:00:00 +0000</pubDate><content:encoded><![CDATA[<p>FortiGuard Labs analyzes a TrickBot variant that uses DNS tunneling for C2 communication, modular execution, and employs persistence and obfuscation techniques</p><Img align="left" border="0" height="1" width="1" alt="" style="border:0;float:left;margin:0;padding:0;width:1px!important;height:1px!important;" hspace="0" src="https://feeds.fortinet.com/~/i/961655441/0/fortinet/blog/threat-research">
<div style="clear:both;padding-top:0.2em;"><a title="Like on Facebook" href="https://feeds.fortinet.com/_/28/961655441/fortinet/blog/threat-research"><img height="20" src="https://assets.feedblitz.com/i/fblike20.png" style="border:0;margin:0;padding:0;"></a>&#160;<a title="Pin it!" href="https://feeds.fortinet.com/_/29/961655441/fortinet/blog/threat-research,"><img height="20" src="https://assets.feedblitz.com/i/pinterest20.png" style="border:0;margin:0;padding:0;"></a>&#160;<a title="Post to X.com" href="https://feeds.fortinet.com/_/24/961655441/fortinet/blog/threat-research"><img height="20" src="https://assets.feedblitz.com/i/x.png" style="border:0;margin:0;padding:0;"></a>&#160;<a title="Subscribe by email" href="https://feeds.fortinet.com/_/19/961655441/fortinet/blog/threat-research"><img height="20" src="https://assets.feedblitz.com/i/email20.png" style="border:0;margin:0;padding:0;"></a>&#160;<a title="Subscribe by RSS" href="https://feeds.fortinet.com/_/20/961655441/fortinet/blog/threat-research"><img height="20" src="https://assets.feedblitz.com/i/rss20.png" style="border:0;margin:0;padding:0;"></a>&nbsp;&#160;</div>]]>
</content:encoded><guid isPermaLink="false">tag:feedblitz.com,2026-07-22:52270/https://feeds.fortinet.com/~/961655441/0/fortinet/blog/threat-research/876fb1c326b98a22cf930cd48b08a5a8</guid></item>
<item>
<feedburner:origLink>https://www.fortinet.com/blog/threat-research/the-ttf-trap-a-global-campaign-of-a-low-detection-lua-loader</feedburner:origLink><title>The TTF Trap: A Global Campaign of a Low-Detection Lua Loader</title><description><![CDATA[FortiGuard Labs analyzes a global phishing campaign using obfuscated JScript, disguised .ttf files, and Lua loaders to deliver RATs and infostealers.<div style="clear:both;padding-top:0.2em;"><a title="Like on Facebook" href="https://feeds.fortinet.com/_/28/960560447/fortinet/blog/threat-research"><img height="20" src="https://assets.feedblitz.com/i/fblike20.png" style="border:0;margin:0;padding:0;"></a>&#160;<a title="Pin it!" href="https://feeds.fortinet.com/_/29/960560447/fortinet/blog/threat-research,"><img height="20" src="https://assets.feedblitz.com/i/pinterest20.png" style="border:0;margin:0;padding:0;"></a>&#160;<a title="Post to X.com" href="https://feeds.fortinet.com/_/24/960560447/fortinet/blog/threat-research"><img height="20" src="https://assets.feedblitz.com/i/x.png" style="border:0;margin:0;padding:0;"></a>&#160;<a title="Subscribe by email" href="https://feeds.fortinet.com/_/19/960560447/fortinet/blog/threat-research"><img height="20" src="https://assets.feedblitz.com/i/email20.png" style="border:0;margin:0;padding:0;"></a>&#160;<a title="Subscribe by RSS" href="https://feeds.fortinet.com/_/20/960560447/fortinet/blog/threat-research"><img height="20" src="https://assets.feedblitz.com/i/rss20.png" style="border:0;margin:0;padding:0;"></a>&nbsp;&#160;</div>]]>
</description><link>https://feeds.fortinet.com/~/960560447/0/fortinet/blog/threat-research~The-TTF-Trap-A-Global-Campaign-of-a-LowDetection-Lua-Loader</link><pubDate>Thu, 16 Jul 2026 13:00:00 +0000</pubDate><content:encoded><![CDATA[<p>FortiGuard Labs analyzes a global phishing campaign using obfuscated JScript, disguised .ttf files, and Lua loaders to deliver RATs and infostealers.</p><Img align="left" border="0" height="1" width="1" alt="" style="border:0;float:left;margin:0;padding:0;width:1px!important;height:1px!important;" hspace="0" src="https://feeds.fortinet.com/~/i/960560447/0/fortinet/blog/threat-research">
<div style="clear:both;padding-top:0.2em;"><a title="Like on Facebook" href="https://feeds.fortinet.com/_/28/960560447/fortinet/blog/threat-research"><img height="20" src="https://assets.feedblitz.com/i/fblike20.png" style="border:0;margin:0;padding:0;"></a>&#160;<a title="Pin it!" href="https://feeds.fortinet.com/_/29/960560447/fortinet/blog/threat-research,"><img height="20" src="https://assets.feedblitz.com/i/pinterest20.png" style="border:0;margin:0;padding:0;"></a>&#160;<a title="Post to X.com" href="https://feeds.fortinet.com/_/24/960560447/fortinet/blog/threat-research"><img height="20" src="https://assets.feedblitz.com/i/x.png" style="border:0;margin:0;padding:0;"></a>&#160;<a title="Subscribe by email" href="https://feeds.fortinet.com/_/19/960560447/fortinet/blog/threat-research"><img height="20" src="https://assets.feedblitz.com/i/email20.png" style="border:0;margin:0;padding:0;"></a>&#160;<a title="Subscribe by RSS" href="https://feeds.fortinet.com/_/20/960560447/fortinet/blog/threat-research"><img height="20" src="https://assets.feedblitz.com/i/rss20.png" style="border:0;margin:0;padding:0;"></a>&nbsp;&#160;</div>]]>
</content:encoded><guid isPermaLink="false">tag:feedblitz.com,2026-07-16:52270/https://feeds.fortinet.com/~/960560447/0/fortinet/blog/threat-research/18c72b2b300a2299e78e4643238cf746</guid></item>
<item>
<feedburner:origLink>https://www.fortinet.com/blog/threat-research/analysis-of-ongoing-ousaban-attacks-targeting-the-iberian-peninsula</feedburner:origLink><title>Analysis of Ongoing Ousaban Attacks Targeting the Iberian Peninsula</title><description><![CDATA[FortiGuard Labs analyzes a geofenced Ousaban campaign targeting Spain and Portugal with phishing PDFs, steganography, and evasive C2.<div style="clear:both;padding-top:0.2em;"><a title="Like on Facebook" href="https://feeds.fortinet.com/_/28/958831322/fortinet/blog/threat-research"><img height="20" src="https://assets.feedblitz.com/i/fblike20.png" style="border:0;margin:0;padding:0;"></a>&#160;<a title="Pin it!" href="https://feeds.fortinet.com/_/29/958831322/fortinet/blog/threat-research,"><img height="20" src="https://assets.feedblitz.com/i/pinterest20.png" style="border:0;margin:0;padding:0;"></a>&#160;<a title="Post to X.com" href="https://feeds.fortinet.com/_/24/958831322/fortinet/blog/threat-research"><img height="20" src="https://assets.feedblitz.com/i/x.png" style="border:0;margin:0;padding:0;"></a>&#160;<a title="Subscribe by email" href="https://feeds.fortinet.com/_/19/958831322/fortinet/blog/threat-research"><img height="20" src="https://assets.feedblitz.com/i/email20.png" style="border:0;margin:0;padding:0;"></a>&#160;<a title="Subscribe by RSS" href="https://feeds.fortinet.com/_/20/958831322/fortinet/blog/threat-research"><img height="20" src="https://assets.feedblitz.com/i/rss20.png" style="border:0;margin:0;padding:0;"></a>&nbsp;&#160;</div>]]>
</description><link>https://feeds.fortinet.com/~/958831322/0/fortinet/blog/threat-research~Analysis-of-Ongoing-Ousaban-Attacks-Targeting-the-Iberian-Peninsula</link><pubDate>Wed, 1 Jul 2026 13:00:00 +0000</pubDate><content:encoded><![CDATA[<p>FortiGuard Labs analyzes a geofenced Ousaban campaign targeting Spain and Portugal with phishing PDFs, steganography, and evasive C2.</p><Img align="left" border="0" height="1" width="1" alt="" style="border:0;float:left;margin:0;padding:0;width:1px!important;height:1px!important;" hspace="0" src="https://feeds.fortinet.com/~/i/958831322/0/fortinet/blog/threat-research">
<div style="clear:both;padding-top:0.2em;"><a title="Like on Facebook" href="https://feeds.fortinet.com/_/28/958831322/fortinet/blog/threat-research"><img height="20" src="https://assets.feedblitz.com/i/fblike20.png" style="border:0;margin:0;padding:0;"></a>&#160;<a title="Pin it!" href="https://feeds.fortinet.com/_/29/958831322/fortinet/blog/threat-research,"><img height="20" src="https://assets.feedblitz.com/i/pinterest20.png" style="border:0;margin:0;padding:0;"></a>&#160;<a title="Post to X.com" href="https://feeds.fortinet.com/_/24/958831322/fortinet/blog/threat-research"><img height="20" src="https://assets.feedblitz.com/i/x.png" style="border:0;margin:0;padding:0;"></a>&#160;<a title="Subscribe by email" href="https://feeds.fortinet.com/_/19/958831322/fortinet/blog/threat-research"><img height="20" src="https://assets.feedblitz.com/i/email20.png" style="border:0;margin:0;padding:0;"></a>&#160;<a title="Subscribe by RSS" href="https://feeds.fortinet.com/_/20/958831322/fortinet/blog/threat-research"><img height="20" src="https://assets.feedblitz.com/i/rss20.png" style="border:0;margin:0;padding:0;"></a>&nbsp;&#160;</div>]]>
</content:encoded><guid isPermaLink="false">tag:feedblitz.com,2026-07-01:52270/https://feeds.fortinet.com/~/958831322/0/fortinet/blog/threat-research/90c5d308742ceffa328646c3a7854149</guid></item>
<item>
<feedburner:origLink>https://www.fortinet.com/blog/threat-research/from-ci-cd-to-cloud-data-how-shai-hulud-persistence-leads-to-redshift-breach</feedburner:origLink><title>From CI/CD to Cloud Data: How Shai Hulud Persistence Leads to Redshift Breach</title><description><![CDATA[See how Shai Hulud-linked CI/CD compromise exposed Jenkins credentials, enabled AWS escalation, and led to Redshift breach activity detected by FortiCNAPP<div style="clear:both;padding-top:0.2em;"><a title="Like on Facebook" href="https://feeds.fortinet.com/_/28/958459373/fortinet/blog/threat-research"><img height="20" src="https://assets.feedblitz.com/i/fblike20.png" style="border:0;margin:0;padding:0;"></a>&#160;<a title="Pin it!" href="https://feeds.fortinet.com/_/29/958459373/fortinet/blog/threat-research,"><img height="20" src="https://assets.feedblitz.com/i/pinterest20.png" style="border:0;margin:0;padding:0;"></a>&#160;<a title="Post to X.com" href="https://feeds.fortinet.com/_/24/958459373/fortinet/blog/threat-research"><img height="20" src="https://assets.feedblitz.com/i/x.png" style="border:0;margin:0;padding:0;"></a>&#160;<a title="Subscribe by email" href="https://feeds.fortinet.com/_/19/958459373/fortinet/blog/threat-research"><img height="20" src="https://assets.feedblitz.com/i/email20.png" style="border:0;margin:0;padding:0;"></a>&#160;<a title="Subscribe by RSS" href="https://feeds.fortinet.com/_/20/958459373/fortinet/blog/threat-research"><img height="20" src="https://assets.feedblitz.com/i/rss20.png" style="border:0;margin:0;padding:0;"></a>&nbsp;&#160;</div>]]>
</description><link>https://feeds.fortinet.com/~/958459373/0/fortinet/blog/threat-research~From-CICD-to-Cloud-Data-How-Shai-Hulud-Persistence-Leads-to-Redshift-Breach</link><pubDate>Fri, 26 Jun 2026 13:00:00 +0000</pubDate><content:encoded><![CDATA[<p>See how Shai Hulud-linked CI/CD compromise exposed Jenkins credentials, enabled AWS escalation, and led to Redshift breach activity detected by FortiCNAPP</p><Img align="left" border="0" height="1" width="1" alt="" style="border:0;float:left;margin:0;padding:0;width:1px!important;height:1px!important;" hspace="0" src="https://feeds.fortinet.com/~/i/958459373/0/fortinet/blog/threat-research">
<div style="clear:both;padding-top:0.2em;"><a title="Like on Facebook" href="https://feeds.fortinet.com/_/28/958459373/fortinet/blog/threat-research"><img height="20" src="https://assets.feedblitz.com/i/fblike20.png" style="border:0;margin:0;padding:0;"></a>&#160;<a title="Pin it!" href="https://feeds.fortinet.com/_/29/958459373/fortinet/blog/threat-research,"><img height="20" src="https://assets.feedblitz.com/i/pinterest20.png" style="border:0;margin:0;padding:0;"></a>&#160;<a title="Post to X.com" href="https://feeds.fortinet.com/_/24/958459373/fortinet/blog/threat-research"><img height="20" src="https://assets.feedblitz.com/i/x.png" style="border:0;margin:0;padding:0;"></a>&#160;<a title="Subscribe by email" href="https://feeds.fortinet.com/_/19/958459373/fortinet/blog/threat-research"><img height="20" src="https://assets.feedblitz.com/i/email20.png" style="border:0;margin:0;padding:0;"></a>&#160;<a title="Subscribe by RSS" href="https://feeds.fortinet.com/_/20/958459373/fortinet/blog/threat-research"><img height="20" src="https://assets.feedblitz.com/i/rss20.png" style="border:0;margin:0;padding:0;"></a>&nbsp;&#160;</div>]]>
</content:encoded><guid isPermaLink="false">tag:feedblitz.com,2026-06-26:52270/https://feeds.fortinet.com/~/958459373/0/fortinet/blog/threat-research/8e6b166c0d81d3b3e79582594b0422b5</guid></item>
<item>
<feedburner:origLink>https://www.fortinet.com/blog/threat-research/threat-actors-weaponize-ai-hype-to-deliver-asyncrat</feedburner:origLink><title>Threat Actors Weaponize AI Hype to Deliver AsyncRAT</title><description><![CDATA[FortiGuard Labs analyzes a multi-stage malware campaign that uses fake AI-themed documents, hidden PowerShell scripts, AutoHotkey loaders, and process injection to deploy AsyncRAT and maintain remote access.<div style="clear:both;padding-top:0.2em;"><a title="Like on Facebook" href="https://feeds.fortinet.com/_/28/957950855/fortinet/blog/threat-research"><img height="20" src="https://assets.feedblitz.com/i/fblike20.png" style="border:0;margin:0;padding:0;"></a>&#160;<a title="Pin it!" href="https://feeds.fortinet.com/_/29/957950855/fortinet/blog/threat-research,"><img height="20" src="https://assets.feedblitz.com/i/pinterest20.png" style="border:0;margin:0;padding:0;"></a>&#160;<a title="Post to X.com" href="https://feeds.fortinet.com/_/24/957950855/fortinet/blog/threat-research"><img height="20" src="https://assets.feedblitz.com/i/x.png" style="border:0;margin:0;padding:0;"></a>&#160;<a title="Subscribe by email" href="https://feeds.fortinet.com/_/19/957950855/fortinet/blog/threat-research"><img height="20" src="https://assets.feedblitz.com/i/email20.png" style="border:0;margin:0;padding:0;"></a>&#160;<a title="Subscribe by RSS" href="https://feeds.fortinet.com/_/20/957950855/fortinet/blog/threat-research"><img height="20" src="https://assets.feedblitz.com/i/rss20.png" style="border:0;margin:0;padding:0;"></a>&nbsp;&#160;</div>]]>
</description><link>https://feeds.fortinet.com/~/957950855/0/fortinet/blog/threat-research~Threat-Actors-Weaponize-AI-Hype-to-Deliver-AsyncRAT</link><pubDate>Thu, 11 Jun 2026 13:00:00 +0000</pubDate><content:encoded><![CDATA[<p>FortiGuard Labs analyzes a multi-stage malware campaign that uses fake AI-themed documents, hidden PowerShell scripts, AutoHotkey loaders, and process injection to deploy AsyncRAT and maintain remote access.</p><Img align="left" border="0" height="1" width="1" alt="" style="border:0;float:left;margin:0;padding:0;width:1px!important;height:1px!important;" hspace="0" src="https://feeds.fortinet.com/~/i/957950855/0/fortinet/blog/threat-research">
<div style="clear:both;padding-top:0.2em;"><a title="Like on Facebook" href="https://feeds.fortinet.com/_/28/957950855/fortinet/blog/threat-research"><img height="20" src="https://assets.feedblitz.com/i/fblike20.png" style="border:0;margin:0;padding:0;"></a>&#160;<a title="Pin it!" href="https://feeds.fortinet.com/_/29/957950855/fortinet/blog/threat-research,"><img height="20" src="https://assets.feedblitz.com/i/pinterest20.png" style="border:0;margin:0;padding:0;"></a>&#160;<a title="Post to X.com" href="https://feeds.fortinet.com/_/24/957950855/fortinet/blog/threat-research"><img height="20" src="https://assets.feedblitz.com/i/x.png" style="border:0;margin:0;padding:0;"></a>&#160;<a title="Subscribe by email" href="https://feeds.fortinet.com/_/19/957950855/fortinet/blog/threat-research"><img height="20" src="https://assets.feedblitz.com/i/email20.png" style="border:0;margin:0;padding:0;"></a>&#160;<a title="Subscribe by RSS" href="https://feeds.fortinet.com/_/20/957950855/fortinet/blog/threat-research"><img height="20" src="https://assets.feedblitz.com/i/rss20.png" style="border:0;margin:0;padding:0;"></a>&nbsp;&#160;</div>]]>
</content:encoded><guid isPermaLink="false">tag:feedblitz.com,2026-06-11:52270/https://feeds.fortinet.com/~/957950855/0/fortinet/blog/threat-research/307ed6968978bae348be04748ff63703</guid></item>
<item>
<feedburner:origLink>https://www.fortinet.com/blog/threat-research/cybercriminals-are-targeting-the-fifa-world-cup-2026</feedburner:origLink><title>Cybercriminals Are Targeting the FIFA World Cup 2026</title><description><![CDATA[FortiGuard Labs research shows how cybercriminals are exploiting the demand for the FIFA World Cup 2026 through phishing, fake tickets, malware, impersonation, and credential theft.<div style="clear:both;padding-top:0.2em;"><a title="Like on Facebook" href="https://feeds.fortinet.com/_/28/957732002/fortinet/blog/threat-research"><img height="20" src="https://assets.feedblitz.com/i/fblike20.png" style="border:0;margin:0;padding:0;"></a>&#160;<a title="Pin it!" href="https://feeds.fortinet.com/_/29/957732002/fortinet/blog/threat-research,"><img height="20" src="https://assets.feedblitz.com/i/pinterest20.png" style="border:0;margin:0;padding:0;"></a>&#160;<a title="Post to X.com" href="https://feeds.fortinet.com/_/24/957732002/fortinet/blog/threat-research"><img height="20" src="https://assets.feedblitz.com/i/x.png" style="border:0;margin:0;padding:0;"></a>&#160;<a title="Subscribe by email" href="https://feeds.fortinet.com/_/19/957732002/fortinet/blog/threat-research"><img height="20" src="https://assets.feedblitz.com/i/email20.png" style="border:0;margin:0;padding:0;"></a>&#160;<a title="Subscribe by RSS" href="https://feeds.fortinet.com/_/20/957732002/fortinet/blog/threat-research"><img height="20" src="https://assets.feedblitz.com/i/rss20.png" style="border:0;margin:0;padding:0;"></a>&nbsp;&#160;</div>]]>
</description><link>https://feeds.fortinet.com/~/957732002/0/fortinet/blog/threat-research~Cybercriminals-Are-Targeting-the-FIFA-World-Cup</link><pubDate>Thu, 4 Jun 2026 13:00:00 +0000</pubDate><content:encoded><![CDATA[<p>FortiGuard Labs research shows how cybercriminals are exploiting the demand for the FIFA World Cup 2026 through phishing, fake tickets, malware, impersonation, and credential theft.</p><Img align="left" border="0" height="1" width="1" alt="" style="border:0;float:left;margin:0;padding:0;width:1px!important;height:1px!important;" hspace="0" src="https://feeds.fortinet.com/~/i/957732002/0/fortinet/blog/threat-research">
<div style="clear:both;padding-top:0.2em;"><a title="Like on Facebook" href="https://feeds.fortinet.com/_/28/957732002/fortinet/blog/threat-research"><img height="20" src="https://assets.feedblitz.com/i/fblike20.png" style="border:0;margin:0;padding:0;"></a>&#160;<a title="Pin it!" href="https://feeds.fortinet.com/_/29/957732002/fortinet/blog/threat-research,"><img height="20" src="https://assets.feedblitz.com/i/pinterest20.png" style="border:0;margin:0;padding:0;"></a>&#160;<a title="Post to X.com" href="https://feeds.fortinet.com/_/24/957732002/fortinet/blog/threat-research"><img height="20" src="https://assets.feedblitz.com/i/x.png" style="border:0;margin:0;padding:0;"></a>&#160;<a title="Subscribe by email" href="https://feeds.fortinet.com/_/19/957732002/fortinet/blog/threat-research"><img height="20" src="https://assets.feedblitz.com/i/email20.png" style="border:0;margin:0;padding:0;"></a>&#160;<a title="Subscribe by RSS" href="https://feeds.fortinet.com/_/20/957732002/fortinet/blog/threat-research"><img height="20" src="https://assets.feedblitz.com/i/rss20.png" style="border:0;margin:0;padding:0;"></a>&nbsp;&#160;</div>]]>
</content:encoded><guid isPermaLink="false">tag:feedblitz.com,2026-06-04:52270/https://feeds.fortinet.com/~/957732002/0/fortinet/blog/threat-research/b1a192435d334a3454a5c9123957908d</guid></item>
<item>
<feedburner:origLink>https://www.fortinet.com/blog/threat-research/inside-cross-platform-propagation-of-new-gafgyt-variant-c0xmo</feedburner:origLink><title>Inside the Cross-Platform Propagation of a New Gafgyt Variant C0XMO</title><description><![CDATA[FortiGuard Labs analyzes C0XMO, a new Gafgyt variant leveraging DD-WRT exploitation and multi-architecture propagation to expand IoT botnet infections.<div style="clear:both;padding-top:0.2em;"><a title="Like on Facebook" href="https://feeds.fortinet.com/_/28/957685901/fortinet/blog/threat-research"><img height="20" src="https://assets.feedblitz.com/i/fblike20.png" style="border:0;margin:0;padding:0;"></a>&#160;<a title="Pin it!" href="https://feeds.fortinet.com/_/29/957685901/fortinet/blog/threat-research,"><img height="20" src="https://assets.feedblitz.com/i/pinterest20.png" style="border:0;margin:0;padding:0;"></a>&#160;<a title="Post to X.com" href="https://feeds.fortinet.com/_/24/957685901/fortinet/blog/threat-research"><img height="20" src="https://assets.feedblitz.com/i/x.png" style="border:0;margin:0;padding:0;"></a>&#160;<a title="Subscribe by email" href="https://feeds.fortinet.com/_/19/957685901/fortinet/blog/threat-research"><img height="20" src="https://assets.feedblitz.com/i/email20.png" style="border:0;margin:0;padding:0;"></a>&#160;<a title="Subscribe by RSS" href="https://feeds.fortinet.com/_/20/957685901/fortinet/blog/threat-research"><img height="20" src="https://assets.feedblitz.com/i/rss20.png" style="border:0;margin:0;padding:0;"></a>&nbsp;&#160;</div>]]>
</description><link>https://feeds.fortinet.com/~/957685901/0/fortinet/blog/threat-research~Inside-the-CrossPlatform-Propagation-of-a-New-Gafgyt-Variant-CXMO</link><pubDate>Wed, 3 Jun 2026 13:00:00 +0000</pubDate><content:encoded><![CDATA[<p>FortiGuard Labs analyzes C0XMO, a new Gafgyt variant leveraging DD-WRT exploitation and multi-architecture propagation to expand IoT botnet infections.</p><Img align="left" border="0" height="1" width="1" alt="" style="border:0;float:left;margin:0;padding:0;width:1px!important;height:1px!important;" hspace="0" src="https://feeds.fortinet.com/~/i/957685901/0/fortinet/blog/threat-research">
<div style="clear:both;padding-top:0.2em;"><a title="Like on Facebook" href="https://feeds.fortinet.com/_/28/957685901/fortinet/blog/threat-research"><img height="20" src="https://assets.feedblitz.com/i/fblike20.png" style="border:0;margin:0;padding:0;"></a>&#160;<a title="Pin it!" href="https://feeds.fortinet.com/_/29/957685901/fortinet/blog/threat-research,"><img height="20" src="https://assets.feedblitz.com/i/pinterest20.png" style="border:0;margin:0;padding:0;"></a>&#160;<a title="Post to X.com" href="https://feeds.fortinet.com/_/24/957685901/fortinet/blog/threat-research"><img height="20" src="https://assets.feedblitz.com/i/x.png" style="border:0;margin:0;padding:0;"></a>&#160;<a title="Subscribe by email" href="https://feeds.fortinet.com/_/19/957685901/fortinet/blog/threat-research"><img height="20" src="https://assets.feedblitz.com/i/email20.png" style="border:0;margin:0;padding:0;"></a>&#160;<a title="Subscribe by RSS" href="https://feeds.fortinet.com/_/20/957685901/fortinet/blog/threat-research"><img height="20" src="https://assets.feedblitz.com/i/rss20.png" style="border:0;margin:0;padding:0;"></a>&nbsp;&#160;</div>]]>
</content:encoded><guid isPermaLink="false">tag:feedblitz.com,2026-06-03:52270/https://feeds.fortinet.com/~/957685901/0/fortinet/blog/threat-research/336daefa36449291584333071f530561</guid></item>
<item>
<feedburner:origLink>https://www.fortinet.com/blog/threat-research/phishing-campaign-deploys-javascript-driven-purelogs-variant-to-steal-sensitive-data</feedburner:origLink><title>Phishing Campaign Deploys JavaScript-Driven PureLogs Variant to Steal Sensitive Data</title><description><![CDATA[FortiGuard Labs analyzed a new phishing campaign that uses obfuscated JavaScript, PowerShell, process hollowing, and PureLogs to steal sensitive data<div style="clear:both;padding-top:0.2em;"><a title="Like on Facebook" href="https://feeds.fortinet.com/_/28/957300263/fortinet/blog/threat-research"><img height="20" src="https://assets.feedblitz.com/i/fblike20.png" style="border:0;margin:0;padding:0;"></a>&#160;<a title="Pin it!" href="https://feeds.fortinet.com/_/29/957300263/fortinet/blog/threat-research,"><img height="20" src="https://assets.feedblitz.com/i/pinterest20.png" style="border:0;margin:0;padding:0;"></a>&#160;<a title="Post to X.com" href="https://feeds.fortinet.com/_/24/957300263/fortinet/blog/threat-research"><img height="20" src="https://assets.feedblitz.com/i/x.png" style="border:0;margin:0;padding:0;"></a>&#160;<a title="Subscribe by email" href="https://feeds.fortinet.com/_/19/957300263/fortinet/blog/threat-research"><img height="20" src="https://assets.feedblitz.com/i/email20.png" style="border:0;margin:0;padding:0;"></a>&#160;<a title="Subscribe by RSS" href="https://feeds.fortinet.com/_/20/957300263/fortinet/blog/threat-research"><img height="20" src="https://assets.feedblitz.com/i/rss20.png" style="border:0;margin:0;padding:0;"></a>&nbsp;&#160;</div>]]>
</description><link>https://feeds.fortinet.com/~/957300263/0/fortinet/blog/threat-research~Phishing-Campaign-Deploys-JavaScriptDriven-PureLogs-Variant-to-Steal-Sensitive-Data</link><pubDate>Tue, 26 May 2026 13:00:00 +0000</pubDate><content:encoded><![CDATA[<p>FortiGuard Labs analyzed a new phishing campaign that uses obfuscated JavaScript, PowerShell, process hollowing, and PureLogs to steal sensitive data</p><Img align="left" border="0" height="1" width="1" alt="" style="border:0;float:left;margin:0;padding:0;width:1px!important;height:1px!important;" hspace="0" src="https://feeds.fortinet.com/~/i/957300263/0/fortinet/blog/threat-research">
<div style="clear:both;padding-top:0.2em;"><a title="Like on Facebook" href="https://feeds.fortinet.com/_/28/957300263/fortinet/blog/threat-research"><img height="20" src="https://assets.feedblitz.com/i/fblike20.png" style="border:0;margin:0;padding:0;"></a>&#160;<a title="Pin it!" href="https://feeds.fortinet.com/_/29/957300263/fortinet/blog/threat-research,"><img height="20" src="https://assets.feedblitz.com/i/pinterest20.png" style="border:0;margin:0;padding:0;"></a>&#160;<a title="Post to X.com" href="https://feeds.fortinet.com/_/24/957300263/fortinet/blog/threat-research"><img height="20" src="https://assets.feedblitz.com/i/x.png" style="border:0;margin:0;padding:0;"></a>&#160;<a title="Subscribe by email" href="https://feeds.fortinet.com/_/19/957300263/fortinet/blog/threat-research"><img height="20" src="https://assets.feedblitz.com/i/email20.png" style="border:0;margin:0;padding:0;"></a>&#160;<a title="Subscribe by RSS" href="https://feeds.fortinet.com/_/20/957300263/fortinet/blog/threat-research"><img height="20" src="https://assets.feedblitz.com/i/rss20.png" style="border:0;margin:0;padding:0;"></a>&nbsp;&#160;</div>]]>
</content:encoded><guid isPermaLink="false">tag:feedblitz.com,2026-05-26:52270/https://feeds.fortinet.com/~/957300263/0/fortinet/blog/threat-research/a527595fa5e43df50d2222627ab904dd</guid></item>
</channel></rss>

