[Op Report] Velvet Tempest linked to ClickFix campaigns for Termite Ransomware, HoK Activity Observed
MalBeacon MalBeacon

[Op Report] Velvet Tempest linked to ClickFix campaigns for Termite Ransomware, HoK Activity Observed

A recent deception operation shows Velvet Tempest leaning on a “ClickFix”-style lure to move fast from initial access into hands-on-keyboard activity consistent with Termite ransomware operations. In this post, we break down the timeline, highlight the most actionable indicators of compromise, and translate the tradecraft into practical defender takeaways—including where deception can turn attacker momentum into instant signal.

Read More
[Op Report] Hands-on-Keyboard Intrusion Abusing Multiple RMMs
MalBeacon MalBeacon

[Op Report] Hands-on-Keyboard Intrusion Abusing Multiple RMMs

Proofpoint observed a hands-on-keyboard intrusion where an operator abused multiple RMM platforms—including Bluetrait, Fleetdeck, Level, and MSP360—after initial access via a malicious PDF “missing Adobe plugin” lure. The activity underscores a growing reality: attackers are increasingly using legitimate IT tooling as a resilient intrusion framework.

Read More
[Update] Deception.Pro Jan 2026
MalBeacon MalBeacon

[Update] Deception.Pro Jan 2026

The January 2026 Deception.Pro update introduces industry based replica browsing for Premium users, expanded and more reliable malware auto detonation across common delivery formats, improved artifact handling with VirusTotal linking, and broad stability enhancements, while laying the groundwork for dedicated KVM infrastructure, TLS inspection, and memory dump support.

Read More