{"id":51519,"date":"2023-04-18T16:54:31","date_gmt":"2023-04-18T16:54:31","guid":{"rendered":"https:\/\/packetstormsecurity.com\/news\/view\/34529\/New-Lockbit-Variant-Targets-MacOS-Another-Relies-On-Conti-Source-Code.html"},"modified":"2023-04-18T16:54:31","modified_gmt":"2023-04-18T16:54:31","slug":"new-lockbit-variant-targets-macos-another-relies-on-conti-source-code","status":"publish","type":"post","link":"https:\/\/www.threatshub.org\/blog\/new-lockbit-variant-targets-macos-another-relies-on-conti-source-code\/","title":{"rendered":"New Lockbit Variant Targets MacOS, Another Relies On Conti Source Code"},"content":{"rendered":"<div><img decoding=\"async\" src=\"https:\/\/files.scmagazine.com\/wp-content\/uploads\/2021\/11\/image2-1.jpg\" class=\"ff-og-image-inserted\"><\/div>\n<p>LockBit, known for the effective evolution of its tactics, has again modified its variant. In one instance, the ransomware strain was seen targeting Mac devices \u2014 the first of its kind for a major ransomware operation.<\/p>\n<p>Patrick Wardle,<a href=\"https:\/\/objective-see.org\/blog\/blog_0x75.html\"> founder of nonprofit ObjectiveSee, was first<\/a> to spot a Twitter post from MalwareHunter, which revealed a potential LockBit ransomware sample targeting MacOS. The ransomware binary was initially undetected by traditional anti-virus tools, but has since begun catching the malicious files.<\/p>\n<p>However, Wardle was quick to point out that while the fresh LockBit sample can indeed run on Apple products, \u201cit\u2019s basically the extent of its impact.\u201d As noted, \u201cThe codesign utility shows that though it\u2019s signed, it\u2019s signed &#8216;ad-hoc&#8217; (say vs. an Apple Developer ID).\u201d<\/p>\n<p>\u201cThis means if downloaded to a macOS system, i.e. deployed by the attackers, macOS won\u2019t let it run,\u201d Wardle explained. \u201cThis is confirmed by the spctl utility which shows \u2018invalid signature.\u2019\u201d<\/p>\n<p>The sample also suggests that it was initially designed to run on Windows. In fact, several sample strings contained nothing that specifically related to MacOS, which may mean the \u201ccode is simply a recompile of LockBit ransomware that targets Windows, Linux, and also VMWare ESXi.<\/p>\n<p>So while it\u2019s notable that a LockBit sample has been found targeting MacOS, it\u2019s unlikely the current variant will impact the average user, Wardle stressed. What\u2019s important is to maintain ongoing conversations about detection and prevention of these kinds of threats.<\/p>\n<h2>LockBit now borrowing code from Conti<\/h2>\n<p>In another fresh campaign, the ransomware appears to rely on the source code of Conti, another highly effective variant. After Conti was disbanded in May 2021, an affiliate leaked the source code of the group that enabled other cybercrime groups to recover the code for future use.<\/p>\n<p>In a <a href=\"https:\/\/www.glimps.fr\/dcouverte-dune-nouvelle-version-du-ramsomware-lockbit\/\" target=\"_blank\" rel=\"noreferrer noopener\">sample observed by Glimps researchers<\/a>, LockBit embedded functions previously used by past interactions of LockBit and Conti family binaries. It was this apparent connection that prompted further analysis and confirmed Conti connections, as well as TrickBot and Bazaloader.<\/p>\n<p>TrickBot was previously employed by the Conti group, which reaffirms the connection. But the BazaLoader tie \u201cis a little more subtle.\u201d Like Lockbit, the group has also been observed using the leaked Conti code.<\/p>\n<p>Glimps was also able to examine LockBit\u2019s payment portal and the group\u2019s ransom note, which found evidence of multiple fresh LockBit variants. The ransom note structure bore similarities to previous variants, while the newly detected strains rely on a string of random characters instead of the .lockbit extension.<\/p>\n<p>\u201cThe different results produced by the analyzes\u2026 confirm what we initially thought: We are indeed faced with variants of Lockbit that shamelessly rely on Conti code, the Lockbit Green version,\u201d researchers wrote.<\/p>\n<p>LockBit is well known for its constant evolution, which has enabled a host of successful attacks across a<a href=\"https:\/\/www.scmagazine.com\/analysis\/ransomware\/blackcat-lockbit-3-0-ransomware-target-healthcare-with-customizable-tactics-triple-extortion\" target=\"_blank\" rel=\"noreferrer noopener\"> range of sectors like healthcare<\/a>. The variant has remained the top attack vector in most<a href=\"https:\/\/www.scmagazine.com\/analysis\/ransomware\/royal-overtakes-lockbit-as-top-ransomware-in-november-as-attacks-increase-41\" target=\"_blank\" rel=\"noreferrer noopener\"> ransomware reports since September 2021<\/a>. A March report confirmed LockBit was behind the Washington state public transit system and ION Group hacks in February.&nbsp;<\/p>\n<p>Most recently, data showed LockBit was leveraging a ransomware-as-a-service (RaaS) model to continue its previous campaigns, which have effectively hindered traditional computer network defenses and mitigation.<\/p>\n<p>Known as LockBit Black, the variant was \u201cmore modular and evasive\u201d than previous versions. Much like the Glimps\u2019 findings, LockBit Black shares similarities with Black Matter and Black Cat ransomware.<\/p>\n<p>READ MORE <a href=\"https:\/\/packetstormsecurity.com\/news\/view\/34529\/New-Lockbit-Variant-Targets-MacOS-Another-Relies-On-Conti-Source-Code.html\">HERE<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>READ MORE HERE&#8230;<\/p>\n","protected":false},"author":2,"featured_media":51520,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"colormag_page_layout":"default_layout","footnotes":""},"categories":[60],"tags":[10476],"class_list":["post-51519","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-packet-storm","tag-headlinemalwareapplecryptography"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.1 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>New Lockbit Variant Targets MacOS, Another Relies On Conti Source Code 2026 | ThreatsHub Cybersecurity News<\/title>\n<meta name=\"description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.threatshub.org\/blog\/new-lockbit-variant-targets-macos-another-relies-on-conti-source-code\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"New Lockbit Variant Targets MacOS, Another Relies On Conti Source Code 2026 | ThreatsHub Cybersecurity News\" \/>\n<meta property=\"og:description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.threatshub.org\/blog\/new-lockbit-variant-targets-macos-another-relies-on-conti-source-code\/\" \/>\n<meta property=\"og:site_name\" content=\"ThreatsHub Cybersecurity News\" \/>\n<meta property=\"article:published_time\" content=\"2023-04-18T16:54:31+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/files.scmagazine.com\/wp-content\/uploads\/2021\/11\/image2-1.jpg\" \/>\n<meta name=\"author\" content=\"TH Author\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@threatshub\" \/>\n<meta name=\"twitter:site\" content=\"@threatshub\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"TH Author\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"3 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/new-lockbit-variant-targets-macos-another-relies-on-conti-source-code\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/new-lockbit-variant-targets-macos-another-relies-on-conti-source-code\\\/\"},\"author\":{\"name\":\"TH Author\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\"},\"headline\":\"New Lockbit Variant Targets MacOS, Another Relies On Conti Source Code\",\"datePublished\":\"2023-04-18T16:54:31+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/new-lockbit-variant-targets-macos-another-relies-on-conti-source-code\\\/\"},\"wordCount\":582,\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/new-lockbit-variant-targets-macos-another-relies-on-conti-source-code\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2023\\\/04\\\/new-lockbit-variant-targets-macos-another-relies-on-conti-source-code.jpg\",\"keywords\":[\"headline,malware,apple,cryptography\"],\"articleSection\":[\"Packet Storm\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/new-lockbit-variant-targets-macos-another-relies-on-conti-source-code\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/new-lockbit-variant-targets-macos-another-relies-on-conti-source-code\\\/\",\"name\":\"New Lockbit Variant Targets MacOS, Another Relies On Conti Source Code 2026 | ThreatsHub Cybersecurity News\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/new-lockbit-variant-targets-macos-another-relies-on-conti-source-code\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/new-lockbit-variant-targets-macos-another-relies-on-conti-source-code\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2023\\\/04\\\/new-lockbit-variant-targets-macos-another-relies-on-conti-source-code.jpg\",\"datePublished\":\"2023-04-18T16:54:31+00:00\",\"description\":\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/new-lockbit-variant-targets-macos-another-relies-on-conti-source-code\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/new-lockbit-variant-targets-macos-another-relies-on-conti-source-code\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/new-lockbit-variant-targets-macos-another-relies-on-conti-source-code\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2023\\\/04\\\/new-lockbit-variant-targets-macos-another-relies-on-conti-source-code.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2023\\\/04\\\/new-lockbit-variant-targets-macos-another-relies-on-conti-source-code.jpg\",\"width\":1200,\"height\":726},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/new-lockbit-variant-targets-macos-another-relies-on-conti-source-code\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"headline,malware,apple,cryptography\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/tag\\\/headlinemalwareapplecryptography\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"New Lockbit Variant Targets MacOS, Another Relies On Conti Source Code\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"name\":\"ThreatsHub Cybersecurity News\",\"description\":\"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"alternateName\":\"Threatshub.org\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\",\"name\":\"ThreatsHub.org\",\"alternateName\":\"Threatshub.org\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"width\":432,\"height\":435,\"caption\":\"ThreatsHub.org\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/threatshub\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\",\"name\":\"TH Author\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"caption\":\"TH Author\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"New Lockbit Variant Targets MacOS, Another Relies On Conti Source Code 2026 | ThreatsHub Cybersecurity News","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.threatshub.org\/blog\/new-lockbit-variant-targets-macos-another-relies-on-conti-source-code\/","og_locale":"en_US","og_type":"article","og_title":"New Lockbit Variant Targets MacOS, Another Relies On Conti Source Code 2026 | ThreatsHub Cybersecurity News","og_description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","og_url":"https:\/\/www.threatshub.org\/blog\/new-lockbit-variant-targets-macos-another-relies-on-conti-source-code\/","og_site_name":"ThreatsHub Cybersecurity News","article_published_time":"2023-04-18T16:54:31+00:00","og_image":[{"url":"https:\/\/files.scmagazine.com\/wp-content\/uploads\/2021\/11\/image2-1.jpg","type":"","width":"","height":""}],"author":"TH Author","twitter_card":"summary_large_image","twitter_creator":"@threatshub","twitter_site":"@threatshub","twitter_misc":{"Written by":"TH Author","Est. reading time":"3 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.threatshub.org\/blog\/new-lockbit-variant-targets-macos-another-relies-on-conti-source-code\/#article","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/new-lockbit-variant-targets-macos-another-relies-on-conti-source-code\/"},"author":{"name":"TH Author","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476"},"headline":"New Lockbit Variant Targets MacOS, Another Relies On Conti Source Code","datePublished":"2023-04-18T16:54:31+00:00","mainEntityOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/new-lockbit-variant-targets-macos-another-relies-on-conti-source-code\/"},"wordCount":582,"publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/new-lockbit-variant-targets-macos-another-relies-on-conti-source-code\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2023\/04\/new-lockbit-variant-targets-macos-another-relies-on-conti-source-code.jpg","keywords":["headline,malware,apple,cryptography"],"articleSection":["Packet Storm"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.threatshub.org\/blog\/new-lockbit-variant-targets-macos-another-relies-on-conti-source-code\/","url":"https:\/\/www.threatshub.org\/blog\/new-lockbit-variant-targets-macos-another-relies-on-conti-source-code\/","name":"New Lockbit Variant Targets MacOS, Another Relies On Conti Source Code 2026 | ThreatsHub Cybersecurity News","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/new-lockbit-variant-targets-macos-another-relies-on-conti-source-code\/#primaryimage"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/new-lockbit-variant-targets-macos-another-relies-on-conti-source-code\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2023\/04\/new-lockbit-variant-targets-macos-another-relies-on-conti-source-code.jpg","datePublished":"2023-04-18T16:54:31+00:00","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","breadcrumb":{"@id":"https:\/\/www.threatshub.org\/blog\/new-lockbit-variant-targets-macos-another-relies-on-conti-source-code\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.threatshub.org\/blog\/new-lockbit-variant-targets-macos-another-relies-on-conti-source-code\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/new-lockbit-variant-targets-macos-another-relies-on-conti-source-code\/#primaryimage","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2023\/04\/new-lockbit-variant-targets-macos-another-relies-on-conti-source-code.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2023\/04\/new-lockbit-variant-targets-macos-another-relies-on-conti-source-code.jpg","width":1200,"height":726},{"@type":"BreadcrumbList","@id":"https:\/\/www.threatshub.org\/blog\/new-lockbit-variant-targets-macos-another-relies-on-conti-source-code\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.threatshub.org\/blog\/"},{"@type":"ListItem","position":2,"name":"headline,malware,apple,cryptography","item":"https:\/\/www.threatshub.org\/blog\/tag\/headlinemalwareapplecryptography\/"},{"@type":"ListItem","position":3,"name":"New Lockbit Variant Targets MacOS, Another Relies On Conti Source Code"}]},{"@type":"WebSite","@id":"https:\/\/www.threatshub.org\/blog\/#website","url":"https:\/\/www.threatshub.org\/blog\/","name":"ThreatsHub Cybersecurity News","description":"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform","publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"alternateName":"Threatshub.org","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.threatshub.org\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.threatshub.org\/blog\/#organization","name":"ThreatsHub.org","alternateName":"Threatshub.org","url":"https:\/\/www.threatshub.org\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","width":432,"height":435,"caption":"ThreatsHub.org"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/threatshub"]},{"@type":"Person","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476","name":"TH Author","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","caption":"TH Author"}}]}},"_links":{"self":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/51519","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/comments?post=51519"}],"version-history":[{"count":0,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/51519\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media\/51520"}],"wp:attachment":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media?parent=51519"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/categories?post=51519"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/tags?post=51519"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}