{"id":52833,"date":"2023-07-19T14:38:52","date_gmt":"2023-07-19T14:38:52","guid":{"rendered":"https:\/\/packetstormsecurity.com\/news\/view\/34812\/FIN8-Retools-Backdoor-Malware-To-Avoid-Detection.html"},"modified":"2023-07-19T14:38:52","modified_gmt":"2023-07-19T14:38:52","slug":"fin8-retools-backdoor-malware-to-avoid-detection","status":"publish","type":"post","link":"https:\/\/www.threatshub.org\/blog\/fin8-retools-backdoor-malware-to-avoid-detection\/","title":{"rendered":"FIN8 Retools Backdoor Malware To Avoid Detection"},"content":{"rendered":"<div><img decoding=\"async\" src=\"https:\/\/files.scmagazine.com\/wp-content\/uploads\/2023\/07\/backdoor-brick-analog.jpg\" class=\"ff-og-image-inserted\"><\/div>\n<p>The FIN8 hacking group has been observed deploying a revamped version of the Sardonic backdoor malware as it intensifies its focus on ransomware attacks.<\/p>\n<p>FIN8 has been active since at least January 2016 and has a reputation for targeting organizations in the hospitality, retail, entertainment, insurance, technology, chemicals, and finance sectors.<\/p>\n<p>While the actor initially <a href=\"https:\/\/www.scmagazine.com\/news\/breach\/visa-warns-against-new-pos-attacks-fin8-fingered-as-the-culprit\">specialized in point-of-sale (POS) attacks<\/a>, over the past few years it has been observed using a number of ransomware threats in its attacks.<\/p>\n<p>In a <a href=\"https:\/\/symantec-enterprise-blogs.security.com\/blogs\/threat-intelligence\/syssphinx-fin8-backdoor\">research post<\/a> published Tuesday, Symantec\u2019s Threat Hunter Team reported that the group, which it tracks under the name Syssphinx, was observed deploying a new variant of the Sardonic backdoor malware to deliver <a href=\"https:\/\/www.scmagazine.com\/news\/ransomware\/blackcat-ransomware-stealth-speed\">BlackCat ransomware<\/a> (also known as ALPHV and <a href=\"https:\/\/www.scmagazine.com\/news\/ransomware\/successor-to-ransomware-used-in-colonial-pipeline-attack-observed-using-new-tools\">Noberus<\/a>). Social engineering and spear-phishing are two of the group\u2019s preferred methods for initial compromise.<\/p>\n<p>\u201cThe group is known for utilizing so-called living-off-the-land tactics, making use of built-in tools and interfaces such as PowerShell and WMI (Windows Management Instrumentation), and abusing legitimate services to disguise its activity,\u201d the researchers wrote.<\/p>\n<p>The group\u2019s expansion into ransomware \u201csuggests the threat actors may be diversifying their focus in an effort to maximize profits from compromised organizations,\u201d they said.<\/p>\n<p>FIN8 was first observed using ransomware in its attacks in June 2021. In January 2022, the <a href=\"https:\/\/www.scmagazine.com\/analysis\/ransomware\/deceptive-financial-ransomware-variant-white-rabbit-emerges-in-banking\">White Rabbit<\/a> ransomware family was linked to the group, and in December 2022 Symantec observed FIN8 deploying BlackCat ransomware.<\/p>\n<p>Like many cybercriminal groups FIN8 \u2014 believed to be based in Eastern Europe\u2019s Commonwealth of Independent States region \u2014 is known for taking extended breaks between attack campaigns, using the time to improve its tactics, techniques, and procedures.&nbsp;<\/p>\n<p>That practice is demonstrated in the way it has evolved the use of backdoor malware over recent years. In 2019, it used the <a href=\"https:\/\/www.scmagazine.com\/news\/cybercrime\/fin8-actors-recent-activity-buoyed-by-new-malware-toolset-report\">Badhatch<\/a> backdoor, which it updated in December 2020 and again in January 2021. Then in 2021, <a href=\"https:\/\/www.bitdefender.com\/blog\/labs\/fin8-threat-actor-spotted-once-again-with-new-sardonic-backdoor\/\">Bitdefender researchers<\/a> linked a newer backdoor, Sardonic, to the group.<\/p>\n<p>Symantec said the most recent attack it observed in December 2022 saw FIN8 leverage a \u201creworked\u201d version of Sardonic where \u201cmost of the backdoor\u2019s features have been altered to give it a new appearance.\u201d<\/p>\n<h2>Why revamp the backdoor?<\/h2>\n<p>The Sardonic backdoor, written in C++, is capable of harvesting system information and executing commands, and has a plugin system designed to load and execute additional malware payloads that are delivered as dynamic link libraries (DLLs).&nbsp;<\/p>\n<p>The revamped version of Sardonic used by FIN8 in the December 2022 attack shares several features with the earlier version discovered by Bitdefender, although most of the code had been rewritten, possibly for obfuscation purposes.<\/p>\n<p>\u201cInterestingly, the backdoor code no longer uses the C++ standard library and most of the object-oriented features have been replaced with a plain C implementation,\u201d the researchers said.<\/p>\n<p>\u201cIn addition, some of the reworkings look unnatural, suggesting that the primary goal of the threat actors could be to avoid similarities with previously disclosed details.\u201d<\/p>\n<p>An example of the changes made in the new version of Sardonic: when messages were sent over the network, the operation code specifying how to interpret them had been moved to after the variable part of the message, \u201ca change that adds some complications to the backdoor logic,\u201d Symantec said.<\/p>\n<p>Overall, the lengths FIN8 had gone to as it changed and refined its TTPs \u201cunderscore how this highly skilled financial threat actor remains a serious threat to organizations,\u201d the researchers concluded.<\/p>\n<p>READ MORE <a href=\"https:\/\/packetstormsecurity.com\/news\/view\/34812\/FIN8-Retools-Backdoor-Malware-To-Avoid-Detection.html\">HERE<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>READ MORE HERE&#8230;<\/p>\n","protected":false},"author":2,"featured_media":52834,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"colormag_page_layout":"default_layout","footnotes":""},"categories":[277],"tags":[6020],"class_list":["post-52833","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity-blogs","tag-headlinehackermalwarebackdoor"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.1 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>FIN8 Retools Backdoor Malware To Avoid Detection 2026 | ThreatsHub Cybersecurity News<\/title>\n<meta name=\"description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.threatshub.org\/blog\/fin8-retools-backdoor-malware-to-avoid-detection\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"FIN8 Retools Backdoor Malware To Avoid Detection 2026 | ThreatsHub Cybersecurity News\" \/>\n<meta property=\"og:description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.threatshub.org\/blog\/fin8-retools-backdoor-malware-to-avoid-detection\/\" \/>\n<meta property=\"og:site_name\" content=\"ThreatsHub Cybersecurity News\" \/>\n<meta property=\"article:published_time\" content=\"2023-07-19T14:38:52+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/files.scmagazine.com\/wp-content\/uploads\/2023\/07\/backdoor-brick-analog.jpg\" \/>\n<meta name=\"author\" content=\"TH Author\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@threatshub\" \/>\n<meta name=\"twitter:site\" content=\"@threatshub\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"TH Author\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"3 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/fin8-retools-backdoor-malware-to-avoid-detection\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/fin8-retools-backdoor-malware-to-avoid-detection\\\/\"},\"author\":{\"name\":\"TH Author\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\"},\"headline\":\"FIN8 Retools Backdoor Malware To Avoid Detection\",\"datePublished\":\"2023-07-19T14:38:52+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/fin8-retools-backdoor-malware-to-avoid-detection\\\/\"},\"wordCount\":565,\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/fin8-retools-backdoor-malware-to-avoid-detection\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2023\\\/07\\\/fin8-retools-backdoor-malware-to-avoid-detection.jpg\",\"keywords\":[\"headline,hacker,malware,backdoor\"],\"articleSection\":[\"CyberSecurity Blogs\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/fin8-retools-backdoor-malware-to-avoid-detection\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/fin8-retools-backdoor-malware-to-avoid-detection\\\/\",\"name\":\"FIN8 Retools Backdoor Malware To Avoid Detection 2026 | ThreatsHub Cybersecurity News\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/fin8-retools-backdoor-malware-to-avoid-detection\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/fin8-retools-backdoor-malware-to-avoid-detection\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2023\\\/07\\\/fin8-retools-backdoor-malware-to-avoid-detection.jpg\",\"datePublished\":\"2023-07-19T14:38:52+00:00\",\"description\":\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/fin8-retools-backdoor-malware-to-avoid-detection\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/fin8-retools-backdoor-malware-to-avoid-detection\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/fin8-retools-backdoor-malware-to-avoid-detection\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2023\\\/07\\\/fin8-retools-backdoor-malware-to-avoid-detection.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2023\\\/07\\\/fin8-retools-backdoor-malware-to-avoid-detection.jpg\",\"width\":900,\"height\":600},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/fin8-retools-backdoor-malware-to-avoid-detection\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"headline,hacker,malware,backdoor\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/tag\\\/headlinehackermalwarebackdoor\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"FIN8 Retools Backdoor Malware To Avoid Detection\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"name\":\"ThreatsHub Cybersecurity News\",\"description\":\"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"alternateName\":\"Threatshub.org\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\",\"name\":\"ThreatsHub.org\",\"alternateName\":\"Threatshub.org\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"width\":432,\"height\":435,\"caption\":\"ThreatsHub.org\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/threatshub\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\",\"name\":\"TH Author\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"caption\":\"TH Author\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"FIN8 Retools Backdoor Malware To Avoid Detection 2026 | ThreatsHub Cybersecurity News","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.threatshub.org\/blog\/fin8-retools-backdoor-malware-to-avoid-detection\/","og_locale":"en_US","og_type":"article","og_title":"FIN8 Retools Backdoor Malware To Avoid Detection 2026 | ThreatsHub Cybersecurity News","og_description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","og_url":"https:\/\/www.threatshub.org\/blog\/fin8-retools-backdoor-malware-to-avoid-detection\/","og_site_name":"ThreatsHub Cybersecurity News","article_published_time":"2023-07-19T14:38:52+00:00","og_image":[{"url":"https:\/\/files.scmagazine.com\/wp-content\/uploads\/2023\/07\/backdoor-brick-analog.jpg","type":"","width":"","height":""}],"author":"TH Author","twitter_card":"summary_large_image","twitter_creator":"@threatshub","twitter_site":"@threatshub","twitter_misc":{"Written by":"TH Author","Est. reading time":"3 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.threatshub.org\/blog\/fin8-retools-backdoor-malware-to-avoid-detection\/#article","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/fin8-retools-backdoor-malware-to-avoid-detection\/"},"author":{"name":"TH Author","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476"},"headline":"FIN8 Retools Backdoor Malware To Avoid Detection","datePublished":"2023-07-19T14:38:52+00:00","mainEntityOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/fin8-retools-backdoor-malware-to-avoid-detection\/"},"wordCount":565,"publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/fin8-retools-backdoor-malware-to-avoid-detection\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2023\/07\/fin8-retools-backdoor-malware-to-avoid-detection.jpg","keywords":["headline,hacker,malware,backdoor"],"articleSection":["CyberSecurity Blogs"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.threatshub.org\/blog\/fin8-retools-backdoor-malware-to-avoid-detection\/","url":"https:\/\/www.threatshub.org\/blog\/fin8-retools-backdoor-malware-to-avoid-detection\/","name":"FIN8 Retools Backdoor Malware To Avoid Detection 2026 | ThreatsHub Cybersecurity News","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/fin8-retools-backdoor-malware-to-avoid-detection\/#primaryimage"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/fin8-retools-backdoor-malware-to-avoid-detection\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2023\/07\/fin8-retools-backdoor-malware-to-avoid-detection.jpg","datePublished":"2023-07-19T14:38:52+00:00","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","breadcrumb":{"@id":"https:\/\/www.threatshub.org\/blog\/fin8-retools-backdoor-malware-to-avoid-detection\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.threatshub.org\/blog\/fin8-retools-backdoor-malware-to-avoid-detection\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/fin8-retools-backdoor-malware-to-avoid-detection\/#primaryimage","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2023\/07\/fin8-retools-backdoor-malware-to-avoid-detection.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2023\/07\/fin8-retools-backdoor-malware-to-avoid-detection.jpg","width":900,"height":600},{"@type":"BreadcrumbList","@id":"https:\/\/www.threatshub.org\/blog\/fin8-retools-backdoor-malware-to-avoid-detection\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.threatshub.org\/blog\/"},{"@type":"ListItem","position":2,"name":"headline,hacker,malware,backdoor","item":"https:\/\/www.threatshub.org\/blog\/tag\/headlinehackermalwarebackdoor\/"},{"@type":"ListItem","position":3,"name":"FIN8 Retools Backdoor Malware To Avoid Detection"}]},{"@type":"WebSite","@id":"https:\/\/www.threatshub.org\/blog\/#website","url":"https:\/\/www.threatshub.org\/blog\/","name":"ThreatsHub Cybersecurity News","description":"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform","publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"alternateName":"Threatshub.org","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.threatshub.org\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.threatshub.org\/blog\/#organization","name":"ThreatsHub.org","alternateName":"Threatshub.org","url":"https:\/\/www.threatshub.org\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","width":432,"height":435,"caption":"ThreatsHub.org"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/threatshub"]},{"@type":"Person","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476","name":"TH Author","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","caption":"TH Author"}}]}},"_links":{"self":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/52833","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/comments?post=52833"}],"version-history":[{"count":0,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/52833\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media\/52834"}],"wp:attachment":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media?parent=52833"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/categories?post=52833"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/tags?post=52833"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}