Blog Zscaler

Ricevi gli ultimi aggiornamenti dal blog di Zscaler nella tua casella di posta

Best Practices

Intelligence Insights: June 2025

image
THE RED CANARY TEAM
giugno 18, 2025 - 4 min read

Amber Albatross abides and Mocha Manakin manifests in this month’s edition of Intelligence Insights

 

Highlights from May

Amber Albatross is number 1 on our top 10 most prevalent threat list this month, for the third month running. Amber Albatross is Red Canary’s name for a cluster of activity that starts from an adware program and leads to a pyInstaller EXE with stealer-like capabilities.

We saw increased SocGholish activity last month, enough to return it to the rankings in a tie for 4th with Mimikatz. Another threat that returned to the rankings in May is AsyncRAT, making the list for the first time since September 2024. AsyncRAT split a tie for 7th with three worm threats; Conficker, Gamarue, and Phorpiex.

SecOps Weekly video thumbnail

 

One threat that’s noticeably missing from our most prevalent threat list is LummaC2. After spending 9 of the past 12 months in the top 10 rankings, May’s disruption of LummaC2’s operations appears to have been successful. It is unclear if this will be a permanent disruption, or if adversaries will stand up new infrastructure so they can resume LummaC2 use.

This month we are debuting a new color bird threat, Mocha Manakin. Mocha Manakin is a Red Canary-named activity cluster delivered via paste and run (aka ClickFix, fakeCAPTCHA), and is our first named paste-and-run threat cluster out of the several we have been tracking since August 2024.

Mocha Manakin is distinct from other paste-and-run clusters because it is followed by the deployment of a NodeJS backdoor that Red Canary is calling NodeInitRAT. You can read more about Mocha Manakin and NodeInitRAT below, as well as in this blog.

 

 

Image

 

This month’s top 10 threats

To track pervasiveness over time, we identify the number of unique customer environments in which we observed a given threat and compare it to what we’ve seen in previous months.

Here’s how the numbers shook out for May 2025:

Month's rankThreat nameThreat description

⬆ 1

Amber Albatross

Red Canary-named cluster of activity that starts from an adware program and progresses through several stages to a pyInstaller EXE with stealer capabilities

⬆ 2

NetSupport Manager

Legitimate remote access tool (RAT) that can be used as a trojan by adversaries to remotely control victim endpoints for unauthorized access

⬇ 3

Scarlet Goldfinch

Activity cluster that uses a distribution scheme similar to SocGholish and uses JScript files to drop NetSupport Manager onto victim systems

⬆ 4*

Mimikatz

Open source tool that dumps credentials using various techniques

⬆ 4*

SocGholish

Dropper/downloader that uses compromised WordPress sites to redirect users to adversary infrastructure posing as necessary browser updates to trick users into running malicious code

⬇ 6

Tangerine Turkey

Red Canary's name for a VBS worm that is delivered via an infected USB and uses a printui DLL hijack to deliver a cryptomining payload

⬆ 7*

AsyncRAT

Open source remote access tool with multiple functions including keylogging and remote desktop control

⬆ 7*

Conficker

Ancient NetBIOS and USB worm that has plagued the internet since 2008. What is dead may never die.

⬆ 7*

Gamarue

Malware family used as part of a botnet. Some variants are worms and frequently spread via infected USB drives

⬆ 7*

Phorpiex

IRC-based botnet that spreads via USB worm functionality and also sends spam emails to phish additional users, and has reportedly delivered ransomware and cryptocurrency miners

⬆ = trending up from previous month ⬇= trending down from previous month ➡ = no change in rank from previous month

*Denotes a tie

Meet Mocha Manakin

 

Mocha Manakin threat logo

Mocha Manakin, Red Canary’s newest color bird threat, is an activity cluster that leverages a PowerShell loader delivered via paste and run (aka ClickFix, fakeCAPTCHA). The majority of the paste and run activity we’ve observed has led to LummaC2, HijackLoader, or NetSupport Manager—although we have seen other payloads as well, including Vidar and XMRig.

Mocha Manakin is distinct because its successful paste and run lure execution is followed by the deployment of a specific NodeJS backdoor that Red Canary calls NodeInitRAT. Once this backdoor is deployed, the adversary can conduct domain reconnaissance, typically enumerating principal names and general domain details.

Mocha Manakin has overlaps in activity related to Interlock ransomware—a ransomware group that has been active since at least September 2024—as reported by Sekoia.io, including:

  • the use of paste and run for initial access
  • follow-on delivery of the NodeJS remote access trojan we call NodeInitRAT
  • some of the same infrastructure

As of May 2025, Red Canary has not directly observed Mocha Manakin activity progress to ransomware. However, we assess with moderate confidence that unmitigated Mocha Manakin activity will likely lead to ransomware.

To learn more about Mocha Manakin and NodeInitRAT in more detail, see our blog on these topics.

 

Detection opportunity: Instances of NodeJS spawning Windows Command Processor to add a registry key

The following pseudo-detection analytic identifies instances of NodeJS, node.exe, spawning Windows Command Processor, cmd.exe, to add a registry key. NodeJS-based remote access trojans (RAT), including NodeInitRAT, can use Windows registry keys to establish persistence on a system. While normal behavior for node.exe includes spawning instances of cmd.exe, creating registry run keys with those instances is not.

parent_process == ('node.exe') && process == ('cmd') && deobfuscated_command_includes ('reg add' || 'run')

 

2025 Threat Detection Report

You've read about the top threats of the last month, how about for last year? The 2025 Threat Detection Report provides in-depth analysis and actionable guidance on every page.

form submtited
Grazie per aver letto

Questo post è stato utile?

Esclusione di responsabilità: questo articolo del blog è stato creato da Zscaler esclusivamente a scopo informativo ed è fornito "così com'è", senza alcuna garanzia circa l'accuratezza, la completezza o l'affidabilità dei contenuti. Zscaler declina ogni responsabilità per eventuali errori o omissioni, così come per le eventuali azioni intraprese sulla base delle informazioni fornite. Eventuali link a siti web o risorse di terze parti sono offerti unicamente per praticità, e Zscaler non è responsabile del relativo contenuto, né delle pratiche adottate. Tutti i contenuti sono soggetti a modifiche senza preavviso. Accedendo a questo blog, l'utente accetta le presenti condizioni e riconosce di essere l'unico responsabile della verifica e dell'uso delle informazioni secondo quanto appropriato per rispondere alle proprie esigenze.

Ricevi gli ultimi aggiornamenti dal blog di Zscaler nella tua casella di posta

Inviando il modulo, si accetta la nostra Informativa sulla privacy.