All Posts
Anomali Cyber Watch
1
min read

Anomali Cyber Watch: Active Probing Revealed Cobalt Strike C2s, Black Basta Ransomware Connected to FIN7, Robin Banks Phishing-as-a-Service Became Stealthier, and More

Anomali Cyber Watch reports active probing and EDR evasion, Cobalt Strike C2s, Black Basta-FIN7 links, stealthier Robin Banks phishing, infostealers, typosquatting, IOCs attached
Published on
November 8, 2022
Table of Contents

The various threat intelligence stories in this iteration of the Anomali Cyber Watch discuss the following topics: Active scanning, EDR evasion, Infostealers, Phishing, and Typosquatting. The IOCs related to these stories are attached to Anomali Cyber Watch and can be used to check your logs for potential malicious activity.

Figure 1 - IOC Summary Charts. These charts summarize the IOCs attached to this magazine and provide a glimpse of the threats discussed.

Trending Cyber News and Threat Intelligence

| [MITRE ATT&CK] Obfuscated Files or Information - T1027 | [MITRE ATT&CK] Credentials from Password Stores - T1555
Tags: detection:Vidar, Malvertising, Binary padding, malware-type:Infostealer, file-type:EXE, file-type:DLL, GNU, Typosquatting, Google Ads, Windows

FEATURED RESOURCES

April 24, 2026
Anomali Cyber Watch

Iran’s Cyber War Machine Is Accelerating — And the Ceasefire Doesn’t Cover It

Read More
April 24, 2026
Anomali Cyber Watch
Public Sector

When 911 Goes Dark: China-Nexus Backdoors, Access Brokers Selling Government Networks, and a Wake-Up Call for State IT Leaders

Read More
April 23, 2026
Anomali Cyber Watch

The Ceasefire Is a Lie: Iranian Cyber Operations Are Running at Full Tempo While the World Looks Away

Read More
Explore All