All Posts
Anomali Cyber Watch
1
min read

Anomali Cyber Watch: Active Probing Revealed Cobalt Strike C2s, Black Basta Ransomware Connected to FIN7, Robin Banks Phishing-as-a-Service Became Stealthier, and More

Anomali Cyber Watch reports active probing and EDR evasion, Cobalt Strike C2s, Black Basta-FIN7 links, stealthier Robin Banks phishing, infostealers, typosquatting, IOCs attached
Published on
November 8, 2022
Table of Contents

The various threat intelligence stories in this iteration of the Anomali Cyber Watch discuss the following topics: Active scanning, EDR evasion, Infostealers, Phishing, and Typosquatting. The IOCs related to these stories are attached to Anomali Cyber Watch and can be used to check your logs for potential malicious activity.

Figure 1 - IOC Summary Charts. These charts summarize the IOCs attached to this magazine and provide a glimpse of the threats discussed.

Trending Cyber News and Threat Intelligence

| [MITRE ATT&CK] Obfuscated Files or Information - T1027 | [MITRE ATT&CK] Credentials from Password Stores - T1555
Tags: detection:Vidar, Malvertising, Binary padding, malware-type:Infostealer, file-type:EXE, file-type:DLL, GNU, Typosquatting, Google Ads, Windows

FEATURED RESOURCES

April 10, 2026
Anomali Cyber Watch

Iran’s Cyber War Is Accelerating — And the Exploitation Window Just Collapsed to Hours

Read More
April 10, 2026
Anomali Cyber Watch
Public Sector

When Nation-States Go Shopping on the Dark Web: Iran’s Blockchain C2 Gambit and What It Means for State Government

Read More
April 9, 2026
Anomali Cyber Watch

Iran’s Cyber War Machine Isn’t Slowing Down — Six Weeks in, Critical Infrastructure Is Under Active Attack

Read More
Explore All