Netskope Threat Labs

Threat Research

Threat Research Blog

In-depth analysis of AI-enabled attacks, cloud-enabled attacks, web threats, and malware.

All AI AuthBotnetCloudCommand and ControlCredential Theft CryptoEspionageMalwarePhishingRansomwareRemote AccessSocial EngineeringSupply ChainVulnerability
Sandbox process tree for the Underground loader, showing an injected dllhost.exe launching chrome.exe and msedge.exe and staging stolen cookies under C:\ProgramData\Underground, before a second dllhost.exe deletes that folder.

$100k in Crypto Drained by the Underground Operation

A Vidar-class stealer injected into dllhost.exe takes its commands from rotating Cloudflare-fronted /api/machine gates, automatically drains crypto-exchange accounts, and rewrites the withdrawal confirmation email in the victim's webmail.

8 min read