■ LIVE INTEL
■ Sentinel APEX ■ Tools Hub ■ API Platform ■ API Docs ■ Corporate ■ Main Site ■ Blog Hub ▲ UPGRADE NOW
SENTINEL APEX ECOSYSTEM — LIVE

AI-Powered
Cyber Intelligence
For The Enterprise

Real-time CVE analysis, APT tracking, malware intelligence, and autonomous SOC capabilities. Trusted by security teams worldwide.

LIVE THREAT INTELLIGENCE FEED
VIEW FULL DASHBOARD ↗
SENTINEL APEX
AI Threat Intel Platform
THREAT API
Checking status...
LATEST CVE
Loading...
Live from Sentinel APEX API
AI SUMMARY
Loading...

TACTICAL ADVISORY: CTM360: Lumma Stealer and Ninja Browser malware campaign abusing Google Groups

TLP:CLEAR // CDB-SENTINEL-GOC // v8.3 ELITE ADVISORY

CTM360: Lumma Stealer and Ninja Browser malware campaign abusing Google Groups

1. INTELLIGENCE SNAPSHOT

ACTOR ID: UNC-CDB-99

CONFIDENCE: Low

RISK SCORE: 7.8/10

v8.3 STEALTH AUTHORITY NODE

2. Advanced Campaign Analysis

Observation 1: CTM360: Lumma Stealer and Ninja Browser malware campaign abusing Google Groups

CDB sensors have identified tactical shifts within this cluster. CTM360 reports 4,000+ malicious Google Groups and 3,500+ Google-hosted URLs used to spread the Lumma Stealer infostealing malware and a trojanized "Ninja Browser." The report details how attackers abuse trusted Google services to steal credentials and maintain persistence across Windows and Linux systems. [...]

Observation 2: Pastebin comments push ClickFix JavaScript attack to hijack crypto swaps

CDB sensors have identified tactical shifts within this cluster. Threat actors are abusing Pastebin comments to distribute a new ClickFix-style attack that tricks cryptocurrency users into executing malicious JavaScript in their browser, allowing attackers to hijack Bitcoin swap transactions and redirect funds to attacker-controlled wallets. [...]

Observation 3: One threat actor responsible for 83% of recent Ivanti RCE attacks

CDB sensors have identified tactical shifts within this cluster. Threat intelligence observations show that a single threat actor is responsible for most of the active exploitation of two critical vulnerabilities in Ivanti Endpoint Manager Mobile (EPMM), tracked as CVE-2026-21962 and CVE-2026-24061. [...]

3. Detection Engineering Center

SIGMA (SIEM-AGNOSTIC)
logsource: {category: dns}
detection: {selection: {query: []}, condition: selection}
KQL (AZURE SENTINEL)
DeviceNetworkEvents | where RemoteUrl has_any ("")
CYBERDUDEBIVASH GOC // v8.3 ELITE NODE
POWERED BY SENTINEL APEX
Get Full Threat Intelligence Access
Live CVE feeds, APT tracking, malware analysis, AI summaries & enterprise SOC integration
▸▸ LATEST THREAT ADVISORIES
⎯⎯⎯ NAVIGATE INTELLIGENCE REPORTS ⎯⎯⎯