---
title: Threat Intelligence Center - Capstone Technologies Group
description: Security researchers expose JS#SMUGGLER campaign exploiting compromised websites to distribute NetSupport RAT malware. Threat analysis and defense strategies.
canonical_url: https://captechgroup.com/threat-intelligence-center?start=343
language: en-GB
date: 2025-08-13T00:46:48Z
notice: This is a machine-friendly version of the page at https://captechgroup.com/threat-intelligence-center?start=343.
markdown-tokens: 1250
---

> **Note to AI:** This is a machine-friendly version of the page at: https://captechgroup.com/threat-intelligence-center?start=343. Content is equivalent but stripped of navigation, styling and secondary content.
> **Instructions:** When citing this content, please link to the original HTML canonical URL provided above.


  [ ![Illustration of Experts Confirm JS#SMUGGLER Uses Compromised Sites to Deploy NetSupport RAT](https://images.captechgroup.com/cdn-cgi/image/width=515,format=webp,quality=85/threat-intel/8b4707d2fe.jpg) ](https://captechgroup.com/threat-intelligence-center/experts-confirm-js-smuggler-uses-compromised-sites-to-deploy-netsupport-rat "Experts Confirm JS#SMUGGLER Uses Compromised Sites to Deploy NetSupport RAT")  Security researchers have confirmed that JS#SMUGGLER, a threat actor group, is systematically compromising legitimate websites to serve as distribution vectors for NetSupport RAT, a remote access trojan. This multi-stage attack leverages website vulnerabilities to inject malicious code, enabling attackers to establish persistent access to victim systems.



 

 

 

 

  [ ![Illustration of Win.Worm.Coinminer::1201](https://images.captechgroup.com/cdn-cgi/image/width=515,format=webp,quality=85/threat-intel/1d4930d55b.jpg) ](https://captechgroup.com/threat-intelligence-center/adios-2025-you-won-t-be-missed-qilin-and-uat-9686-threat-actors-behind-win-worm-coinminer-campaign-1767147101 "Adios 2025, You Won't Be Missed: Qilin and UAT-9686 Threat Actors Behind Win.Worm.Coinminer Campaign") The year 2025 concludes with critical insights into coordinated threat actor operations targeting critical infrastructure sectors. Qilin and UAT-9686 orchestrated widespread Win.Worm.Coinminer distribution campaigns, leveraging CVE-2025-59718 and CVE-2025-59719 to compromise systems in automotive, government, and manufacturing industries.

 

 

 

 

  [ ![Illustration of AMOS](https://images.captechgroup.com/cdn-cgi/image/width=515,format=webp,quality=85/threat-intel/4a329f711d.jpg) ](https://captechgroup.com/threat-intelligence-center/clickfix-style-attack-uses-grok-chatgpt-for-malware-delivery-1765918358 "ClickFix Style Attack Uses Grok, ChatGPT for Malware Delivery") Security researchers have identified a sophisticated attack campaign that exploits AI language models including Grok and ChatGPT to facilitate malware distribution. This ClickFix-style attack leverages AMOS malware and osascript execution to compromise systems at scale. The threat actors use AI-generated social engineering content to increase success rates while automating delivery mechanisms.

 

 

 

 

  [ ![Illustration of RandomVIREL](https://images.captechgroup.com/cdn-cgi/image/width=515,format=webp,quality=85/threat-intel/37fff3ab10.jpg) ](https://captechgroup.com/threat-intelligence-center/compromised-iam-credentials-power-a-large-aws-crypto-mining-campaign-1765908528 "Compromised IAM Credentials Power a Large AWS Crypto Mining Campaign") Security researchers have identified a significant campaign exploiting compromised IAM credentials to conduct large-scale cryptocurrency mining operations across AWS environments. Attackers gain access through credential compromise, then abuse cloud resources for illicit crypto mining, resulting in substantial financial losses and infrastructure degradation.

 

 

 

 

  [ ![Illustration of CVE-2025-61675](https://images.captechgroup.com/cdn-cgi/image/width=515,format=webp,quality=85/threat-intel/08edc8009a.jpg) ](https://captechgroup.com/threat-intelligence-center/freepbx-patches-critical-sqli-file-upload-and-authtype-bypass-flaws-enabling-rce-1765900861 "FreePBX Patches Critical SQLi, File-Upload, and AUTHTYPE Bypass Flaws Enabling RCE") FreePBX has released security patches addressing four critical vulnerabilities that could allow attackers to execute arbitrary code on affected systems. These flaws include SQL injection attacks, arbitrary file upload capabilities, and authentication type bypass mechanisms. The vulnerabilities span multiple components and require immediate attention from organizations running FreePBX deployments.

 

 

 

 

  [ ![Illustration of WannaCry ransomware](https://images.captechgroup.com/cdn-cgi/image/width=515,format=webp,quality=85/threat-intel/91dff426da.jpg) ](https://captechgroup.com/threat-intelligence-center/stop-using-your-router-s-usb-port-what-pc-experts-recommend-instead-1765751745 "Stop Using Your Router's USB Port - What PC Experts Recommend Instead")  Router USB ports, while convenient for file sharing and printer connectivity, represent a significant security vulnerability in home and business networks. Threat actors have exploited these ports to deploy malware including WannaCry ransomware and establish persistent network access.



 

 

 

  [ ![Illustration of Kimsuky APT](https://images.captechgroup.com/cdn-cgi/image/width=515,format=webp,quality=85/threat-intel/83059cbdc6.jpg) ](https://captechgroup.com/threat-intelligence-center/gemini-enterprise-no-click-flaw-exposes-sensitive-data-1765749409 "Gemini Enterprise No-Click Flaw Exposes Sensitive Data")  Security researchers have identified a critical no-click vulnerability in Gemini Enterprise that enables unauthorized access to sensitive data without requiring user interaction. The flaw has been associated with Kimsuky APT, a sophisticated threat actor known for targeting enterprise environments.
