Skip to main content
Blog

Threat Intelligence Blog

Research, insights, and updates from the isMalicious team.

Malicious Browser Extensions Are Stealing Session Cookies: Detection Guide
Malware2026-07-30

Malicious Browser Extensions Are Stealing Session Cookies: Detection Guide

Rebranded browser extensions are harvesting session cookies and OAuth tokens after silent updates. Here is how to detect and respond before EDR ever sees it.

6 min readRead
AMOS macOS Infostealer: ClickFix Shows Why Hash Reputation Must Cover Developer Macs
Malware2026-07-05

AMOS macOS Infostealer: ClickFix Shows Why Hash Reputation Must Cover Developer Macs

AMOS and related macOS infostealers are turning social engineering into credential theft. File hash reputation, URL scanning, and domain intelligence help teams respond before stolen tokens spread.

3 min readRead
Session Token Theft: Why Infostealers Bypass MFA and How Defenders Respond
Malware2026-05-05

Session Token Theft: Why Infostealers Bypass MFA and How Defenders Respond

Infostealers increasingly target browser cookies, session tokens, and refresh tokens. Learn why MFA is not enough, what token theft looks like, and how to detect replay.

10 min readRead
File Hash Analysis for Malware Detection: SHA-256, Reputation, and Threat Intel Workflows
Malware2026-04-18

File Hash Analysis for Malware Detection: SHA-256, Reputation, and Threat Intel Workflows

Learn how cryptographic file hashes power malware identification, why SHA-256 dominates security tooling, and how to combine hash lookups with broader threat intelligence for fewer false positives.

8 min readRead
File Hash Analysis: MD5, SHA-1, and SHA-256 for Malware Detection and Threat Hunting
Malware2026-04-18

File Hash Analysis: MD5, SHA-1, and SHA-256 for Malware Detection and Threat Hunting

A practical guide to file hashes in cybersecurity—how MD5, SHA-1, and SHA-256 work, why they matter for malware detection, incident response, and threat hunting, and how to use hash lookups to enrich indicators of compromise.

9 min readRead
Polymorphic Malware: The Shapeshifting Code
Malware2026-03-27

Polymorphic Malware: The Shapeshifting Code

Traditional antivirus relies on signatures, but polymorphic malware changes its code every time it replicates. Discover how this shapeshifting threat evades detection.

1 min readRead
Command & Control Infrastructure: Detecting C2 Traffic Before It Is Too Late
Malware2026-03-04

Command & Control Infrastructure: Detecting C2 Traffic Before It Is Too Late

Once malware establishes a C2 channel, attackers have a persistent foothold in your environment. Understand how C2 infrastructure is built, how beacons evade detection, and how to identify malicious outbound connections using threat intelligence.

9 min readRead
Industrial Control Systems (ICS) Malware Trends: The OT/IT Convergence Risk
Malware2026-02-19

Industrial Control Systems (ICS) Malware Trends: The OT/IT Convergence Risk

Operational Technology (OT) environments are under siege. We analyze the latest ICS-specific malware strains targeting PLCs and SCADA systems, and offer defense strategies for critical infrastructure.

2 min readRead
Infostealer Malware: How Credentials End Up on the Dark Web
Malware2026-01-11

Infostealer Malware: How Credentials End Up on the Dark Web

Infostealers harvest credentials and sensitive data from infected systems, fueling a massive underground economy. Learn how these threats operate, how to detect them, and how to protect your organization from credential theft.

10 min readRead
DNS Security and Threat Intelligence: Blocking Malware at the Resolver
Malware2026-01-05

DNS Security and Threat Intelligence: Blocking Malware at the Resolver

DNS is the first line of defense against malware and phishing. Learn how protective DNS and threat intelligence blocklists can stop threats before they reach your network, with integration guides for Pi-hole, AdGuard, and enterprise DNS.

12 min readRead

Expert Threat Intelligence Analysis

Our blog features in-depth analysis from our threat research team. Each article is backed by real data from our analysis of millions of malicious domains, IPs, and URLs across the global threat landscape. Topics include ransomware campaigns, phishing techniques, malware distribution networks, and emerging threat trends. We publish specific intelligence that security teams can immediately use to improve their defenses.

Practical Security Guidance

Beyond threat analysis, we share practical guidance for security practitioners. Our tutorials cover API integration, SIEM configuration, threat hunting techniques, and building effective threat intelligence programs. Whether you're a SOC analyst, security engineer, or CISO, you'll find content tailored to your role and experience level.

Stay Ahead of Emerging Threats

The threat landscape evolves constantly. Our blog keeps you informed about the latest attack techniques, newly discovered vulnerabilities, and emerging threat actors. Subscribe to our newsletter for weekly digests of the most important developments in cybersecurity.

Subscribe to Our Newsletter

Weekly threat intelligence insights delivered to your inbox.