img

Intelligence to Stay Ahead of Cyber Threats

Cyber threats are evolving fast — and so is Aryaka. The Aryaka Threat Research Lab, led by Aditya K. Sood, Ph.D., delivers threat intelligence and research to help businesses proactively detect, mitigate, and defend against emerging risks.
Led by Aditya K. Sood, Ph.D., the Aryaka Threat Research Lab drives innovation by feeding advanced threat insights into Aryaka’s Unified SASE as a Service platform.

Contributors

Aditya K Sood
Aditya K Sood

VP of Security Engineering and AI Strategy

Read Bio >

Varadharajan K
Varadharajan K

Principal Threat Research Engineer

Read Bio >

Explore our latest research below

Blog
Report
Whitepapers
News

From ZIP File to crpx0 Ransomware: Anatomy of a Multi-Stage Attack

Aryaka Threat Research Labs has discovered a campaign that shows how simple user actions can trigger complex, multi-stage malware execution…

Read Blog

Kernel in the Crosshairs: The BlackSanta Threat Campaign Targeting Recruitment Workflows

The Resume that wasn’t a Resume It begins in one of the most trusted workflows inside any organization: hiring. An…

Read Blog

Espionage Without Noise: Understanding APT36’s Enduring Campaigns

Critical infrastructure all over the world is under threat from highly organized, state-sponsored “espionage ecosystems”. These loosely knit but well-resourced…

Read Blog

Phantoms in the Cloud: Fraudsters Exploit Google Cloud Storage for Deceptive Campaigns

It all began with a whisper—a few unassuming emails slipping into inboxes on an ordinary Tuesday morning. No bells, no…

Read Blog

BatShadow: Vietnamese Threat Actor Expands Its Digital Operations

By Aditya K Sood | By Varadharajan K | Sept 25, 2025 Get the new Batshadow Threat Report or Explore…

Read Blog

Vidar Malware is Back: New Aryaka Threat Research Report

Vidar, a well-known info-stealing malware, is making the rounds again with a few new tricks. In a new report, Aryaka’s…

Read Blog

Wiley’s Internet Technology Letters Published Research on Generative AI for Adaptive Threat Hunting

Recently, we published a research piece in Wiley’s Internet Technology Letters on highlighting the importance of Generative (GenAI) for revolutionizing…

Read Blog

North Korea’s Kimsuky APT: A Stealthy Threat Adapting to the Evolving Digital World

By Aditya K Sood | By Varadharajan K | July 29, 2025 In today’s hyper-connected landscape, the traditional notion of…

Read Blog

Fortifying Your Network: How Aryaka’s Unified SASE Shields Against Advanced Threats Like Remcos RAT

In the evolving landscape of cybersecurity, threats like Remcos RAT (Remote Access Trojan) have become increasingly sophisticated, leveraging stealthy techniques…

Read Blog

Advanced AI Security Research Released in Communications of the ACM Magazine

Our latest research on the challenges associated with malicious AI models has been published in the Communications of the ACM…

Read Blog

Remcos on the Wire: Analyzing Network Artifacts and C2 Command Structures

By Varadharajan K | By Bikash Dash | Jun 02, 2025 Overview   Remcos is a remote access trojan (RAT)…

Read Blog

Advanced Security Research: The Paradigm of Hallucinations in AI-driven Cybersecurity Systems

Aryaka Threat Research Lab recently published an advanced AI research paper in the Elsevier Computer and Electrical Engineering (CAEE) journal…

Read Blog

Strela Stealer Malware Research: Tracing the Digital Footprint and Network Behavior

Strela Stealer, a sophisticated information-stealing malware, is designed to exfiltrate sensitive user credentials, primarily targeting email and web browser data.…

Read Blog

Snake Infostealer: A Look into Data Exfiltration via SMTP

Data exfiltration via Simple Mail Transfer Protocol (SMTP) is a robust method attackers use to transfer sensitive or confidential information…

Read Blog

Introducing Aryaka Threat Research Lab

Cybersecurity threats are evolving at an unprecedented pace, putting organizations at constant risk. To stay ahead of these threats and…

Read Blog

SaltTyphoon APT: Unified SASE as a Service to the Rescue

Overview Events like SaltTyphoon are an excellent reminder of enterprise and users’ susceptibility to breaches because of dependencies on infrastructure…

Read Blog

Disrupting The Attack Surface with Unified SASE as a Service by Deterring Malicious Communication

Resilient cybersecurity is a strategic approach that emphasizes the ability of an organization to withstand, adapt to, and recover from…

Read Blog
TRL Page Mockup

crpx0 Ransomware Operations

Double Extortion, Crypto Theft, and Network Footprint

View Report
report trl page

BlackSanta EDR-Killer

A Silent Threat Targeting Recruitment Workflows

View Report
report 1

Unveiling Transparent Tribe’s (APT36) C&C and Network Tradecraft

Targeting Indian Government and Defence

View Report
report 2

Scam in the Cloud

How Attackers Weaponize Google Cloud Storage to Launch Multi-Stage Fraud Campaigns

View Report
report 3

Vietnamese Threat Actor Expands Operations

New “BatShade” Campaign Takes Center Stage

View Report
report 4

Vidar Infostealer in Action

From API Hooking to Covert Data Exfiltration

View Report
report 5

From Reconnaissance to Control

The Operational Blueprint of Kimsuky APT for Cyber Espionage

View Report
whitepaper 1

Aryaka Threat Research Lab

Disrupting The Attack Surface with Unified SASE as a Service by Deterring Malicious Communication

Read Whitepaper
the hacker news

ThreatsDay Bulletin: PAN-OS RCE, Mythos cURL Bug, AI Tokenizer Attacks, and 10+ Stories

A VBScript loader prepares the system and silently installs the components needed to run Python-based code. This is where the…

Read News
Sc media

New CRPx0 malware campaign uses OnlyFans lure for crypto theft and ransomware

A complex and stealthy malware campaign dubbed CRPx0 is targeting MacOS and Windows systems, with potential Linux capabilities in development.…

Read News
securityweek

Free OnlyFans Lure Used to Spread Cross-Platform CRPx0 Malware

CRPx0 is a complex, stealthy and persistent malware campaign. It currently targets macOS and Windows systems, and appears to have…

Read News
techradar

Russian hackers target HR departments with vicious new ‘BlackSanta’ malware

Russian hackers have been targeting Human Resources (HR) departments at various organizations around the world with a never-before seen piece…

Read News
Aryaka Threat Research Lab News Coverage - Cybernews

HR departments are being targeted with fake resumes that disable security protection

A threat campaign against human resource (HR) departments has recently been launched. What seems like a decent resume actually is…

Read News
security week

‘BlackSanta’ Malware Activates EDR and AV Killer Before Detonating Payload

The malware disables antivirus and EDR protections at the kernel level, clearing the path for credential harvesting, system reconnaissance, and…

Read News
SC Media

BlackSanta ‘EDR-killer’ malware targets HR departments

A specialized “EDR-killer” malware module known as BlackSanta has been discovered operated by a Russian-speaking threat actor that primarily targets…

Read News
hackread

BlackSanta Malware Targets HR Staff with Fake CV Downloads

Aryaka researchers have identified a new threat from a Russian-speaking group using ‘BlackSanta’ malware. By disguising attacks as job applications,…

Read News
infosecurity trl

BlackSanta EDR-Killer Targets HR Teams in CV-Themed Campaign

A new malware campaign targeting human resources and recruiting staff has seen attackers distribute malicious files disguised as job applications.

Read News
gbhackers

HR Departments Targeted by Multi-Layered BlackSanta EDR Killer Malware

Threat actors are increasingly targeting human resources (HR) departments by disguising malware as job application documents.

Read News
security boulevard

BlackSanta Malware Shuts Down Protections, Targets HR and Recruiting Operations

Russian threat actors have targeted HR employees and recruiters for more than a year with a sophisticated campaign that includes…

Read News
CSO

Resumés with malicious ISO attachments are circulating, says Aryaka

HR staff need to understand that these unfamiliar files execute commands and shouldn’t be opened.

Read News
DarkReading

‘BlackSanta’ EDR Killer Targets HR Workflows

A campaign by Russian-speaking cyberattackers hijacks workflows to deliver security-busting malware, allowing attackers to steal data without detection.

Read News
theregister logo

Fake job applications pack malware that kills endpoint detection before stealing data

A Russian-speaking cyber criminal is targeting corporate HR teams with fake CVs that quietly install malware which can disable security…

Read News
bleepingcomputer

New ‘BlackSanta’ EDR killer spotted targeting HR departments

For more than a year, a Russian-speaking threat actor targeted human resource (HR) departments with malware that delivers a new…

Read News
help net security

HR, recruiters targeted in year-long malware campaign

An attack campaign targeting HR departments and job recruiters has been stealthily compromising systems, Aryaka researchers have discovered.

Read News
Computer weekly

Convergence – The Sequel (And How To Avoid Trade-Offs)

I recently published a blog, post-conversation with Albert Estevez Polo (current leader in “Broadband-Testing name of the year 2026” competition)…

Read News
Computer weekly

Making sense of AI’s role in cyber security

Cyber security companies have jumped on the AI bandwagon. We look at where artificial intelligence is a useful add-on and…

Read News
cyber security news

APT36 Hacker Group Attacking Linux Systems with New Tools to Disturb Services

Indian defense sector and government-aligned organizations have been targeted by multiple campaigns that are designed to compromise Windows and Linux…

Read News
The Hackewr news

APT36 and SideCopy Launch Cross-Platform RAT Campaigns Against Indian Entities

Indian defense sector and government-aligned organizations have been targeted by multiple campaigns that are designed to compromise Windows and Linux…

Read News
SC Media

Report sheds light on multi-pronged APT36 attacks against India

Indian government and defense organizations have been targeted by Pakistan-linked threat group APT36, also known as Transparent Tribe, in multiple…

Read News
security week

RATs in the Machine: Inside a Pakistan-Linked Three-Pronged Cyber Assault on India

Transparent Tribe (APT36) is targeting Indian defense and government sectors with GETA, ARES, and Desk RATs in a new wave…

Read News
gbhackers logo

APT36 Targets Linux Systems With New Tools Designed to Disrupt Services

Critical infrastructure worldwide faces mounting threats from sophisticated, state-sponsored “espionage ecosystems.”

Read News
Computer weekly

From promise to proof: making AI security adoption tangible

The Security Think Tank considers what CISOs and buyers need to know to cut through the noise around AI and…

Read News
Cloud 365

Unified SASE e Segurança Integrada Marcam os Desafios Reais dos CISO Portugueses

A visibilidade continua a ser um dos principais problemas dos CISO. Não por falta de ferramentas, mas pela fragmentação dos…

Read News
Computer weekly

From trust to turbulence: Cyber’s road ahead in 2026

As we prepare to close out 2025, the Computer Weekly Security Think Tank panel looks back at the past year,…

Read News
CSO

Suspicious traffic could be testing CDN evasion, says expert

An individual or group is doing new probing of content delivery networks (CDNs), an effort that CSOs, CIOs and network…

Read News
Forbes

New Android Warning As Humanized Password Stealer Confirmed

New Android Warning As Humanized Password Stealer Confirmed

Read News
DarkReading

Vampire Bot Malware Sinks Fangs Into Job Hunters

The campaign is the latest by BatShadow, one of a growing number of cybercrime groups operating out of Vietnam.

Read News
IT Brief

BatShade: Vietnamese threat actor expands its digital operations

Aryaka Threat Research Labs has identified a new campaign by the Vietnamese threat actor BatShade, which continues to rely on…

Read News
Security Brief

BatShade: Vietnamese threat actor expands its digital operations

Aryaka Threat Research Labs has identified a new campaign by the Vietnamese threat actor BatShade, which continues to rely on…

Read News
The Hackewr news

BatShadow Group Uses New Go-Based ‘Vampire Bot’ Malware to Hunt Job Seekers

A Vietnamese threat actor named BatShadow has been attributed to a new campaign that leverages social engineering tactics to deceive…

Read News
The Hackewr news

⚡ Weekly Recap: Bootkit Malware, AI-Powered Attacks, Supply Chain Breaches, Zero-Days & More

In a world where threats are persistent, the modern CISO’s real job isn’t just to secure technology—it’s to preserve institutional…

Read News
Bankind Info

Breach Roundup: Vidar Strikes Back

Every week, ISMG rounds up cybersecurity incidents and breaches around the world. This week, the Vidar infostealer is badder than…

Read News
DarkReading

Vidar Infostealer Back With a Vengeance

The pervasive Vidar infostealer has evolved with a suite of new evasion techniques and covert data exfiltration methods, according to…

Read News
SC Media

Adoption of Vidar infostealer on the rise, report finds

More cybercriminals have been utilizing the Vidar information stealer in attacks this year due to the malware’s low barrier of…

Read News
trl silicon

Vidar infostealer gains traction among cybercriminals as ease of use drives adoption

A new report released today by secure access service edge provider Aryaka Networks Inc. is warning of the growing threat…

Read News
DarkReading

How Evolving RATs Are Redefining Enterprise Security Threats

A more unified and behavior-aware approach to detection can significantly improve security outcomes.

Read News
DarkReading

Rubio Impersonator Signals Growing Security Threat From Deepfakes

An impostor who posed as the secretary of state in text and voice communications with diplomats and politicians demonstrates the…

Read News
Computer weekly

Fortifying the future: The pivotal role of CISOs in AI operations

The Security Think Tank considers how CISOs can best plan to facilitate the secure running of AI and Gen AI-based…

Read News
CPO

French Luxury Giant Dior Confirms Data Breach after a Cyber Attack

French luxury giant Dior has confirmed a data breach after experiencing a cyber attack that resulted in unauthorized access to…

Read News
Aryaka Threat Research Lab News Coverage - SecurityBrief United States

Ransomware hits Kettering Health: Experts speak out

Amajor ransomware attack has struck Kettering Health, a nonprofit network operating 14 medical centres and more than 120 outpatient facilities…

Read News
Aryaka Threat Research Lab News Coverage - Cybernews

M&S hackers used employee logins from third-party consulting firm TCS, sources say

New information reveals Scattered Spider, the ransomware group responsible for the Marks & Spencer (M&S) cyberattack, allegedly gained access to…

Read News
Aryaka Threat Research Lab News Coverage - Digital Journal

Perfume and steel: Dior and Nucor in cyberattacks

Luxury fashion giant Dior and steel manufacturing giant Nucor both announced that the companies were dealing with cybersecurity incidents. This…

Read News
Aryaka Threat Research Lab News Coverage - SecurityBrief United States

Coinbase offers USD $20 million bounty after insider data breach

Coinbase, one of the world’s largest cryptocurrency exchanges, has confirmed it suffered a significant data breach orchestrated by cybercriminals who…

Read News
Aryaka Threat Research Lab News Coverage - SecurityBrief United States

Alabama cyberattack exposes state staff credentials, disrupts services

The state of Alabama is investigating a significant cybersecurity incident that has led to the disruption of certain government services…

Read News
Computer weekly

Unspoken risk: Human factors undermine trusted platforms

A leak of information on American military operations caused a major political incident in March 2025.

Read News
itpro logo

What is polymorphic malware?

Polymorphic malware constantly changes its code to avoid detection, making it a top cybersecurity threat that demands advanced, behavior-based defenses

Read News
easyprey

Safe AI Implementation

Red models associated with AI technologies highlight real-world vulnerabilities and the importance of proactive security measures.

Read News
itpro logo

Malware-free attacks: The threat to businesses

Malware-free attacks are a growing risk – what can businesses do to mitigate them?

Read News
security news

Kidney dialysis firm DaVita hit by weekend ransomware attack

DaVita, a kidney dialysis company, has experienced a ransomware attack. The organization disclosed the incident in a filing with the…

Read News
helpnetsecurity

Strategic AI readiness for cybersecurity: From hype to reality

AI readiness in cybersecurity involves more than just possessing the latest tools and technologies; it is a strategic necessity.

Read News
sc media

Fate of DNA data raises privacy, identity issues in 23andMe bankruptcy

News of the troubled DNA testing services company 23andMe filing for Chapter 11 bankruptcy protection set off a spirited debate…

Read News
enterprise security tech

23andMe Bankruptcy Sparks Urgent DNA Data Privacy Reckoning

In what could become a defining moment for consumer privacy in the digital age, 23andMe — the once high-flying genetics…

Read News
dark reading

23andMe Bankruptcy Filing May Put Sensitive Data at Risk

Genetic testing company 23andMe quietly filed for bankruptcy over the weekend, and now security experts are worried about the fate…

Read News
sc media uk

DeepSeek AI: The Hidden Perils of Data Privacy and Security

DeepSeek AI is a cautionary tale that underscores the need for greater security, transparency and accountability in the AI ecosystem.

Read News
csi

DeepSeek – A Deep Dive Reveals More Than One Red Flag

Like many advanced AI-driven tools, the Chinese DeepSeek AI application offers incredible innovation. Still, it raises significant data privacy concerns…

Read News
betanews

How GenAI adoption introduces network and security challenges [Q&A]

Enterprises are increasingly using GenAI to transform their organization. As they move ahead, they’re evaluating their preparedness from a business,…

Read News
security brief

Experts warn of security risks as DeepSeek limits new sign-ups

Cybersecurity experts have raised concerns over potential security risks in DeepSeek’s artificial intelligence platform after the Chinese AI startup announced…

Read News
Blog

From ZIP File to crpx0 Ransomware: Anatomy of a Multi-Stage Attack

Read Blog

Kernel in the Crosshairs: The BlackSanta Threat Campaign Targeting Recruitment Workflows

Read Blog

Espionage Without Noise: Understanding APT36’s Enduring Campaigns

Read Blog

Phantoms in the Cloud: Fraudsters Exploit Google Cloud Storage for Deceptive Campaigns

Read Blog

BatShadow: Vietnamese Threat Actor Expands Its Digital Operations

Read Blog
Vidar-Malware Report

Vidar Malware is Back: New Aryaka Threat Research Report

Read Blog

Wiley’s Internet Technology Letters Published Research on Generative AI for Adaptive Threat Hunting

Read Blog

North Korea’s Kimsuky APT: A Stealthy Threat Adapting to the Evolving Digital World

Read Blog

Fortifying Your Network: How Aryaka’s Unified SASE Shields Against Advanced Threats Like Remcos RAT

Read Blog

Advanced AI Security Research Released in Communications of the ACM Magazine

Read Blog

Remcos on the Wire: Analyzing Network Artifacts and C2 Command Structures

Read Blog

Advanced Security Research: The Paradigm of Hallucinations in AI-driven Cybersecurity Systems

Read Blog

Strela Stealer Malware Research: Tracing the Digital Footprint and Network Behavior

Read Blog

Snake Infostealer: A Look into Data Exfiltration via SMTP

Read Blog

Introducing Aryaka Threat Research Lab

Read Blog

SaltTyphoon APT: Unified SASE as a Service to the Rescue

Read Blog
Reports
Placeholder Image

crpx0 Ransomware Operations

Double Extortion, Crypto Theft, and Network Footprint

View Report

BlackSanta EDR-Killer

A Silent Threat Targeting Recruitment Workflows

View Report

Unveiling Transparent Tribe’s (APT36) C&C and Network Tradecraft

Targeting Indian Government and Defence

View Report

Scam in the Cloud

How Attackers Weaponize Google Cloud Storage to Launch Multi-Stage Fraud Campaigns

View Report

Vietnamese Threat Actor Expands Operations

New “BatShade” Campaign Takes Center Stage

View Report

Vidar Infostealer in Action

From API Hooking to Covert Data Exfiltration

View Report

From Reconnaissance to Control

The Operational Blueprint of Kimsuky APT for Cyber Espionage

View Report
Whitepapers

Aryaka Threat Research Lab

Disrupting The Attack Surface with Unified SASE as a Service by Deterring Malicious Communication

Read Whitepaper
News
the hacker news

ThreatsDay Bulletin: PAN-OS RCE, Mythos cURL Bug, AI Tokenizer Attacks, and 10+ Stories

Read News
Sc media

New CRPx0 malware campaign uses OnlyFans lure for crypto theft and ransomware

Read News
securityweek

Free OnlyFans Lure Used to Spread Cross-Platform CRPx0 Malware

Read News
techradar

Russian hackers target HR departments with vicious new ‘BlackSanta’ malware

Read News
Aryaka Threat Research Lab News Coverage - Cybernews

HR departments are being targeted with fake resumes that disable security protection

Read News
security week

‘BlackSanta’ Malware Activates EDR and AV Killer Before Detonating Payload

Read News
SC Media

BlackSanta ‘EDR-killer’ malware targets HR departments

Read News
hackread

BlackSanta Malware Targets HR Staff with Fake CV Downloads

Read News
infosecurity trl

BlackSanta EDR-Killer Targets HR Teams in CV-Themed Campaign

Read News
gbhackers

HR Departments Targeted by Multi-Layered BlackSanta EDR Killer Malware

Read News
security boulevard

BlackSanta Malware Shuts Down Protections, Targets HR and Recruiting Operations

Read News
CSO

Resumés with malicious ISO attachments are circulating, says Aryaka

Read News