Malware
SecBox
- First Reported
- Sep 3, 2026
- Latest Reported
- Sep 3, 2026
Reported Context (1)
- The initial beachhead allowed the agent to gain command execution on the IIS server. This command-execution was used to download, stage and execute a Go-based implant we have called "SecBox": Chinese-Speaking Operator Used AI Agents to Target Government and Education Systems Across Asia
CVE (8)
Malware (1)
MITRE ATT&CK (12)
Vendors (5)
Products (15)
Tools (5)
Industries (9)
Countries (5)
Note: Related entities, including threat actors, malware, CVEs, MITRE ATT&CK techniques, vendors, products, tools, countries, and industries, are shown when they appear in the same reporting. Their presence does not necessarily mean they were targeted, compromised, vulnerable, responsible for the activity, or directly involved in the incident.