AcronisAcronisAcronisAcronisAcronisAcronisAcronisAcronisAcronisAcronisAcronis
Acronis
Acronis Threat Research Unit

Acronis Threat Research Unit

Threat Research Unit is a dedicated Acronis unit composed of experienced cybersecurity experts. Our team includes cross-functional experts in cybersecurity, AI, and threat intelligence. We are empowering IT teams with intelligence-driven cyberthreat research and reporting.

Acronis Threat Research Unit's articles

November 19, 2025

Cooking up trouble: How TamperedChef uses signed apps to deliver stealthy payloads

Acronis Threat Research Unit (TRU) observed a global malvertising / SEO campaign, tracked as “TamperedChef.” It delivers legitimate-looking installers that disguise as common applications to trick users into installing them, establish persistence and deliver obfuscated JavaScript payloads for remote access and control.

November 18, 2025

Acronis Cyberthreats Update, November 2025

The Acronis Cyberthreats Update covers current cyberthreat activity and trends, as observed by Acronis Threat Research Unit (TRU) and Acronis sensors. Figures presented here were gathered in October 2025 and reflect threats that Acronis detected, as well as news stories from the public domain.

November 10, 2025

MSP cybersecurity news digest November 10, 2025

Must-know cybersecurity news for MSPs: GlassWorm, ClickFix, Gootloader and the dangerous new era of AI-powered malware. Review key threats and a major public-sector breach.

November 10, 2025

Acronis TRU Alliance {VirusTotal}: Tracking FileFix, Shadow Vector, and SideWinder

Introducing the Acronis TRU Alliance Series. This new series highlights collaborative research analysis between Acronis Threat Research Unit (TRU) and other leading threat intelligence teams. In this first post of our collaboration series, we’ve teamed up with VirusTotal (VT) to share practical insights from Acronis TRU on several recent reports.

November 07, 2025

MSP cybersecurity news digest, November 3, 2025

Qilin ransomware abuses Windows Subsystem for Linux to deploy Linux encryptors on Windows, Atroposia malware includes built-in vulnerability scanner for targeted exploitation, and more. Here are the latest threats to MSP security.

October 28, 2025

MSP cybersecurity news digest, October 28, 2025

Urgent WSUS RCE flaw actively exploited! Plus: Fake LastPass inheritance emails steal vaults, Iran's MuddyWater APT targets government entities and a new RedTiger Discord infostealer.

October 17, 2025

Acronis Cyberthreats Update, October 2025

The Acronis Cyberthreats Update covers current cyberthreat activity and trends, as observed by Acronis Threat Research Unit (TRU) and Acronis sensors. Figures presented here were gathered in September 2025 and reflect threats that Acronis detected, as well as news stories from the public domain.

October 13, 2025

MSP cybersecurity news digest, October 13, 2025

Medusa exploits GoAnywhere MFT, Discord data leaks via Zendesk, plus Vampire Bot and Qilin ransomware attacks. Get the critical MSP cybersecurity news and defense actions now.

October 06, 2025

MSP cybersecurity news digest, October 6, 2025

Harrods breach tied to supplier compromise leaks 430,000 records, MatrixPDF toolkit weaponizes PDFs for phishing and malware delivery, and more. Here are the latest threats to MSP security.