First observed in 2017, Bateleur is a JavaScript-based backdoor tool created by the Carbanak (also known as FIN7 or Anunak) advanced persistent threat group.
Epic is a backdoor created by the Turla advanced persistent threat group for use as a primary stage in their campaigns
Gorgon Group is an Advanced Persistent Threat (APT) group that has conducted targeted attacks against government organisations in the United Kingdom and other nations since February 2018.
First observed in 2017, Paradise is a ransomware tool sold to affiliates through a Malware-as-a-Service (MaaS) model.
Mebromi is a trojan that contains several rootkits and has been sold on underground markets since 2011.
QQ Browser is a Windows and Android internet browser produced by the Chinese technology company, Tencent. It is one of the most popular internet browsers worldwide, although only has a small percentage of UK users.
First observed in 2017, Hermes is a ransomware tool sold to other threat actors for use in their own campaigns
MiniDuke, also known as CosmicDuke or TinyBaron, is a remote access trojan targeting users in Europe, North America and Asia.
Parasite HTTP is a remote access trojan (RAT) that is sold on underground markets. It steals information and creates a backdoor for remote control of affected devices.
CactusTorch is fileless malware that executes malicious code on the infected devices.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
