APT1 is an apt_group tracked by ThreatCluster, appearing in 3 threat clusters built from 4 intelligence report mentions.
APT1 is a apt_group tracked across 3 threat clusters and 4 intelligence report mentions on ThreatCluster. First observed April 22, 2026; most recent activity July 24, 2026.
In early 2026, the Iranian APT group MuddyWater launched cyberattacks against U.S. banking, a major airport, and Israeli operations of a U.S.-based software company. The attacks intensified in March, coinciding with…
Recent reports detail the tactics employed by various cyber adversaries to enumerate files and directories on compromised systems. Adversaries utilize command shell utilities and custom tools to gather sensitive…
On July 24, 2026, Google Threat Intelligence Group (GTIG) rolled out a new unified naming system for cyber threat actors. This system aims to standardize tracking across platforms and improve clarity in threat…
APT1 is an apt_group tracked by ThreatCluster, appearing in 3 threat clusters built from 4 intelligence report mentions.
The most recent intelligence report mentioning APT1 on ThreatCluster is dated July 24, 2026. Activity was first observed April 22, 2026, giving a tracked span from then to July 24, 2026.
Across ThreatCluster reporting, APT1 most frequently co-occurs with Ajax Security Team, Andariel, Apt12, Apt19, Apt28, among 12 tracked related entities.
The most significant recent cluster is “MuddyWater Targets U.S. Entities Amid Geopolitical Tensions” (16 articles · Updated July 22, 2026). APT1 appears across 3 threat clusters in total, listed above with sources.
APT1 appears in 4 intelligence report mentions across 3 deduplicated threat clusters, aggregated from 17,000+ monitored sources.