Related Threat Clusters
-
MuddyWater Targets U.S. Entities Amid Geopolitical Tensions
In early 2026, the Iranian APT group MuddyWater launched cyberattacks against U.S. banking, a major airport, and Israeli operations of a U.S.-based software company. The attacks intensified in March, coinciding with…
16 articles · Updated July 22, 2026 -
Bybit Sues North Korea Over $1.5 Billion Crypto Theft
Bybit has filed a civil lawsuit against North Korea, its Reconnaissance General Bureau, and the Lazarus Group, accusing them of orchestrating a $1.5 billion hack in February 2025. The lawsuit, filed in the U.S. District…
23 articles · Updated August 8, 2026 -
China-aligned APT Groups Target Global Maritime and Tech Sectors Amid Geopolitical Tensions
ESET's latest APT Activity Report reveals that from October 2025 to March 2026, China-aligned threat actors engaged in extensive espionage campaigns, particularly in Venezuela and the Gulf region. Following U.S.…
6 articles · Updated May 28, 2026 -
North Korea Adopts Modular Malware to Evade Detection and Takedowns
North Korea's cyber program has transitioned to a modular malware strategy, moving away from monolithic malware families to a more fragmented ecosystem. This change is a response to years of international sanctions, law…
3 articles · Updated April 6, 2026 -
Exploitation of Client Software Vulnerabilities and User Execution Techniques
Recent cybersecurity reports detail the exploitation of software vulnerabilities in client applications, particularly targeting web browsers and Microsoft Office. Adversaries utilize techniques such as Drive-by…
2 articles · Updated June 8, 2026 -
GrayAlpha Threat Actor Uses MaskBat Loader for NetSupport RAT Deployments
Insikt Group identified GrayAlpha, a threat actor linked to FIN7, utilizing a custom loader named MaskBat to deploy NetSupport RAT through various infection vectors. These include fake browser update pages, fake 7-Zip…
2 articles · Updated August 6, 2026 -
Ransomware Fuels Surge in Global Cyberattacks
As of February 12, 2026, organizations worldwide are experiencing an average of 2,090 cyber-attacks per week, largely driven by ransomware incidents. This increase highlights the ongoing challenges faced by businesses…
1908 articles · Updated February 12, 2026 -
Critical Vulnerabilities Discovered in Mozilla Products
Multiple vulnerabilities have been identified in Mozilla products, with the most severe allowing for arbitrary code execution. Exploitation could enable attackers to install programs, access, modify, or delete data, and…
44 articles · Updated April 8, 2026 -
Chrome Vulnerabilities Allow Arbitrary Code Execution and System Crashes
Google has released a critical security update for Chrome, addressing two high-severity vulnerabilities that could allow arbitrary code execution and denial-of-service attacks. Users on Windows, macOS, and Linux are…
500 articles · Updated February 4, 2026 -
North Korean Lazarus Group Targets US Healthcare with Medusa Ransomware
Cybersecurity researchers have identified attacks utilizing Medusa ransomware, attributed to the Lazarus group, a North Korean state-backed hacking operation. These attacks are primarily targeting U.S. healthcare…
20 articles · Updated February 24, 2026
Recent Intelligence Reports
- Gunra Ransomware Hit Hospitals and Governments; Linux Victims Should Not Pay Ransom — Techtimes · August 11, 2026
- This $1.5 billion hack is exposing just how 'irreversible' stolen crypto really is — Cryptoslate · August 8, 2026
- T1189 — attack.mitre.org · August 7, 2026
- 002 — attack.mitre.org · July 23, 2026
- 001 — attack.mitre.org · July 23, 2026
- T1203 · Exploitation for Client Execution — attack.mitre.org · June 8, 2026
- ESET Research APT Report: China-aligned groups spy in Venezuela and the Gulf, target AI ... — Markets.Businessinsider · May 28, 2026
- ESET APT Activity Report Q4 2025–Q1 2026 — Welivesecurity · May 28, 2026