Related Threat Clusters
-
MuddyWater Targets U.S. Entities Amid Geopolitical Tensions
In early 2026, the Iranian APT group MuddyWater launched cyberattacks against U.S. banking, a major airport, and Israeli operations of a U.S.-based software company. The attacks intensified in March, coinciding with…
16 articles · Updated July 22, 2026 -
Exploitation of Remote Services in Cyber Attacks
Adversaries are increasingly leveraging external remote services like VPNs and Citrix to gain unauthorized access to networks. These attacks often involve using valid accounts obtained through credential harvesting or…
2 articles · Updated June 3, 2026 -
Widespread Abuse of ScreenConnect to Deploy AsyncRAT via Fake Installers
A significant cybersecurity campaign has emerged, exploiting the legitimate remote access tool ScreenConnect to deploy AsyncRAT malware. Attackers utilized spoofed websites and typosquatted domains, masquerading as…
7 articles · Updated July 1, 2026 -
GrayAlpha Threat Actor Uses MaskBat Loader for NetSupport RAT Deployments
Insikt Group identified GrayAlpha, a threat actor linked to FIN7, utilizing a custom loader named MaskBat to deploy NetSupport RAT through various infection vectors. These include fake browser update pages, fake 7-Zip…
2 articles · Updated August 6, 2026 -
Blind Eagle APT Targets Colombian Government with Multi-Stage Malware
The advanced persistent threat group Blind Eagle has executed a series of cyberattacks targeting Colombian government agencies using sophisticated multi-stage malware. The attacks began with spear-phishing emails that…
2 articles · Updated December 19, 2025
Recent Intelligence Reports
- T1027 — attack.mitre.org · August 7, 2026
- 002 — attack.mitre.org · July 23, 2026
- 002 — attack.mitre.org · July 23, 2026
- 001 — attack.mitre.org · July 23, 2026
- 012 — attack.mitre.org · July 1, 2026
- External Remote Services — attack.mitre.org · June 3, 2026
- Cyber Threat Group Blind Eagle Launches Sophisticated Malware Attacks — Techjuice.Pk · December 19, 2025