Related Threat Clusters
-
Coordinated Cyberattack Disrupts Water Utilities in Minnesota
A coordinated cyberattack affected water utilities in over 30 Minnesota communities on July 26 and 27, 2026. Key cities impacted include Plymouth, South St. Paul, Braham, and Maple Plain. The attack targeted…
321 articles · Updated July 27, 2026 -
China-aligned APT Groups Target Global Maritime and Tech Sectors Amid Geopolitical Tensions
ESET's latest APT Activity Report reveals that from October 2025 to March 2026, China-aligned threat actors engaged in extensive espionage campaigns, particularly in Venezuela and the Gulf region. Following U.S.…
6 articles · Updated May 28, 2026 -
PATCHCORD Malware Targets Afghan Telecom and South Asian Infrastructure
Acronis Threat Research Unit has identified a new malware campaign named PATCHCORD, targeting Afghan telecom providers and critical infrastructure in South Asia. The malware, a custom backdoor written in C/C++, is…
10 articles · Updated August 13, 2026 -
State-Linked Cyber Threats Intensify Amid AI Advancements
Recent reports indicate that state-linked hackers are leveraging artificial intelligence to enhance their cyber capabilities, posing significant risks to national utilities and intellectual property. Additionally, a US…
2 articles · Updated March 11, 2026 -
SideCopy Targets Afghanistan Finance Ministry with XenoRAT Campaign
A Pakistan-linked threat actor, SideCopy, has initiated a spear-phishing campaign against Afghanistan's Ministry of Finance, targeting all 34 provincial revenue directorates. The campaign utilizes a ZIP archive…
5 articles · Updated May 30, 2026 -
Bitdefender Alerts on APT36's New AI 'Vibeware' Targeting India
Bitdefender has reported a new AI-driven attack model termed 'vibeware', which generates numerous disposable malware variants. This tactic is linked to APT36 (Transparent Tribe), a Pakistan-aligned threat actor that has…
8 articles · Updated March 6, 2026 -
Chronus Group Breach Exposes 36 Million Mexican Citizens' Data
In January 2026, the Chronus Group executed a significant data breach against the Mexican government, compromising 2.3 terabytes of sensitive data from at least 25 agencies. The breach exposed personal information of up…
2 articles · Updated May 28, 2026 -
Operation TrustTrap Uncovers 16,800 Fake Domains Targeting User Data
Cyble Research and Intelligence Labs (CRIL) has identified Operation TrustTrap, a significant domain spoofing campaign involving over 16,800 fraudulent domains that mimic legitimate U.S. government portals, particularly…
2 articles · Updated April 29, 2026 -
SilkParasite APT Targets Central Asian Governments with New RATs
The SilkParasite cyberespionage operation, linked to a China-nexus APT, is actively targeting government organizations across Central Asia, including Uzbekistan, Turkmenistan, Kyrgyzstan, Tajikistan, and Kazakhstan.…
10 articles · Updated August 19, 2026 -
APT36 Campaign Uses LNK Files for Cyberespionage Against Indian Targets
APT36, also known as Transparent Tribe, conducted a spear-phishing campaign targeting Indian government, strategic, and academic organizations. The campaign involved delivering malicious LNK files disguised as PDFs,…
2 articles · Updated January 5, 2026
Recent Intelligence Reports
- Threat Intelligence — www.eset.com · August 27, 2026
- SilkParasite: Tracking a China-Nexus APT Across Central Asia — Bitdefender · August 19, 2026
- APT36 Suspected in PATCHCORD Espionage Campaign Using Google Sheets C2 — Securityaffairs.Co · August 16, 2026
- Bitdefender — www.bitdefender.com · August 13, 2026
- PATCHCORD: New malware cluster targets Afghan telecom and South Asian critical infrastructure — Acronis · August 13, 2026
- PATCHCORD: New malware cluster targets Afghan telecom and South Asian critical infrastructure — Acronis · August 13, 2026
- Significant Cyber Incidents — www.csis.org · August 13, 2026
- SideCopy Deploys Persistent XenoRAT Against Afghanistan Finance Ministry — Gbhackers · May 30, 2026