Related Threat Clusters
-
Persistent Firestarter Malware Targets Cisco Firepower Devices in US Agencies
A sophisticated backdoor malware named Firestarter has been discovered on Cisco Firepower devices, attributed to the state-sponsored threat actor UAT-4356. The malware exploits two vulnerabilities, CVE-2025-20333 and…
37 articles · Updated April 23, 2026 -
MuddyWater Targets U.S. Entities Amid Geopolitical Tensions
In early 2026, the Iranian APT group MuddyWater launched cyberattacks against U.S. banking, a major airport, and Israeli operations of a U.S.-based software company. The attacks intensified in March, coinciding with…
16 articles · Updated July 22, 2026 -
ScarCruft's Supply-Chain Attack Targets Yanbian Gaming Platform with BirdCall Malware
ESET researchers reported a supply-chain attack by the North Korean APT group ScarCruft, targeting a gaming platform in the Yanbian region of China. The attack, ongoing since late 2024, involved trojanizing both Windows…
10 articles · Updated May 5, 2026 -
New NarwhalRAT Malware Targets Korean Users via Phishing Emails
A new malware named NarwhalRAT has been discovered targeting Korean users through phishing emails impersonating the Microsoft security team. The malware, linked to the North Korean hacking group APT37, can perform over…
9 articles · Updated June 15, 2026 -
APT37 Launches Targeted Cyberattack Using Social Media and Tampered Software
APT37, a North Korean state-sponsored threat group, has initiated a new targeted intrusion campaign aimed at defense-related entities. The attack utilizes social media platforms like Facebook and encrypted messaging…
2 articles · Updated April 13, 2026 -
North Korean Konni Group Uses KakaoTalk for Malware Distribution in Spear-Phishing Campaign
North Korea-linked hackers from the Konni group executed a spear-phishing campaign utilizing the KakaoTalk messaging platform to distribute malware and steal sensitive information. The campaign involved sending emails…
9 articles · Updated March 16, 2026 -
Exploitation of Client Software Vulnerabilities and User Execution Techniques
Recent cybersecurity reports detail the exploitation of software vulnerabilities in client applications, particularly targeting web browsers and Microsoft Office. Adversaries utilize techniques such as Drive-by…
2 articles · Updated June 8, 2026 -
Mini Shai-Hulud Supply Chain Attack Targets SAP npm Packages
A new supply chain attack, dubbed 'Mini Shai-Hulud', has compromised multiple npm packages related to SAP's Cloud Application Programming Model (CAP). This attack involves injecting malicious preinstall scripts into…
751 articles · Updated April 29, 2026 -
APT37 Hackers Deploy Custom Malware Against Air-Gapped Systems
North Korean threat group APT37 has initiated a campaign named Ruby Jumper, utilizing new custom malware to target air-gapped systems, which are typically isolated from the internet. This marks a significant advancement…
10 articles · Updated February 27, 2026 -
GrayAlpha Threat Actor Uses MaskBat Loader for NetSupport RAT Deployments
Insikt Group identified GrayAlpha, a threat actor linked to FIN7, utilizing a custom loader named MaskBat to deploy NetSupport RAT through various infection vectors. These include fake browser update pages, fake 7-Zip…
2 articles · Updated August 6, 2026
Recent Intelligence Reports
- Narwhalrat — www.genians.co.kr · August 8, 2026
- T1189 — attack.mitre.org · August 7, 2026
- T1027 — attack.mitre.org · August 7, 2026
- 003 — attack.mitre.org · July 23, 2026
- 002 — attack.mitre.org · July 23, 2026
- 001 — attack.mitre.org · July 23, 2026
- 001 — attack.mitre.org · July 23, 2026
- APT37 Hackers Use NarwhalRAT Malware With MS-Themed Phishing and Dead — Gbhackers · June 15, 2026