Related Threat Clusters
-
Persistent Firestarter Malware Targets Cisco Firepower Devices in US Agencies
A sophisticated backdoor malware named Firestarter has been discovered on Cisco Firepower devices, attributed to the state-sponsored threat actor UAT-4356. The malware exploits two vulnerabilities, CVE-2025-20333 and…
37 articles · Updated April 23, 2026 -
Lazarus Group Escalates Attacks with Fileless RemotePE Trojan Targeting Crypto and Banks
The Lazarus Group, a North Korea-linked cybercrime organization, has intensified its operations against financial and cryptocurrency sectors using a sophisticated fileless Remote Access Trojan (RAT) called RemotePE.…
12 articles · Updated May 25, 2026 -
MuddyWater Targets U.S. Entities Amid Geopolitical Tensions
In early 2026, the Iranian APT group MuddyWater launched cyberattacks against U.S. banking, a major airport, and Israeli operations of a U.S.-based software company. The attacks intensified in March, coinciding with…
16 articles · Updated July 22, 2026 -
North Korean Hackers Target Open Source Software Supply Chain via npm Packages
Amazon's threat intelligence has linked a series of compromises of popular npm packages—axios, debug, chalk, and typo-crypto—to a North Korean hacking group known as Sapphire Sleet. The group employed social engineering…
11 articles · Updated July 29, 2026 -
FamousSparrow APT Expands Targeting to Azerbaijani Energy Sector
FamousSparrow, a China-aligned APT group, launched a multi-wave cyberespionage campaign against an Azerbaijani oil and gas company from late December 2025 to February 2026. The attackers employed an evolved DLL…
10 articles · Updated May 13, 2026 -
Data Destruction and Disk Wiping Techniques Targeting Organizations
Adversaries are employing data destruction and disk wiping techniques to disrupt organizational operations. Techniques include overwriting files and disk data, with malware exhibiting worm-like propagation capabilities.…
2 articles · Updated July 22, 2026 -
North Korean Sapphire Sleet Targets macOS Users in New Social Engineering Campaign
A North Korean cybercrime group known as Sapphire Sleet has launched a social engineering campaign targeting macOS users, as reported by Microsoft's Threat Intelligence unit. The campaign involves tricking users into…
7 articles · Updated April 17, 2026 -
Mini Shai-Hulud Supply Chain Attack Targets SAP npm Packages
A new supply chain attack, dubbed 'Mini Shai-Hulud', has compromised multiple npm packages related to SAP's Cloud Application Programming Model (CAP). This attack involves injecting malicious preinstall scripts into…
751 articles · Updated April 29, 2026 -
GrayAlpha Threat Actor Uses MaskBat Loader for NetSupport RAT Deployments
Insikt Group identified GrayAlpha, a threat actor linked to FIN7, utilizing a custom loader named MaskBat to deploy NetSupport RAT through various infection vectors. These include fake browser update pages, fake 7-Zip…
2 articles · Updated August 6, 2026 -
Kelp DAO Exploit: $293 Million Drain Triggers DeFi Contagion
On April 18, 2026, Kelp DAO's LayerZero-powered cross-chain bridge was exploited, resulting in the theft of 116,500 rsETH, valued at approximately $293 million. The attacker utilized a forged cross-chain message to…
187 articles · Updated April 18, 2026
Recent Intelligence Reports
- T1189 — attack.mitre.org · August 7, 2026
- Amazon pins multiple open source compromises on North Korea — Computerweekly · July 30, 2026
- 002 — attack.mitre.org · July 23, 2026
- T1485 — attack.mitre.org · July 23, 2026
- 001 — attack.mitre.org · July 23, 2026
- Microsoft Attributes Mastra AI Supply Chain Attack to North Korea — Infosecurity-Magazine · June 22, 2026
- SOC Prime: Detect Lazarus Attacks Using Three New RATs — socprime.com · May 26, 2026
- T1505.003 Web Shell — attack.mitre.org · May 13, 2026