Apt44 is a apt_group tracked across 12 threat clusters and 15 intelligence report mentions on ThreatCluster. First observed November 6, 2025; most recent activity July 23, 2026.
The Russian state-backed hacking group Sandworm has intensified its operations against Ukrainian organizations by deploying data-wiping malware. This campaign targets critical sectors, including the grain industry, and…
Two Russia-aligned cyber campaigns are exploiting the WinRAR vulnerability CVE-2025-8088 against Ukrainian targets nearly a year after it was patched. The flaw, a path traversal vulnerability, allows attackers to write…
Ukraine's CERT-UA reported that the Russian GRU-linked hacking group Sandworm is employing fake CAPTCHA prompts to trick users into executing malicious PowerShell commands on their devices. This method, known as…
The Russian state-sponsored group Sandworm has intensified its cyber operations against industrial and critical infrastructure, utilizing pre-compromised operational technology (OT) environments instead of zero-day…
Ukrainian CERT has reported a cyber campaign attributed to threat cluster UAC-0099, targeting organizations in Ukraine. The attackers distribute a ZIP archive containing Notepad++ version 8.8.3 and a malicious plugin…
Amazon Web Services (AWS) has linked a multi-year cyber espionage campaign targeting Western critical infrastructure, particularly in the energy sector, to the Russian GRU-affiliated group Sandworm (APT44). The campaign…
Spanish authorities arrested a man in Palencia suspected of being affiliated with pro-Russia hacktivist groups CyberArmy of Russia Reborn (CARR) and Z-Pentest. The arrest, made in March 2026, followed an FBI tip-off…
The Russian state-backed hacker group Sandworm has launched a campaign using data-wiping malware against Ukrainian organizations, particularly focusing on the grain sector. This attack aims to disrupt critical…
APT36, also known as Transparent Tribe, has been conducting persistent cyber espionage campaigns against the Indian government and defense organizations for over a decade. This espionage ecosystem, which includes the…
The cyber threat group Amaranth-Dragon has leveraged a critical vulnerability in WinRAR, identified as CVE-2025-8088, to gain persistent control over systems belonging to Southeast Asian governments. This exploitation…