Related Threat Clusters
-
Russian Hackers Exploit Zimbra Zero-Day for Espionage Campaign
Since July 2025, Russian state-backed hackers, known as Laundry Bear, have exploited a zero-click vulnerability (CVE-2025-66376) in the Zimbra Collaboration Suite to infiltrate Western government and commercial…
82 articles · Updated July 23, 2026 -
GRU Compromises Home Routers in 23 States to Steal Outlook Credentials
The FBI and partners disrupted a covert network of compromised TP-Link and MikroTik routers exploited by the Russian GRU (APT28) to steal Outlook credentials. This operation, known as Operation Masquerade, revealed that…
6 articles · Updated May 22, 2026 -
Widespread DNS Poisoning Campaign Targets Hotel Wi-Fi to Steal Credentials
A DNS poisoning campaign has compromised hotel and conference center Wi-Fi gateways to steal Microsoft 365 login credentials from corporate travelers. The campaign has been active since at least June 2026, affecting…
73 articles · Updated July 24, 2026 -
Russian FSB Exploits Vulnerable Routers to Target Critical Infrastructure
A joint advisory from 21 global cybersecurity agencies warns that Russian state hackers from the FSB's Center 16 are exploiting poorly configured routers to infiltrate critical infrastructure networks worldwide. The…
76 articles · Updated July 13, 2026 -
EU Sanctions Russia Over Ongoing Cyber Espionage Campaign
The European Union has condemned and sanctioned Russia for a prolonged cyber espionage campaign targeting its member states. The campaign, orchestrated by the 16th Centre of the FSB, has involved infiltrating government…
172 articles · Updated July 13, 2026 -
APT28 Exploits Vulnerable Routers for Global DNS Hijacking Campaign
Russian cyber group APT28, also known as Fancy Bear, has been exploiting vulnerabilities in TP-Link and MikroTik routers to conduct large-scale DNS hijacking operations. This campaign, which has affected over 18,000…
100 articles · Updated April 7, 2026 -
APT28 Exploits Roundcube Vulnerabilities in Targeted Cyber Espionage Campaign
APT28 (Fancy Bear) has been linked to Operation Roundish, utilizing a comprehensive Roundcube exploitation toolkit against Ukrainian government targets. The toolkit, discovered in January 2026, includes XSS payloads, a…
3 articles · Updated July 23, 2026 -
China-aligned APT Groups Target Global Maritime and Tech Sectors Amid Geopolitical Tensions
ESET's latest APT Activity Report reveals that from October 2025 to March 2026, China-aligned threat actors engaged in extensive espionage campaigns, particularly in Venezuela and the Gulf region. Following U.S.…
6 articles · Updated May 28, 2026 -
BlueDelta Espionage Campaign Using HOOKEDGE Targets European Governments
BlueDelta, a Russian state-linked threat actor, has conducted a series of espionage campaigns targeting government and diplomatic organizations in Romania, Spain, and Türkiye from late September 2025 to early April…
4 articles · Updated August 28, 2026 -
Russian APT Campaign Targets Ukraine with BadPaw and MeowMeow Malware
A Russian cyber campaign has been identified targeting Ukrainian organizations using new malware families, BadPaw and MeowMeow, delivered via phishing emails. The operation begins with emails containing links to ZIP…
4 articles · Updated March 5, 2026
Recent Intelligence Reports
- Threat Intelligence — www.eset.com · August 27, 2026
- BlueDelta Targets Defense and Diplomacy with HOOKEDGE — Recordedfuture · August 27, 2026
- Top 5 Cyber Threat Intelligence Services Benchmarked — Aimultiple · August 12, 2026
- Top 5 Cyber Threat Intelligence Services Benchmarked — Aimultiple · August 12, 2026
- ReliaQuest — reliaquest.com · August 5, 2026
- FrostArmada — www.lumen.com · August 3, 2026
- Operation Roundpress — www.welivesecurity.com · July 24, 2026
- Hackers hijack hotel Wi — Bleepingcomputer · July 24, 2026