Related Threat Clusters
-
GRU Compromises Home Routers in 23 States to Steal Outlook Credentials
The FBI and partners disrupted a covert network of compromised TP-Link and MikroTik routers exploited by the Russian GRU (APT28) to steal Outlook credentials. This operation, known as Operation Masquerade, revealed that…
6 articles · Updated May 22, 2026 -
Gamaredon APT Escalates Cyber Operations Against Ukraine in 2025
The Gamaredon group, a Russian-aligned APT, has significantly upgraded its cyber capabilities in 2025, focusing on spear-phishing campaigns against Ukrainian targets. ESET Research reports that Gamaredon conducted 35…
7 articles · Updated June 25, 2026 -
EU Sanctions Russia Over Ongoing Cyber Espionage Campaign
The European Union has condemned and sanctioned Russia for a prolonged cyber espionage campaign targeting its member states. The campaign, orchestrated by the 16th Centre of the FSB, has involved infiltrating government…
172 articles · Updated July 13, 2026 -
MuddyWater Targets U.S. Entities Amid Geopolitical Tensions
In early 2026, the Iranian APT group MuddyWater launched cyberattacks against U.S. banking, a major airport, and Israeli operations of a U.S.-based software company. The attacks intensified in March, coinciding with…
16 articles · Updated July 22, 2026 -
Data Destruction and Disk Wiping Techniques Targeting Organizations
Adversaries are employing data destruction and disk wiping techniques to disrupt organizational operations. Techniques include overwriting files and disk data, with malware exhibiting worm-like propagation capabilities.…
2 articles · Updated July 22, 2026 -
New Russian STOCKSTAY Spyware Targets Ukrainian Military
Google Threat Intelligence has identified a new spyware named STOCKSTAY, developed by the Russian hacking group Turla, aimed at Ukrainian military and government entities. This Windows backdoor is designed for cyber…
9 articles · Updated June 26, 2026 -
Kazuar Malware Evolves into Advanced P2P Botnet for Espionage
Kazuar, a malware attributed to the Russian state actor Secret Blizzard, has evolved into a sophisticated peer-to-peer botnet designed for long-term espionage. Originally a standard backdoor, Kazuar's modular…
10 articles · Updated May 15, 2026 -
Mini Shai-Hulud Supply Chain Attack Targets SAP npm Packages
A new supply chain attack, dubbed 'Mini Shai-Hulud', has compromised multiple npm packages related to SAP's Cloud Application Programming Model (CAP). This attack involves injecting malicious preinstall scripts into…
751 articles · Updated April 29, 2026 -
Aerospace Phishing Campaign Uses AnyDesk for Remote Access and Data Exfiltration
A spear-phishing campaign targets the aerospace sector, impersonating the Russian research institute VNIIR. Attackers use a spoof domain (vniir-avia.space) to deliver a password-protected RAR archive containing a…
4 articles · Updated July 7, 2026 -
GrayAlpha Threat Actor Uses MaskBat Loader for NetSupport RAT Deployments
Insikt Group identified GrayAlpha, a threat actor linked to FIN7, utilizing a custom loader named MaskBat to deploy NetSupport RAT through various infection vectors. These include fake browser update pages, fake 7-Zip…
2 articles · Updated August 6, 2026
Recent Intelligence Reports
- T1027 — attack.mitre.org · August 7, 2026
- T1485 — attack.mitre.org · July 23, 2026
- SPECIAL Informat. ro / What is Center 16 of the FSB and Turla, one of the oldest and most ... — Informat.Ro · July 13, 2026
- Thousands of MCP Servers Found Vulnerable to File Access and Injection Attacks — Gbhackers · July 7, 2026
- Attackers Exfiltrate AnyDesk Configuration Data via Blat SMTP in Aerospace Phishing Campaign — Gbhackers · July 7, 2026
- Turla group deploys new STOCKSTAY backdoor against Ukraine and Italy — Feeds.Feedburner · June 26, 2026
- Google discovers new Russian virus attacking Ukrainian military — Dev.Ua · June 26, 2026
- Russian APT 'Gamaredon' Upgrades Its Arsenal, Requiring New Defenses — Darkreading · June 25, 2026