Related Threat Clusters
-
Kimsuky Expands AI Capabilities for Cyberattacks
The North Korean hacking group Kimsuky has developed local AI tools to enhance its cyberattack capabilities, as reported by Genians Security Center on August 10, 2026. The group is utilizing large language models (LLMs)…
49 articles · Updated August 10, 2026 -
MuddyWater Targets U.S. Entities Amid Geopolitical Tensions
In early 2026, the Iranian APT group MuddyWater launched cyberattacks against U.S. banking, a major airport, and Israeli operations of a U.S.-based software company. The attacks intensified in March, coinciding with…
16 articles · Updated July 22, 2026 -
Kimsuky Exploits South Korean Groupware Vendors with New Gomir Variants
The Kimsuky group, linked to North Korea, targeted South Korean groupware vendors from late 2025 to early 2026, deploying new malware variants BirdTroy and DriveTroy. These Linux backdoors utilized Google Drive for…
4 articles · Updated July 24, 2026 -
FamousSparrow APT Expands Targeting to Azerbaijani Energy Sector
FamousSparrow, a China-aligned APT group, launched a multi-wave cyberespionage campaign against an Azerbaijani oil and gas company from late December 2025 to February 2026. The attackers employed an evolved DLL…
10 articles · Updated May 13, 2026 -
China-aligned APT Groups Target Global Maritime and Tech Sectors Amid Geopolitical Tensions
ESET's latest APT Activity Report reveals that from October 2025 to March 2026, China-aligned threat actors engaged in extensive espionage campaigns, particularly in Venezuela and the Gulf region. Following U.S.…
6 articles · Updated May 28, 2026 -
Kimsuky Group Leverages AI for Malware Targeting South Korean Government
The North Korean hacking group Kimsuky is utilizing generative AI to create malware aimed at South Korean government systems, as reported by Kaspersky on May 14, 2026. The malware, named HelloDoor, is a Rust-based…
5 articles · Updated May 14, 2026 -
Kimsuky Targets South Korea with Advanced Malware and Social Engineering Tactics
North Korean hackers known as Kimsuky have launched a series of cyberattacks against South Korean military and corporate sectors during March and April 2026. The group utilized sophisticated social engineering tactics,…
2 articles · Updated May 29, 2026 -
Exploitation of Remote Services in Cyber Attacks
Adversaries are increasingly leveraging external remote services like VPNs and Citrix to gain unauthorized access to networks. These attacks often involve using valid accounts obtained through credential harvesting or…
2 articles · Updated June 3, 2026 -
Alex Lab Hack Affects SPD Bank Clients After $8.3M Exploit
A security breach at the Bitcoin DeFi protocol Alex Lab has impacted customers of Shanghai Pudong Development Bank (SPD Bank). The incident, which occurred on June 6, 2025, resulted in the loss of approximately $8.3…
6 articles · Updated April 30, 2026 -
North Korean Hackers Target Pharma Firms with Weaponized Excel Malware
North Korean state-backed hackers, specifically the Kimsuky group, have initiated a targeted campaign against pharmaceutical and life science companies. The attackers utilize weaponized Excel files, disguised as…
2 articles · Updated April 27, 2026
Recent Intelligence Reports
- Kimsuky Abuses Remote Access Tools Across Northeast Asia — Socprime · August 26, 2026
- Kimsuky Uses AI — Cybersecuritynews · August 24, 2026
- a popular alternative to traditional phishing and how businesses can close the gap — Belgashare.Be · August 18, 2026
- Kimsuky Ai Llm — www.genians.co.kr · August 18, 2026
- How QR-code phishing can slip past corporate security measures — Welivesecurity · August 17, 2026
- Dead Drop Resolver — attack.mitre.org · August 14, 2026
- Kimsuky Ai Llm — www.genians.co.kr · August 12, 2026
- North Korean hacking group builds AI tools — Itnews.Au · August 10, 2026