Knaithe — Threat Actor Profile, Campaigns & Targets

Threat entity extracted from intelligence sources

Frequency
1
occurrences
First Seen
July 30, 2026
Last Seen
July 30, 2026

Knaithe is an apt_group tracked by ThreatCluster, appearing in 1 threat cluster built from 1 intelligence report mention.

Knaithe is a apt_group tracked across 1 threat cluster and 1 intelligence report mention on ThreatCluster. First observed July 30, 2026; most recent activity July 30, 2026.

Related Threat Clusters

Recent Intelligence Reports

  • Chinese — Oodaloop · July 30, 2026

Frequently asked questions

What is Knaithe?

Knaithe is an apt_group tracked by ThreatCluster, appearing in 1 threat cluster built from 1 intelligence report mention.

Is Knaithe still active?

The most recent intelligence report mentioning Knaithe on ThreatCluster is dated July 30, 2026.

What is Knaithe associated with?

Across ThreatCluster reporting, Knaithe most frequently co-occurs with KnYuan, MiniMax, T1071 - Application Layer Protocol, Qwen, Telegram, among 11 tracked related entities.

What are the latest developments involving Knaithe?

The most significant recent cluster is “DeepSeek AI Used in Autonomous Cyberattack Campaign by Chinese Threat Actor” (5 articles · Updated August 2, 2026). Knaithe appears across 1 threat cluster in total, listed above with sources.

How much reporting does ThreatCluster have on Knaithe?

Knaithe appears in 1 intelligence report mention across 1 deduplicated threat cluster, aggregated from 17,000+ monitored sources.

CVSS v3.1 Breakdown