Related Threat Clusters
-
MuddyWater Targets U.S. Entities Amid Geopolitical Tensions
In early 2026, the Iranian APT group MuddyWater launched cyberattacks against U.S. banking, a major airport, and Israeli operations of a U.S.-based software company. The attacks intensified in March, coinciding with…
16 articles · Updated July 22, 2026 -
China-aligned APT Groups Target Global Maritime and Tech Sectors Amid Geopolitical Tensions
ESET's latest APT Activity Report reveals that from October 2025 to March 2026, China-aligned threat actors engaged in extensive espionage campaigns, particularly in Venezuela and the Gulf region. Following U.S.…
6 articles · Updated May 28, 2026 -
North Korean Konni Group Uses KakaoTalk for Malware Distribution in Spear-Phishing Campaign
North Korea-linked hackers from the Konni group executed a spear-phishing campaign utilizing the KakaoTalk messaging platform to distribute malware and steal sensitive information. The campaign involved sending emails…
9 articles · Updated March 16, 2026 -
Cyber Adversaries Exploit File Enumeration and Data Collection Techniques
Recent reports detail the tactics employed by various cyber adversaries to enumerate files and directories on compromised systems. Adversaries utilize command shell utilities and custom tools to gather sensitive…
2 articles · Updated April 22, 2026 -
North Korean Hackers Launch Destructive Cyberattack on Smartphones and PCs
A North Korea-linked hacking group has executed a new cyberattack capable of remotely controlling Android smartphones and PCs, leading to data deletion and malware distribution. The attack, attributed to groups Kimsuky…
13 articles · Updated November 10, 2025 -
Microsoft Mitigates Windows LNK Vulnerability Exploited in Zero-Day Attacks
Microsoft has mitigated a high-severity Windows LNK vulnerability, tracked as CVE-2025-9491, which has been exploited by state-backed and cybercrime groups in zero-day attacks. This flaw allows attackers to hide…
3 articles · Updated December 3, 2025 -
Five Plead Guilty in North Korean IT Worker Fraud Scheme
Five individuals have pleaded guilty to facilitating North Korean operatives in obtaining remote IT jobs at U.S. companies by using false and stolen identities. The U.S. Department of Justice has also seized $15 million…
39 articles · Updated November 17, 2025 -
Konni Hackers Target Blockchain Engineers with AI Malware
The North Korean hacker group Konni is utilizing AI-generated PowerShell malware to target developers and engineers in the blockchain sector. This campaign is linked to APT37 and Kimsuky activity clusters, with Konni…
9 articles · Updated January 24, 2026 -
North Korea's Konni APT Targets Android and Windows Users in September 2025
In September 2025, the North Korea-linked APT group Konni, also known as Kimsuky, targeted users by posing as counselors to steal data and wipe Android phones using Google Find Hub. The attacks also affected Windows…
3 articles · Updated December 3, 2025 -
FBI Alerts on Kimsuky Hackers Using QR Codes for Phishing Attacks
The FBI has issued a warning about the North Korean hacker group Kimsuky employing malicious QR codes in spear-phishing campaigns targeting U.S. organizations. The attacks focus on entities involved in North…
17 articles · Updated January 9, 2026
Recent Intelligence Reports
- 001 — attack.mitre.org · July 23, 2026
- ESET APT Activity Report Q4 2025–Q1 2026 — Welivesecurity · May 28, 2026
- T1005 — attack.mitre.org · April 22, 2026
- North Korea-Linked 'Konni' Hacker Group Spreads Malware via Spear — M.Alphabiz.Co.Kr · March 17, 2026
- Pyongyang-Sponsored Hacking Group Uses KakaoTalk in Malware Distribution Campaign: Report — Ground.News · March 16, 2026
- North Korea hackers used KakaoTalk in spear-phishing campaign, report says — Upi · March 16, 2026
- Konni Hijacks KakaoTalk Accounts in Spear — Gbhackers · March 16, 2026
- Pyongyang-sponsored hacking group uses KakaoTalk in malware distribution campaign: report — Koreatimes.Co.Kr · March 16, 2026