Related Threat Clusters
-
MuddyWater Targets U.S. Entities Amid Geopolitical Tensions
In early 2026, the Iranian APT group MuddyWater launched cyberattacks against U.S. banking, a major airport, and Israeli operations of a U.S.-based software company. The attacks intensified in March, coinciding with…
16 articles · Updated July 22, 2026 -
FamousSparrow APT Expands Targeting to Azerbaijani Energy Sector
FamousSparrow, a China-aligned APT group, launched a multi-wave cyberespionage campaign against an Azerbaijani oil and gas company from late December 2025 to February 2026. The attackers employed an evolved DLL…
10 articles · Updated May 13, 2026 -
China-nexus Threat Actor Deploys PlugX in Persian Gulf Amid Middle East Conflict
On March 1, 2026, a China-nexus threat actor launched a cyber campaign targeting countries in the Persian Gulf region, coinciding with renewed conflict in the Middle East. The attack utilized social engineering tactics,…
2 articles · Updated March 12, 2026 -
QuickFox VPN Supply Chain Attack Delivers FDMTP Backdoor to Windows Users
A supply chain attack targeting the QuickFox VPN application has been uncovered, affecting Windows users. The attack, attributed to the Chinese state-sponsored group Mustang Panda, involved a trojanized version of the…
14 articles · Updated August 6, 2026 -
TA416 Resumes Cyber Espionage Against European Governments Amid Geopolitical Tensions
Chinese state-backed group TA416 has reemerged with intensified cyber espionage campaigns targeting European governments, following a quiet period since 2023. Proofpoint reported that the group's renewed activity began…
9 articles · Updated April 1, 2026 -
HoneyMyte APT Upgrades CoolClient Backdoor with Kernel Driver for Enhanced Stealth
The HoneyMyte APT group has deployed an upgraded variant of the CoolClient backdoor in cyber-espionage campaigns targeting organizations in Myanmar, Mongolia, Pakistan, India, and Russia. This new variant introduces a…
10 articles · Updated August 14, 2026 -
Chinese APT Campaign Targets Asia-Pacific with FDMTP Backdoor
A months-long espionage campaign linked to the Chinese group Mustang Panda has been identified, utilizing an updated variant of the FDMTP backdoor. This campaign, tracked by Darktrace, began in late September 2025 and…
3 articles · Updated May 14, 2026 -
Mustang Panda Launches PlugX RAT Campaign via Fake Browser Update
Mustang Panda, a Chinese state-sponsored threat group, has initiated a cyberattack campaign deploying the PlugX remote access tool (RAT). The attack utilizes a fake browser updater to trick users into downloading a…
2 articles · Updated June 2, 2026 -
Chinese Hackers Leverage DeepSeek AI for Increased Cyberattacks
Chinese state-affiliated hacking groups have significantly increased their cyberattack volume by integrating DeepSeek and other open-source AI models into their operations. According to TeamT5, a Taiwanese cybersecurity…
9 articles · Updated August 25, 2026 -
Malaysia's Cyber Threat Landscape Faces Significant Transformation Amid Digital Expansion
Malaysia's cyber threat landscape is experiencing a structural shift due to rapid digital growth and geopolitical factors, making it a prime target for cyber attacks. A report from Cyfirma indicates that state-backed…
2 articles · Updated April 8, 2026
Recent Intelligence Reports
- China Hacked NASA, Federal Reserve: FBI Seizes Platforms Behind Eight — Techtimes · August 27, 2026
- Justice Department and FBI Seize Platforms Operated and Used by China State — Justice · August 26, 2026
- DeepSeek, ChatGPT and Claude: How Chinese hackers are using AI in cyberattacks — Firstpost · August 25, 2026
- China's hackers use DeepSeek for attacks, researchers say — Straitstimes · August 25, 2026
- Deepseek 'AI of choice' for hackers, who use it to boost attacks, say researchers — Businesstimes.Sg · August 25, 2026
- Risky Bulletin: The EU publishes its upcoming cybersecurity standards — News.Risky.Biz · August 17, 2026
- Earth Preta Updated Stealthy Strategies — www.trendmicro.com · August 15, 2026
- Family Tree Dll Sideloading Cases May Be Related — www.sophos.com · August 15, 2026