Related Threat Clusters
-
Exploitation of WinRAR CVE-2025-8088 Threatens Ukrainian Organizations
Two Russia-aligned cyber campaigns are exploiting the WinRAR vulnerability CVE-2025-8088 against Ukrainian targets nearly a year after it was patched. The flaw, a path traversal vulnerability, allows attackers to write…
19 articles · Updated June 8, 2026 -
Exploitation of WinRAR Path Traversal Flaw Continues Amid CISA Warning
The CVE-2025-8088 vulnerability in WinRAR is being exploited by various threat actors for initial access and to deploy malware. The flaw allows attackers to use Alternate Data Streams to write malicious files to…
12 articles · Updated January 27, 2026 -
SHADOW-VOID-042 Spear-Phishing Campaign Targets Multiple Industries
In November 2025, a spear-phishing campaign utilizing Trend Micro-themed lures targeted various sectors, including energy, defense, pharmaceuticals, and cybersecurity. The campaign was detected and mitigated by the…
2 articles · Updated December 12, 2025 -
Russian-linked Threat Actors Deploy SocGholish Malware via Fake Browser Updates
Cybersecurity researchers at Arctic Wolf Labs have identified a cyberattack campaign utilizing fake browser update notifications to distribute SocGholish malware. This campaign is linked to Russian threat actors and…
12 articles · Updated November 26, 2025 -
Russian Cyber Groups Target US Engineering Firm with Advanced Attacks
A series of cyberattacks targeting a US engineering firm has been attributed to Russian cyber groups. The attackers utilized SocGholish and RomCom tools, which are commonly associated with cybercrime, to obscure their…
1 article · Updated November 28, 2025 -
Russian Hackers Target US Engineering Firm Linked to Ukraine
A U.S.-based civil engineering firm was attacked by the Russia-aligned threat group RomCom, which utilized SocGholish malware in a September attack. The attack is believed to be connected to the firm's work for a U.S.…
5 articles · Updated November 25, 2025
Recent Intelligence Reports
- ESET researchers themselves discovered — www.welivesecurity.com · June 30, 2026
- Old WinRAR Flaw Fuels Attacks on Ukraine: How Unmanaged Software Keeps the Door Open — Trendmicro · June 9, 2026
- WinRAR path traversal flaw still exploited by numerous hackers — Bleepingcomputer · January 27, 2026
- SHADOW-VOID-042 Targets Multiple Industries with Void Rabisu-like Tactics — Trendmicro · December 12, 2025
- Cyberattacks Against the US Intensify as Russian Groups Target Engineering Firm — Thecyberexpress · November 28, 2025
- Russian RomCom Uses SocGholish to Deploy Malware on Ukraine Supporters — Technadu · November 27, 2025
- Russia — Cybersecuritydive · November 25, 2025
- Russian hackers target US engineering firm because of work done for Ukraine — Abcnews.Go · November 25, 2025