Related Threat Clusters
-
Russian GRU Hackers Use Fake CAPTCHAs to Compromise Ukrainian Users
Ukraine's CERT-UA reported that the Russian GRU-linked hacking group Sandworm is employing fake CAPTCHA prompts to trick users into executing malicious PowerShell commands on their devices. This method, known as…
2 articles · Updated July 21, 2026 -
Sandworm Hackers Use Fake Job Interviews to Deploy Trojanized VPN Client
The Russian threat group Sandworm has been targeting IT professionals through a social engineering campaign since May 2026. The campaign, attributed to the UAC-0145 subgroup, involves impersonating IT companies and…
7 articles · Updated August 11, 2026 -
Sandworm Targets Critical Infrastructure with Aggressive OT Attacks
The Russian state-sponsored group Sandworm has intensified its cyber operations against industrial and critical infrastructure, utilizing pre-compromised operational technology (OT) environments instead of zero-day…
5 articles · Updated May 14, 2026 -
AWS Attributes Cyber Espionage to Russian GRU-linked Group Sandworm
Amazon Web Services (AWS) has linked a multi-year cyber espionage campaign targeting Western critical infrastructure, particularly in the energy sector, to the Russian GRU-affiliated group Sandworm (APT44). The campaign…
4 articles · Updated December 16, 2025 -
APT36's Ongoing Espionage Campaign Against Indian Government
APT36, also known as Transparent Tribe, has been conducting persistent cyber espionage campaigns against the Indian government and defense organizations for over a decade. This espionage ecosystem, which includes the…
2 articles · Updated February 10, 2026
Recent Intelligence Reports
- Fake Corporate VPN Test Creates Scheduled Task and Downloads Malware on Windows — Gbhackers · August 12, 2026
- Russia's GRU Hackers Target Ukraine With Fake CAPTCHAs and an Unkillable Blockchain Server — Techtimes · July 21, 2026
- Sandworm Activity In Industrial Environments What The Data Reveals — www.nozominetworks.com · May 14, 2026
- Sandworm uses pre-compromised OT environments instead of zero — Industrialcyber.Co · May 14, 2026
- Espionage Without Noise: Understanding APT36's Enduring Campaigns — Securitybrief · February 11, 2026
- Amazon Threat Intelligence identifies Russian cyber threat group targeting Western critical infrastructure — Aws.Amazon · December 15, 2025