Related Threat Clusters
-
Russian Hackers Exploit Zimbra Zero-Day for Espionage Campaign
Since July 2025, Russian state-backed hackers, known as Laundry Bear, have exploited a zero-click vulnerability (CVE-2025-66376) in the Zimbra Collaboration Suite to infiltrate Western government and commercial…
82 articles · Updated July 23, 2026 -
APT28 Exploits Vulnerable Routers for Global DNS Hijacking Campaign
Russian cyber group APT28, also known as Fancy Bear, has been exploiting vulnerabilities in TP-Link and MikroTik routers to conduct large-scale DNS hijacking operations. This campaign, which has affected over 18,000…
100 articles · Updated April 7, 2026 -
APT28 Exploits Roundcube Vulnerabilities in Targeted Cyber Espionage Campaign
APT28 (Fancy Bear) has been linked to Operation Roundish, utilizing a comprehensive Roundcube exploitation toolkit against Ukrainian government targets. The toolkit, discovered in January 2026, includes XSS payloads, a…
3 articles · Updated July 23, 2026 -
China-aligned APT Groups Target Global Maritime and Tech Sectors Amid Geopolitical Tensions
ESET's latest APT Activity Report reveals that from October 2025 to March 2026, China-aligned threat actors engaged in extensive espionage campaigns, particularly in Venezuela and the Gulf region. Following U.S.…
6 articles · Updated May 28, 2026 -
APT28 Revives Advanced Malware Toolkit for Cyber-Espionage
APT28, a Russian threat actor, has reactivated its malware development team and deployed a modern espionage toolkit that includes a customized version of the Covenant open-source tool. This resurgence indicates a…
10 articles · Updated March 10, 2026 -
APT28's Operation MacroMaze: Macro Malware Campaign Targets Europe
APT28, a Russia-linked advanced persistent threat group, conducted a cyberespionage campaign named Operation MacroMaze from September 2025 to January 2026. The campaign involved deploying macro malware embedded in…
3 articles · Updated February 24, 2026 -
Sednit Group Resurfaces with SlimAgent Keylogger in Ukraine
ESET researchers have identified the resurgence of the Sednit group, a notorious Russian cybercriminal organization, linked to the deployment of a keylogger named SlimAgent in Ukraine. This activity is traced back to a…
4 articles · Updated March 10, 2026 -
Cyberattacks Target Ukraine and EU via Microsoft Office Vulnerability
CERT-UA has reported a new wave of cyberattacks targeting Ukrainian government agencies and EU organizations, exploiting the Microsoft Office vulnerability CVE-2026-21509. Attackers are using malicious emails disguised…
59 articles · Updated February 2, 2026 -
Benchmarking Cyber Threat Intelligence Services: Key Findings
A hands-on benchmark of five cyber threat intelligence services was conducted, evaluating them against 33 criteria across eight categories. The evaluation utilized historical indicators of compromise (IOCs), six threat…
4 articles · Updated August 12, 2026
Recent Intelligence Reports
- Top 5 Cyber Threat Intelligence Services Benchmarked — Aimultiple · August 12, 2026
- Top 5 Cyber Threat Intelligence Services Benchmarked — Aimultiple · August 12, 2026
- Operation Roundpress — www.welivesecurity.com · July 24, 2026
- Operation Roundish — hunt.io · July 24, 2026
- ESET Research APT Report: China-aligned groups spy in Venezuela and the Gulf, target AI ... — Markets.Businessinsider · May 28, 2026
- ESET APT Activity Report Q4 2025–Q1 2026 — Welivesecurity · May 28, 2026
- FBI Takes Down APT28 Network Behind Global DNS Hijacking Attacks — Thecyberexpress · April 8, 2026
- Russian Threat Actor Sednit Resurfaces With Sophisticated Toolkit — Darkreading · March 10, 2026