Related Threat Clusters
-
MuddyWater Targets U.S. Entities Amid Geopolitical Tensions
In early 2026, the Iranian APT group MuddyWater launched cyberattacks against U.S. banking, a major airport, and Israeli operations of a U.S.-based software company. The attacks intensified in March, coinciding with…
16 articles · Updated July 22, 2026 -
PATCHCORD Malware Targets Afghan Telecom and South Asian Infrastructure
Acronis Threat Research Unit has identified a new malware campaign named PATCHCORD, targeting Afghan telecom providers and critical infrastructure in South Asia. The malware, a custom backdoor written in C/C++, is…
10 articles · Updated August 13, 2026 -
SideCopy Targets Afghanistan Finance Ministry with XenoRAT Campaign
A Pakistan-linked threat actor, SideCopy, has initiated a spear-phishing campaign against Afghanistan's Ministry of Finance, targeting all 34 provincial revenue directorates. The campaign utilizes a ZIP archive…
5 articles · Updated May 30, 2026 -
Bitdefender Alerts on APT36's New AI 'Vibeware' Targeting India
Bitdefender has reported a new AI-driven attack model termed 'vibeware', which generates numerous disposable malware variants. This tactic is linked to APT36 (Transparent Tribe), a Pakistan-aligned threat actor that has…
8 articles · Updated March 6, 2026 -
Exploitation of Client Software Vulnerabilities and User Execution Techniques
Recent cybersecurity reports detail the exploitation of software vulnerabilities in client applications, particularly targeting web browsers and Microsoft Office. Adversaries utilize techniques such as Drive-by…
2 articles · Updated June 8, 2026 -
Operation TrustTrap Uncovers 16,800 Fake Domains Targeting User Data
Cyble Research and Intelligence Labs (CRIL) has identified Operation TrustTrap, a significant domain spoofing campaign involving over 16,800 fraudulent domains that mimic legitimate U.S. government portals, particularly…
2 articles · Updated April 29, 2026 -
GrayAlpha Threat Actor Uses MaskBat Loader for NetSupport RAT Deployments
Insikt Group identified GrayAlpha, a threat actor linked to FIN7, utilizing a custom loader named MaskBat to deploy NetSupport RAT through various infection vectors. These include fake browser update pages, fake 7-Zip…
2 articles · Updated August 6, 2026 -
Critical Vulnerabilities Discovered in Mozilla Products
Multiple vulnerabilities have been identified in Mozilla products, with the most severe allowing for arbitrary code execution. Exploitation could enable attackers to install programs, access, modify, or delete data, and…
44 articles · Updated April 8, 2026 -
APT36 Campaign Uses LNK Files for Cyberespionage Against Indian Targets
APT36, also known as Transparent Tribe, conducted a spear-phishing campaign targeting Indian government, strategic, and academic organizations. The campaign involved delivering malicious LNK files disguised as PDFs,…
2 articles · Updated January 5, 2026 -
APT36 Malware Campaign Targets Indian Government via Windows LNK Files
APT36, also known as Transparent Tribe, has initiated a malware campaign targeting Indian government entities by exploiting Windows LNK shortcut files. The campaign begins with spear-phishing emails containing a ZIP…
4 articles · Updated December 31, 2025
Recent Intelligence Reports
- Bitdefender — www.bitdefender.com · August 13, 2026
- PATCHCORD: New malware cluster targets Afghan telecom and South Asian critical infrastructure — Acronis · August 13, 2026
- PATCHCORD: New malware cluster targets Afghan telecom and South Asian critical infrastructure — Acronis · August 13, 2026
- T1189 — attack.mitre.org · August 7, 2026
- 002 — attack.mitre.org · July 23, 2026
- T1203 · Exploitation for Client Execution — attack.mitre.org · June 8, 2026
- SideCopy Deploys Persistent XenoRAT Against Afghanistan Finance Ministry — Gbhackers · May 30, 2026
- SideCopy Deploys Persistent XenoRAT Against Afghanistan Finance Ministry — Gbhackers · May 30, 2026