Related Threat Clusters
-
Sandworm Launches Wiper Malware Campaign Against Ukrainian Organizations
The Russian state-backed hacking group Sandworm has intensified its operations against Ukrainian organizations by deploying data-wiping malware. This campaign targets critical sectors, including the grain industry, and…
6 articles · Updated November 7, 2025 -
Russian FSB Exploits Vulnerable Routers to Target Critical Infrastructure
A joint advisory from 21 global cybersecurity agencies warns that Russian state hackers from the FSB's Center 16 are exploiting poorly configured routers to infiltrate critical infrastructure networks worldwide. The…
76 articles · Updated July 13, 2026 -
Exploitation of WinRAR CVE-2025-8088 Threatens Ukrainian Organizations
Two Russia-aligned cyber campaigns are exploiting the WinRAR vulnerability CVE-2025-8088 against Ukrainian targets nearly a year after it was patched. The flaw, a path traversal vulnerability, allows attackers to write…
19 articles · Updated June 8, 2026 -
Gamaredon APT Escalates Cyber Operations Against Ukraine in 2025
The Gamaredon group, a Russian-aligned APT, has significantly upgraded its cyber capabilities in 2025, focusing on spear-phishing campaigns against Ukrainian targets. ESET Research reports that Gamaredon conducted 35…
7 articles · Updated June 25, 2026 -
EU Sanctions Russia Over Ongoing Cyber Espionage Campaign
The European Union has condemned and sanctioned Russia for a prolonged cyber espionage campaign targeting its member states. The campaign, orchestrated by the 16th Centre of the FSB, has involved infiltrating government…
172 articles · Updated July 13, 2026 -
MuddyWater Targets U.S. Entities Amid Geopolitical Tensions
In early 2026, the Iranian APT group MuddyWater launched cyberattacks against U.S. banking, a major airport, and Israeli operations of a U.S.-based software company. The attacks intensified in March, coinciding with…
16 articles · Updated July 22, 2026 -
OceanLotus Shifts Focus to Domestic Espionage with SPECTRALVIPER Attacks
From mid-2024 to early 2026, the Vietnam-aligned APT group OceanLotus has intensified its focus on domestic espionage, utilizing the SPECTRALVIPER backdoor in two major campaigns. The first campaign targeted a…
17 articles · Updated June 11, 2026 -
China-aligned APT Groups Target Global Maritime and Tech Sectors Amid Geopolitical Tensions
ESET's latest APT Activity Report reveals that from October 2025 to March 2026, China-aligned threat actors engaged in extensive espionage campaigns, particularly in Venezuela and the Gulf region. Following U.S.…
6 articles · Updated May 28, 2026 -
France Attributes Cyber Espionage to Russian FSB's Turla Group
On July 13, 2026, France officially attributed a series of cyber intrusions targeting its government and defense sectors to the Turla intrusion set, linked to Russia's FSB 16th Center. The attacks, ongoing since the…
3 articles · Updated July 13, 2026 -
New Russian STOCKSTAY Spyware Targets Ukrainian Military
Google Threat Intelligence has identified a new spyware named STOCKSTAY, developed by the Russian hacking group Turla, aimed at Ukrainian military and government entities. This Windows backdoor is designed for cyber…
9 articles · Updated June 26, 2026
Recent Intelligence Reports
- Threat Intelligence — www.eset.com · August 27, 2026
- T1189 — attack.mitre.org · August 7, 2026
- France’s ANSSI — cyber.gouv.fr · August 5, 2026
- T1102 — attack.mitre.org · July 23, 2026
- 4145474 Francia Viklikala Predstavnika Posolstva Rf Cerez Kiberataki — www.ukrinform.ua · July 18, 2026
- France summons Russian embassy representative over cyberattacks — Ukrinform · July 18, 2026
- France summons Russian chargé over FSB — Mezha · July 18, 2026
- UK urges households to stockpile food over fears of Russian cyberattacks - RBC — Newsukraine.Rbc.Ua · July 15, 2026