Unc1151 is a apt_group tracked across 6 threat clusters and 10 intelligence report mentions on ThreatCluster. First observed May 14, 2026; most recent activity July 24, 2026.
Russian threat actors TA488 and TA458 are exploiting vulnerabilities in webmail servers, specifically targeting Ukrainian entities and government sectors. TA488 utilizes a half-click exploit via CVE-2025-66376 in Zimbra…
A phishing campaign targeting Ukrainian government organizations has been attributed to the Belarus-aligned Ghostwriter group, also known as UAC-0057. The campaign involves sending emails with PDF attachments that lead…
On May 29, 2026, Yury Hubarevich, a prominent Belarusian politician, was targeted in a phishing attack linked to the Belarusian espionage group UNC1151. The attack involved an email disguised as a Google notification,…
A suspected China-aligned threat group, tracked as UNK_MassTraction, has been exploiting vulnerabilities in Roundcube mail servers at U.S. and Canadian universities since May 2026. The campaign targets physics and…
The Belarus-aligned cyber group FrostyNeighbor has launched a targeted campaign against government organizations in Ukraine and Poland since March 2026. Utilizing spearphishing techniques, the group delivers malicious…
Mandiant Threat Intelligence has assessed with high confidence that UNC1151 is linked to the Belarusian government, conducting cyber operations primarily targeting Ukraine, Lithuania, Latvia, Poland, and Germany. The…