Related Threat Clusters
-
OceanLotus Shifts Focus to Domestic Espionage with SPECTRALVIPER Attacks
From mid-2024 to early 2026, the Vietnam-aligned APT group OceanLotus has intensified its focus on domestic espionage, utilizing the SPECTRALVIPER backdoor in two major campaigns. The first campaign targeted a…
17 articles · Updated June 11, 2026 -
Tropic Trooper Expands Tactics with Multi-Stage Attacks on Japanese and Taiwanese Targets
On March 12, 2026, Zscaler ThreatLabz reported a campaign by the Tropic Trooper APT targeting Chinese-speaking individuals in Taiwan, Japan, and South Korea. The attack involved a malicious ZIP archive containing…
5 articles · Updated April 24, 2026 -
Exploitation of Client Software Vulnerabilities and User Execution Techniques
Recent cybersecurity reports detail the exploitation of software vulnerabilities in client applications, particularly targeting web browsers and Microsoft Office. Adversaries utilize techniques such as Drive-by…
2 articles · Updated June 8, 2026 -
New Remcos RAT Campaign Exploits CVE-2017-11882 via Phishing
A new phishing campaign distributing a variant of the Remcos RAT has been identified, targeting Microsoft Windows users. The attack utilizes a fake shipping document to deliver a malicious Word file that exploits…
2 articles · Updated May 29, 2026 -
GopherWhisper APT Targets Mongolia Using Cloud Tools for Espionage
The Chinese APT group known as GopherWhisper has been identified as targeting the Mongolian government using multiple cloud-based tools for espionage. Active since November 2023, the group has backdoored at least 12…
8 articles · Updated April 24, 2026 -
New Malware Campaign Targets Manufacturing and Government Sectors
A sophisticated malware attack campaign has targeted manufacturing and government organizations in Europe and the Middle East, particularly in Italy, Finland, and Saudi Arabia. The campaign employs obfuscation…
4 articles · Updated December 22, 2025 -
Malware Campaign Utilizes Reused JPEG for Payload Delivery
A malware campaign has been identified that exploits Microsoft Equation Editor (CVE-2017-11882) to deliver a malicious payload embedded in a JPEG image. The campaign uses a specific attachment named…
2 articles · Updated February 19, 2026 -
Bactor Ransomware Identified in Cybersecurity Monitoring
CYFIRMA Research and Advisory Team has identified Bactor Ransomware while monitoring underground forums. This ransomware targets Windows systems and affects multiple industries and technologies. The findings are part of…
5 articles · Updated November 20, 2025 -
Emergence of New Ransomware Variants: Bactor, ChickenKiller, and Midnight
Multiple ransomware strains, including Bactor, ChickenKiller, and Midnight, have been identified by CYFIRMA Research and Norton. Bactor and ChickenKiller ransomware target Windows systems, while Midnight ransomware has…
7 articles · Updated November 27, 2025
Recent Intelligence Reports
- G0050 — attack.mitre.org · June 11, 2026
- T1203 · Exploitation for Client Execution — attack.mitre.org · June 8, 2026
- New Remcos Campaign Distributed Through Fake Shipping Document — www.fortinet.com · May 29, 2026
- G0081 — attack.mitre.org · April 24, 2026
- 86083 — securelist.com · April 24, 2026
- Tracking Malware Campaigns With Reused Material — Socprime · February 19, 2026
- Tracking Malware Campaigns With Reused Material, (Wed, Feb 18th) — Isc.Sans.Edu · February 18, 2026
- New malware attack campaign involves widely used sophisticated loader — Scworld · December 22, 2025