Related Threat Clusters
-
Mirage Kitten Targets Aviation and FinTech with New Cross-Platform Malware
The Iranian cyberespionage group Mirage Kitten has launched a campaign targeting technology professionals in the aviation and FinTech sectors across the Middle East and Africa. This operation involves the use of two…
6 articles · Updated September 1, 2026 -
Armored Likho APT Targets Power Grids with BusySnake Stealer Malware
A newly identified APT group, Armored Likho, is conducting a phishing campaign targeting government agencies and electric power sectors in Russia, Brazil, and Kazakhstan. The group employs a sophisticated infostealer…
7 articles · Updated July 4, 2026 -
Tortoiseshell Expands Malware Arsenal with New Backdoor and SSH Tunneling Tool
The Iranian-linked Tortoiseshell APT group has expanded its malware toolkit, introducing a new backdoor and reverse SSH tunneling utility. Group-IB Threat Intelligence identified these developments following a report by…
6 articles · Updated August 26, 2026 -
Operation Double Barrel: State-Sponsored Exploitation of Korean Financial Software
From 2025 to mid-2026, a state-sponsored threat group exploited vulnerabilities in Korean financial security software, utilizing watering hole attacks and spear phishing to deploy backdoors named Struggle and Brandoor.…
7 articles · Updated July 30, 2026 -
Mirage Kitten Malware Targets Middle East and Africa with New Toolset
The Mirage Kitten APT group has deployed a sophisticated malware suite, including the NightLedger backdoor, across the Middle East and Africa. This campaign has successfully infiltrated sensitive sectors such as…
2 articles · Updated July 30, 2026 -
CAV3RN Framework Upgrades to Outlook Calendar for C2 Communication
The Project CAV3RN cyberespionage framework has evolved with the introduction of a new communication module, AzureCommunication.dll, which replaces the previous HTTP/WebSocket component. This module utilizes Outlook…
2 articles · Updated July 21, 2026 -
Project CAV3RN Enhances Espionage Tactics Using Google Apps Script and DNS
Project CAV3RN is a modular cyberespionage framework targeting organizations in Israel. Recent developments reveal its use of a sophisticated command-and-control (C2) design that dynamically combines direct HTTPS…
3 articles · Updated August 12, 2026 -
StrikeShark Campaign Unleashes SharkLoader Malware to Deploy Cobalt Strike
A new malware family named SharkLoader has been discovered, linked to a campaign called StrikeShark, which targets various sectors, including a diplomatic organization in Indonesia. SharkLoader acts as a loader to…
14 articles · Updated June 25, 2026 -
Toy Ghouls Launch GenieLocker Ransomware Targeting Russian Manufacturing
The Toy Ghouls group, also known as Bearlyfy, has introduced a new ransomware called GenieLocker, active since March 2026. This ransomware targets Windows, Linux, and VMware ESXi systems, primarily affecting the…
5 articles · Updated July 30, 2026 -
Kaspersky and AFRIPOL Enhance Cybersecurity Training for African Law Enforcement
Kaspersky, in collaboration with AFRIPOL, conducted cybersecurity training for law enforcement from 23 African countries from November 2025 to March 2026. Approximately 40 officers participated in the 'Security…
95 articles · Updated March 25, 2026
Recent Intelligence Reports
- Mirage Kitten targeting aviation and FinTech sectors across the Middle East and Africa with a new malware set — Securelist · September 1, 2026
- Securelist — securelist.com · August 26, 2026
- Project CAV3RN continues: Google Apps Script as C2 relay and DNS — Securelist · August 11, 2026
- Kaspersky's Global Research and Analysis Team — securelist.com · July 30, 2026
- Toy Ghouls’ new toy: the GenieLocker ransomware — Securelist · July 30, 2026
- Mirage Kitten targets Middle East and Africa region with new malware — Securelist · July 28, 2026
- New Project CAV3RN module abuses Outlook calendar events for C2 and DNS AAAA records for configuration recovery — Securelist · July 21, 2026
- Armored Likho digging a snake pit: inside the covert BusySnake Stealer campaign — Securelist · July 3, 2026