Related Threat Clusters
-
Persistent Firestarter Malware Targets Cisco Firepower Devices in US Agencies
A sophisticated backdoor malware named Firestarter has been discovered on Cisco Firepower devices, attributed to the state-sponsored threat actor UAT-4356. The malware exploits two vulnerabilities, CVE-2025-20333 and…
37 articles · Updated April 23, 2026 -
MuddyWater Targets U.S. Entities Amid Geopolitical Tensions
In early 2026, the Iranian APT group MuddyWater launched cyberattacks against U.S. banking, a major airport, and Israeli operations of a U.S.-based software company. The attacks intensified in March, coinciding with…
16 articles · Updated July 22, 2026 -
Russian GRU Hackers Use Fake CAPTCHAs to Compromise Ukrainian Users
Ukraine's CERT-UA reported that the Russian GRU-linked hacking group Sandworm is employing fake CAPTCHA prompts to trick users into executing malicious PowerShell commands on their devices. This method, known as…
2 articles · Updated July 21, 2026 -
Widespread Abuse of ScreenConnect to Deploy AsyncRAT via Fake Installers
A significant cybersecurity campaign has emerged, exploiting the legitimate remote access tool ScreenConnect to deploy AsyncRAT malware. Attackers utilized spoofed websites and typosquatted domains, masquerading as…
7 articles · Updated July 1, 2026 -
New Remcos RAT Campaign Exploits CVE-2017-11882 via Phishing
A new phishing campaign distributing a variant of the Remcos RAT has been identified, targeting Microsoft Windows users. The attack utilizes a fake shipping document to deliver a malicious Word file that exploits…
2 articles · Updated May 29, 2026 -
New Agent Tesla Malware Variant Uses Emojis for Evasion in BEC Campaign
A new variant of the Agent Tesla malware, identified as version 4, employs Unicode emoji characters to obfuscate its JScript dropper in a business email compromise (BEC) campaign targeting finance departments. The…
7 articles · Updated August 21, 2026 -
Cruciferra Crypter Service Powers Multiple Cybercrime Campaigns
Proofpoint has identified a sophisticated crypter service named Cruciferra, first sold in autumn 2025, that is utilized by various cybercriminal groups to cloak malware. The service employs advanced techniques such as…
8 articles · Updated July 20, 2026 -
Global Phishing Campaign Uses Lua Loader Disguised as TrueType Font Files
Since late March 2026, a large-scale phishing campaign has been observed utilizing disguised TrueType Font (.ttf) files to deliver Lua-based loaders and various malware, including Agent Tesla and Remcos. The attackers…
5 articles · Updated July 16, 2026 -
GrayAlpha Threat Actor Uses MaskBat Loader for NetSupport RAT Deployments
Insikt Group identified GrayAlpha, a threat actor linked to FIN7, utilizing a custom loader named MaskBat to deploy NetSupport RAT through various infection vectors. These include fake browser update pages, fake 7-Zip…
2 articles · Updated August 6, 2026 -
ClickFix Attack Wave Targets Windows Users with StealC Malware
A new social engineering campaign named ClickFix is targeting Windows users by presenting fake CAPTCHA verification pages. Victims are led to compromised websites that display fraudulent Cloudflare security checks,…
218 articles · Updated February 13, 2026
Recent Intelligence Reports
- New Agent Tesla malware version uses emoji obfuscation to evade detection — Scworld · August 21, 2026
- Hackers Hide Agent Tesla Malware Behind Emojis to Steal Browser and Email Passwords — Ground.News · August 21, 2026
- Hackers Hide Agent Tesla JScript Behind Unicode Emojis to Evade Detection — Cybersecuritynews · August 21, 2026
- New Agent Tesla Malware Variant Boosts Evasion Capabilities — Infosecurity-Magazine · August 21, 2026
- Hackers Hide Agent Tesla Malware Behind Emojis to Steal Browser and Email Passwords — Gbhackers · August 21, 2026
- T1027 — attack.mitre.org · August 7, 2026
- 003 — attack.mitre.org · July 23, 2026
- 002 — attack.mitre.org · July 23, 2026