Related Threat Clusters
-
Persistent Firestarter Malware Targets Cisco Firepower Devices in US Agencies
A sophisticated backdoor malware named Firestarter has been discovered on Cisco Firepower devices, attributed to the state-sponsored threat actor UAT-4356. The malware exploits two vulnerabilities, CVE-2025-20333 and…
37 articles · Updated April 23, 2026 -
Lazarus Group Escalates Attacks with Fileless RemotePE Trojan Targeting Crypto and Banks
The Lazarus Group, a North Korea-linked cybercrime organization, has intensified its operations against financial and cryptocurrency sectors using a sophisticated fileless Remote Access Trojan (RAT) called RemotePE.…
12 articles · Updated May 25, 2026 -
MuddyWater Targets U.S. Entities Amid Geopolitical Tensions
In early 2026, the Iranian APT group MuddyWater launched cyberattacks against U.S. banking, a major airport, and Israeli operations of a U.S.-based software company. The attacks intensified in March, coinciding with…
16 articles · Updated July 22, 2026 -
Drift Protocol Hack: $285M Stolen Funds Transferred After Months of Dormancy
In April 2026, the Drift Protocol was hacked, leading to a loss of approximately $285 million. The Ethereum wallet known as 'Drift Exploiter 4' began transferring these stolen funds on July 25, 2026, with significant…
2 articles · Updated July 26, 2026 -
Radiant Capital Winding Down After $50M Hack Linked to North Korean Group
Radiant Capital, a decentralized lending protocol, is winding down operations after failing to recover from a $50 million hack attributed to a North Korean state-sponsored group, the Lazarus Group. The exploit occurred…
5 articles · Updated June 1, 2026 -
Circle's USDC Freezing Policy Under Scrutiny After $285M Drift Protocol Exploit
On April 1, 2026, the Drift Protocol on Solana was exploited, resulting in over $270 million in losses, primarily in USDC. North Korean state hackers executed 31 withdrawals in a rapid 12-minute window, leading to a…
19 articles · Updated April 10, 2026 -
Exploitation of Client Software Vulnerabilities and User Execution Techniques
Recent cybersecurity reports detail the exploitation of software vulnerabilities in client applications, particularly targeting web browsers and Microsoft Office. Adversaries utilize techniques such as Drive-by…
2 articles · Updated June 8, 2026 -
Armored Likho Expands Cyber-Espionage with New Rust Toolkit
In May 2026, the Armored Likho group, also known as Eagle Werewolf, launched a cyber-espionage campaign targeting private individuals and organizations in Russia, including corporations, government bodies, and…
2 articles · Updated August 13, 2026 -
Spearphishing Campaigns Exploit Malicious Links for User Execution
Recent reports detail various adversaries utilizing spearphishing tactics to exploit users into clicking malicious links. These links often lead to the execution of malware or the harvesting of sensitive information,…
2 articles · Updated September 2, 2026 -
GrayAlpha Threat Actor Uses MaskBat Loader for NetSupport RAT Deployments
Insikt Group identified GrayAlpha, a threat actor linked to FIN7, utilizing a custom loader named MaskBat to deploy NetSupport RAT through various infection vectors. These include fake browser update pages, fake 7-Zip…
2 articles · Updated August 6, 2026
Recent Intelligence Reports
- 001 — attack.mitre.org · September 2, 2026
- Dead Drop Resolver — attack.mitre.org · August 14, 2026
- T1027 — attack.mitre.org · August 7, 2026
- cryptopolitan.com — www.cryptopolitan.com · July 26, 2026
- 002 — attack.mitre.org · July 23, 2026
- 002 — attack.mitre.org · July 23, 2026
- T1203 · Exploitation for Client Execution — attack.mitre.org · June 8, 2026
- Don't Fear the Repo: UNK_DeadDrop Phishing Campaign Targets Developers to Steal Cryptocurrency — Proofpoint · June 8, 2026