Related Threat Clusters
-
Operation Endgame Disrupts Evil Corp's SocGholish Malware Network
On June 18, 2026, international law enforcement agencies launched Operation Endgame, disrupting the SocGholish malware infrastructure linked to the Russian cybercrime group Evil Corp. The operation resulted in the…
67 articles · Updated June 18, 2026 -
Exploitation of WinRAR CVE-2025-8088 Threatens Ukrainian Organizations
Two Russia-aligned cyber campaigns are exploiting the WinRAR vulnerability CVE-2025-8088 against Ukrainian targets nearly a year after it was patched. The flaw, a path traversal vulnerability, allows attackers to write…
19 articles · Updated June 8, 2026 -
Kimsuky Expands AI Capabilities for Cyberattacks
The North Korean hacking group Kimsuky has developed local AI tools to enhance its cyberattack capabilities, as reported by Genians Security Center on August 10, 2026. The group is utilizing large language models (LLMs)…
49 articles · Updated August 10, 2026 -
MuddyWater Targets U.S. Entities Amid Geopolitical Tensions
In early 2026, the Iranian APT group MuddyWater launched cyberattacks against U.S. banking, a major airport, and Israeli operations of a U.S.-based software company. The attacks intensified in March, coinciding with…
16 articles · Updated July 22, 2026 -
Critical Vulnerabilities in ConnectWise ScreenConnect Exploited in Active Attacks
ConnectWise ScreenConnect has been compromised by two critical vulnerabilities, CVE-2024-1708 and CVE-2024-1709, which allow attackers to bypass authentication and execute remote code. The vulnerabilities were disclosed…
9 articles · Updated April 29, 2026 -
SideCopy Targets Afghanistan Finance Ministry with XenoRAT Campaign
A Pakistan-linked threat actor, SideCopy, has initiated a spear-phishing campaign against Afghanistan's Ministry of Finance, targeting all 34 provincial revenue directorates. The campaign utilizes a ZIP archive…
5 articles · Updated May 30, 2026 -
Cybercriminals Exploit BNB Chain for Malware via Fake CAPTCHAs
Microsoft Threat Intelligence has reported a new malware campaign utilizing the BNB Smart Chain, employing a technique called EtherHiding. This method allows hackers to store malicious code within blockchain smart…
12 articles · Updated August 7, 2026 -
Widespread Abuse of ScreenConnect to Deploy AsyncRAT via Fake Installers
A significant cybersecurity campaign has emerged, exploiting the legitimate remote access tool ScreenConnect to deploy AsyncRAT malware. Attackers utilized spoofed websites and typosquatted domains, masquerading as…
7 articles · Updated July 1, 2026 -
Formbook Malware Campaign Targets Organizations with Advanced Phishing Techniques
Two phishing campaigns have been identified targeting organizations in Greece, Spain, Slovenia, Bosnia, Croatia, and several South American countries, aiming to deliver the Formbook infostealer malware. The first…
2 articles · Updated April 21, 2026 -
Cruciferra Crypter Service Powers Multiple Cybercrime Campaigns
Proofpoint has identified a sophisticated crypter service named Cruciferra, first sold in autumn 2025, that is utilized by various cybercriminal groups to cloak malware. The service employs advanced techniques such as…
8 articles · Updated July 20, 2026
Recent Intelligence Reports
- North Korean Spy Group Kimsuky Built Offline AI Lab on Attack Servers to Analyze Stolen Files — Techtimes · August 10, 2026
- Kimsuky Uses Local LLMs, AI — Cybersecuritynews · August 10, 2026
- Microsoft Warns Hackers Are Using BNB Chain to Spread Malware — U.Today · August 6, 2026
- 002 — attack.mitre.org · July 23, 2026
- 001 — attack.mitre.org · July 23, 2026
- Unpacking “Cruciferra”: An Analysis of a Sophisticated Crypter Service — Proofpoint · July 20, 2026
- Cruciferra Crypter Uses Process Ghosting to Evade Detection — Infosecurity-Magazine · July 20, 2026
- Opendir To Phishing Operator — blog.lexfo.fr · July 14, 2026