Related Threat Clusters
-
MuddyWater Targets U.S. Entities Amid Geopolitical Tensions
In early 2026, the Iranian APT group MuddyWater launched cyberattacks against U.S. banking, a major airport, and Israeli operations of a U.S.-based software company. The attacks intensified in March, coinciding with…
16 articles · Updated July 22, 2026 -
Chinese APT VerdantBamboo Exploits Brickstorm Malware for Long-term Network Access
The Chinese espionage group UNC5221, also known as VerdantBamboo, has been using the Brickstorm backdoor and new malware variants Plenet and AgentPSD to maintain access to compromised Microsoft 365 environments.…
5 articles · Updated June 5, 2026 -
VerdantBamboo's 18-Month Cyber Campaign Targets Managed Service Providers
A Chinese threat actor known as VerdantBamboo compromised a company's network through a managed service provider (MSP) over 18 months. The initial breach involved a Linux-based Egnyte Storage Sync appliance, which was…
2 articles · Updated June 5, 2026 -
Google Reports 90 Exploited Zero-Day Vulnerabilities in 2025
Google's Threat Intelligence Group tracked 90 zero-day vulnerabilities exploited in 2025, a rise from 78 in 2024. Less than half of these vulnerabilities were attributed to specific threat actors, with spyware vendors…
35 articles · Updated March 5, 2026 -
Chinese Hackers Exploit Dell Zero-Day Flaw CVE-2026-22769 Since Mid-2024
A Chinese state-backed hacking group, UNC6201, has been exploiting a critical zero-day vulnerability in Dell RecoverPoint for Virtual Machines since at least mid-2024. The flaw, tracked as CVE-2026-22769, features a…
40 articles · Updated February 17, 2026 -
Cloud Attacks Shift Focus to Exploiting Software Vulnerabilities
Hackers are increasingly targeting newly disclosed vulnerabilities in third-party software to access cloud environments, with the time frame for such attacks decreasing significantly. Google reports a notable decline in…
1 article · Updated March 9, 2026 -
GrayAlpha Threat Actor Uses MaskBat Loader for NetSupport RAT Deployments
Insikt Group identified GrayAlpha, a threat actor linked to FIN7, utilizing a custom loader named MaskBat to deploy NetSupport RAT through various infection vectors. These include fake browser update pages, fake 7-Zip…
2 articles · Updated August 6, 2026 -
Typosquatting Attack Targets Python Developers with Malicious Package
A malicious Python package named 'parsimonius' was uploaded to the Python Package Index (PyPI), mimicking the legitimate 'parsimonious' library. This typosquatting attack exploited developer trust, leading to 2,474…
6 articles · Updated June 5, 2026 -
VECT 2.0 Ransomware Compromises File Recovery for Victims
VECT 2.0 ransomware has emerged as a significant threat, leaving victims unable to recover files even with the attackers' decryptor. This ransomware employs a flawed design that discards nonces for earlier parts of…
5 articles · Updated June 5, 2026 -
Chinese Hackers Deploy Brickworm Malware Against US Infrastructure
Chinese state-sponsored actors have utilized Brickworm malware to breach critical US infrastructure, targeting government and IT networks globally. The malware specifically exploits vulnerabilities in VMware vSphere and…
8 articles · Updated December 5, 2025
Recent Intelligence Reports
- T1027 — attack.mitre.org · August 7, 2026
- T1102 — attack.mitre.org · July 23, 2026
- Verdantbamboo Just Another Brickstorm In The Firewall — www.volexity.com · June 5, 2026
- Chinese APT deploys new malware to keep access to hacked networks — Bleepingcomputer · June 5, 2026
- Chinese APT deploys new malware to keep access to hacked networks — Bleepingcomputer · June 5, 2026
- Chinese APT VerdantBamboo Uses BRICKSTORM Malware to Compromise Firewalls and Appliances — Cybersecuritynews · June 5, 2026
- China’s VerdantBamboo Experimented With Three Re — Thecyberexpress · June 5, 2026
- Malicious Python Package Mimics Parsimonious Parser — Gbhackers · June 5, 2026