Related Threat Clusters
-
Russian Cyber Espionage Groups Target Academia and Government via OAuth Abuse
Google's Threat Intelligence Group is monitoring three suspected Russian cyber espionage clusters, including UNC6293, UNC7005, and UNC5976, which are targeting individuals in academia, aerospace, defense, and government…
2 articles · Updated August 21, 2026 -
Exploitation of Remote Services in Cyber Attacks
Adversaries are increasingly leveraging external remote services like VPNs and Citrix to gain unauthorized access to networks. These attacks often involve using valid accounts obtained through credential harvesting or…
2 articles · Updated June 3, 2026 -
GrayAlpha Threat Actor Uses MaskBat Loader for NetSupport RAT Deployments
Insikt Group identified GrayAlpha, a threat actor linked to FIN7, utilizing a custom loader named MaskBat to deploy NetSupport RAT through various infection vectors. These include fake browser update pages, fake 7-Zip…
2 articles · Updated August 6, 2026 -
Operation PhantomCLR: Advanced AppDomain Hijacking Targets Financial Sectors
A sophisticated cyber attack campaign, named Operation PhantomCLR, has been identified, targeting organizations in the Middle East and EMEA financial sectors. The attackers exploit a legitimate Intel utility,…
3 articles · Updated April 20, 2026
Recent Intelligence Reports
- Apt29 Evolving Diplomatic Phishing — cloud.google.com · August 21, 2026
- T1027 — attack.mitre.org · August 7, 2026
- T1021 — attack.mitre.org · July 4, 2026
- Operation PhantomCLR : Stealth Execution via AppDomain Hijacking and In — Cyfirma · April 18, 2026