Related Threat Clusters
-
Persistent Firestarter Malware Targets Cisco Firepower Devices in US Agencies
A sophisticated backdoor malware named Firestarter has been discovered on Cisco Firepower devices, attributed to the state-sponsored threat actor UAT-4356. The malware exploits two vulnerabilities, CVE-2025-20333 and…
37 articles · Updated April 23, 2026 -
Operation Endgame Disrupts Evil Corp's SocGholish Malware Network
On June 18, 2026, international law enforcement agencies launched Operation Endgame, disrupting the SocGholish malware infrastructure linked to the Russian cybercrime group Evil Corp. The operation resulted in the…
67 articles · Updated June 18, 2026 -
MuddyWater Targets U.S. Entities Amid Geopolitical Tensions
In early 2026, the Iranian APT group MuddyWater launched cyberattacks against U.S. banking, a major airport, and Israeli operations of a U.S.-based software company. The attacks intensified in March, coinciding with…
16 articles · Updated July 22, 2026 -
GrayAlpha Threat Actor Uses MaskBat Loader for NetSupport RAT Deployments
Insikt Group identified GrayAlpha, a threat actor linked to FIN7, utilizing a custom loader named MaskBat to deploy NetSupport RAT through various infection vectors. These include fake browser update pages, fake 7-Zip…
2 articles · Updated August 6, 2026 -
Grandoreiro Banking Trojan Resurfaces in Mexico with DLL Sideloading Tactics
The Grandoreiro banking trojan has re-emerged in a new campaign targeting users in Mexico, which accounted for 40% of observed detections. This malware, originating from Brazil, employs DLL sideloading techniques using…
5 articles · Updated August 19, 2026
Recent Intelligence Reports
- 'Grandoreiro' Malware Resurfaces With Mexico Campaign — Darkreading · August 20, 2026
- T1027 — attack.mitre.org · August 7, 2026
- 002 — attack.mitre.org · July 23, 2026
- Global Cyber Strike Disrupts SocGholish, Amadey, and StealC Malware Networks — Albaniandailynews · June 24, 2026
- 1.4 million leaked WordPress credentials — www.politie.nl · June 23, 2026
- Operation Endgame Hits SocGholish Malware Network, 14,971 Websites Cleaned — Thecyberexpress · June 19, 2026
- Police cleans nearly 15,000 SocGholish — Bleepingcomputer · June 18, 2026
- 11 Politie En Om Openen De Jacht Op Beruchte Malwaregroep Socgholish — www.politie.nl · June 18, 2026