Related Threat Clusters
-
MuddyWater Targets U.S. Entities Amid Geopolitical Tensions
In early 2026, the Iranian APT group MuddyWater launched cyberattacks against U.S. banking, a major airport, and Israeli operations of a U.S.-based software company. The attacks intensified in March, coinciding with…
16 articles · Updated July 22, 2026 -
PEEP Chrome Extension Turns Browsers Into Remote Access Tools
Cybersecurity researchers have uncovered a sophisticated post-exploitation toolkit named PEEP, which masquerades as a 'Smart Bookmarks' Chrome extension. This malware requires prior administrative access to be…
12 articles · Updated September 7, 2026 -
Glassworm Malware Targets React Native npm Packages in Supply Chain Attack
On March 16, 2026, two React Native npm packages, [email protected] and [email protected], were compromised in a supply chain attack attributed to Glassworm malware. The…
3 articles · Updated March 17, 2026 -
GlassWorm Malware Campaign Targets OpenVSX with 73 Malicious Extensions
A resurgence of the GlassWorm malware campaign has been identified, targeting the OpenVSX ecosystem with 73 'sleeper' extensions that become malicious after updates. Six of these extensions have already been activated…
8 articles · Updated April 27, 2026 -
Malicious JetBrains Plugins Exfiltrate AI API Keys from Developers
A coordinated malware campaign has been uncovered involving at least 15 malicious plugins on the JetBrains Marketplace, designed to steal AI API keys from developers. These plugins, masquerading as AI coding assistants,…
7 articles · Updated June 16, 2026 -
Glassworm Botnet Targeting Developers Disrupted by CrowdStrike and Google
The Glassworm botnet, which has targeted software developers since early 2025, was taken down in a coordinated operation by CrowdStrike, Google, and the Shadowserver Foundation on May 26, 2026. This botnet utilized…
30 articles · Updated May 27, 2026 -
Armored Likho Expands Cyber-Espionage with New Rust Toolkit
In May 2026, the Armored Likho group, also known as Eagle Werewolf, launched a cyber-espionage campaign targeting private individuals and organizations in Russia, including corporations, government bodies, and…
2 articles · Updated August 13, 2026 -
GlassWorm's ForceMemo Campaign Compromises Hundreds of Python Repositories
The ForceMemo campaign, attributed to the GlassWorm threat actor, is actively targeting the Python open-source ecosystem by exploiting stolen GitHub tokens to inject obfuscated malware into numerous repositories. The…
6 articles · Updated March 18, 2026 -
Analysis of GlassWorm V2 Malware via Compromised Cursor Extension
A variant of the GlassWorm malware has been identified, distributed through a compromised Cursor extension on Open VSX. The attack utilizes a sophisticated infection chain and a resilient command-and-control (C2)…
2 articles · Updated March 13, 2026 -
GlassWorm Campaign Expands with 72 Malicious Open VSX Extensions
The GlassWorm malware campaign has intensified its operations by utilizing 72 newly identified malicious Open VSX extensions. These extensions exploit transitive dependencies within developer environments, allowing the…
8 articles · Updated March 14, 2026
Recent Intelligence Reports
- PEEP Malware: Chrome Extension Hijacks Browsers, Steals Data — bitnewsbot.com · September 8, 2026
- cybernoz.com — cybernoz.com · September 8, 2026
- PEEP Turns Chrome and Edge Into Post — Thehackernews · September 7, 2026
- 23-Year-Old Sality P2P Botnet Disrupted — Securityweek · September 2, 2026
- Dead Drop Resolver — attack.mitre.org · August 14, 2026
- T1539 — attack.mitre.org · July 23, 2026
- Multiple JetBrains IDE plugins caught stealing AI keys — Aikido.Dev · June 16, 2026
- Google and CrowdStrike dismantle botnet targeting open source developers — News.Laodong.Vn · May 28, 2026