Related Threat Clusters
-
MuddyWater Targets U.S. Entities Amid Geopolitical Tensions
In early 2026, the Iranian APT group MuddyWater launched cyberattacks against U.S. banking, a major airport, and Israeli operations of a U.S.-based software company. The attacks intensified in March, coinciding with…
16 articles · Updated July 22, 2026 -
Gambling Goblin Targets Brazilian Government Sites for SEO Fraud
A Chinese-speaking cybercrime group, dubbed Gambling Goblin, has been targeting Brazilian government and educational institutions since mid-2025. This group is connected to the previously documented Earth Berberoka and…
4 articles · Updated September 2, 2026 -
Armored Likho Expands Cyber-Espionage with New Rust Toolkit
In May 2026, the Armored Likho group, also known as Eagle Werewolf, launched a cyber-espionage campaign targeting private individuals and organizations in Russia, including corporations, government bodies, and…
2 articles · Updated August 13, 2026 -
Spearphishing Campaigns Exploit Malicious Links for User Execution
Recent reports detail various adversaries utilizing spearphishing tactics to exploit users into clicking malicious links. These links often lead to the execution of malware or the harvesting of sensitive information,…
2 articles · Updated September 2, 2026 -
GoPix Trojan Targets Brazilian Financial Sector with Advanced Techniques
GoPix is a sophisticated banking Trojan that has been actively targeting Brazilian financial institutions and cryptocurrency users for over three years. The malware employs memory-only implants and utilizes malvertising…
2 articles · Updated March 16, 2026 -
Grandoreiro Banking Trojan Expands Global Reach with New Campaigns
The Grandoreiro banking trojan, active since 2016, has intensified its phishing campaigns targeting over 1,700 banks and financial institutions across 60 countries, including recent operations in South Africa and…
4 articles · Updated May 28, 2026 -
GrayAlpha Threat Actor Uses MaskBat Loader for NetSupport RAT Deployments
Insikt Group identified GrayAlpha, a threat actor linked to FIN7, utilizing a custom loader named MaskBat to deploy NetSupport RAT through various infection vectors. These include fake browser update pages, fake 7-Zip…
2 articles · Updated August 6, 2026 -
Ousaban Banking Trojan Targets Users in Spain and Portugal with Advanced Techniques
The Ousaban banking trojan has been identified targeting Windows users in Spain and Portugal since May 2026. This malware employs phishing PDFs disguised as corrupted files to lure victims into clicking an 'Atualizar'…
8 articles · Updated July 1, 2026 -
VENON Malware Targets 33 Brazilian Banks with Rust-Based Attack
A new banking malware named VENON has been identified, specifically targeting users in Brazil. This malware, developed in Rust, represents a shift from the previously common Delphi-based variants in the region. VENON…
3 articles · Updated March 13, 2026 -
Critical Vulnerabilities Discovered in Mozilla Products
Multiple vulnerabilities have been identified in Mozilla products, with the most severe allowing for arbitrary code execution. Exploitation could enable attackers to install programs, access, modify, or delete data, and…
44 articles · Updated April 8, 2026
Recent Intelligence Reports
- 001 — attack.mitre.org · September 2, 2026
- Gambling Goblin Turns Brazilian Government Sites Into SEO Weapons — Infosecurity-Magazine · September 2, 2026
- Mexico’s Cybersecurity Plan 2025-2030: Turning Ambition Into Defense — Recordedfuture · August 25, 2026
- Mexico’s Cybersecurity Plan 2025-2030: Turning Ambition Into Defense — Recordedfuture · August 25, 2026
- Disrupting A Grandoreiro Malware Operation — www.interpol.int · August 20, 2026
- Grandoreiro Banking Trojan Unleashed — www.ibm.com · August 20, 2026
- 'Grandoreiro' Malware Resurfaces With Mexico Campaign — Darkreading · August 20, 2026
- Grandoreiro Resurfaces in Mexico With New DLL Sideloading Campaign — Infosecurity-Magazine · August 19, 2026