Frequency
3
occurrences
First Seen
April 6, 2026
Last Seen
August 7, 2026
Related Threat Clusters
-
Kimsuky Exploits South Korean Groupware Vendors with New Gomir Variants
The Kimsuky group, linked to North Korea, targeted South Korean groupware vendors from late 2025 to early 2026, deploying new malware variants BirdTroy and DriveTroy. These Linux backdoors utilized Google Drive for…
4 articles · Updated July 24, 2026 -
North Korea Adopts Modular Malware to Evade Detection and Takedowns
North Korea's cyber program has transitioned to a modular malware strategy, moving away from monolithic malware families to a more fragmented ecosystem. This change is a response to years of international sanctions, law…
3 articles · Updated April 6, 2026 -
GrayAlpha Threat Actor Uses MaskBat Loader for NetSupport RAT Deployments
Insikt Group identified GrayAlpha, a threat actor linked to FIN7, utilizing a custom loader named MaskBat to deploy NetSupport RAT through various infection vectors. These include fake browser update pages, fake 7-Zip…
2 articles · Updated August 6, 2026
Recent Intelligence Reports
- T1027 — attack.mitre.org · August 7, 2026
- Analysis Of Kimsuky S Attack On A South Korean Groupware Vendor Using A New Gomir Family Variant — www.enki.co.kr · July 24, 2026
- North Korea's Modular Malware Strategy Hides Attribution, Defies Takedowns — Gbhackers · April 6, 2026