Related Threat Clusters
-
MuddyWater Targets U.S. Entities Amid Geopolitical Tensions
In early 2026, the Iranian APT group MuddyWater launched cyberattacks against U.S. banking, a major airport, and Israeli operations of a U.S.-based software company. The attacks intensified in March, coinciding with…
16 articles · Updated July 22, 2026 -
Armored Likho Expands Cyber-Espionage with New Rust Toolkit
In May 2026, the Armored Likho group, also known as Eagle Werewolf, launched a cyber-espionage campaign targeting private individuals and organizations in Russia, including corporations, government bodies, and…
2 articles · Updated August 13, 2026 -
Ousaban Banking Trojan Targets Users in Spain and Portugal with Advanced Techniques
The Ousaban banking trojan has been identified targeting Windows users in Spain and Portugal since May 2026. This malware employs phishing PDFs disguised as corrupted files to lure victims into clicking an 'Atualizar'…
8 articles · Updated July 1, 2026 -
Grandoreiro Banking Trojan Resurfaces in Mexico with DLL Sideloading Tactics
The Grandoreiro banking trojan has re-emerged in a new campaign targeting users in Mexico, which accounted for 40% of observed detections. This malware, originating from Brazil, employs DLL sideloading techniques using…
5 articles · Updated August 19, 2026
Recent Intelligence Reports
- Grandoreiro goes north: From Brazil to Mexico with a new DLL sideloading campaign — Acronis · August 19, 2026
- Dead Drop Resolver — attack.mitre.org · August 14, 2026
- 002 — attack.mitre.org · July 23, 2026
- A Brazilian banking trojan is targeting Santander and BBVA customers with fake PDF lures — Thenextweb · July 1, 2026