Related Threat Clusters
-
Operation Endgame Disrupts Evil Corp's SocGholish Malware Network
On June 18, 2026, international law enforcement agencies launched Operation Endgame, disrupting the SocGholish malware infrastructure linked to the Russian cybercrime group Evil Corp. The operation resulted in the…
67 articles · Updated June 18, 2026 -
MuddyWater Targets U.S. Entities Amid Geopolitical Tensions
In early 2026, the Iranian APT group MuddyWater launched cyberattacks against U.S. banking, a major airport, and Israeli operations of a U.S.-based software company. The attacks intensified in March, coinciding with…
16 articles · Updated July 22, 2026 -
Exploitation of Client Software Vulnerabilities and User Execution Techniques
Recent cybersecurity reports detail the exploitation of software vulnerabilities in client applications, particularly targeting web browsers and Microsoft Office. Adversaries utilize techniques such as Drive-by…
2 articles · Updated June 8, 2026 -
GrayAlpha Threat Actor Uses MaskBat Loader for NetSupport RAT Deployments
Insikt Group identified GrayAlpha, a threat actor linked to FIN7, utilizing a custom loader named MaskBat to deploy NetSupport RAT through various infection vectors. These include fake browser update pages, fake 7-Zip…
2 articles · Updated August 6, 2026 -
Russia's Cybercrime Landscape Shifts Amid Law Enforcement Actions
Recent arrests of cybercriminals in Russia indicate a changing landscape for cybercrime, traditionally tolerated by the state as long as domestic interests were not targeted. The ongoing Operation Endgame, initiated in…
2 articles · Updated January 9, 2026 -
Operation Endgame Disrupts Major Malware Networks Rhadamanthys, VenomRAT, and Elysium
Law enforcement from nine countries has dismantled over 1,000 servers associated with the Rhadamanthys infostealer, VenomRAT remote access Trojan, and Elysium botnet during Operation Endgame. This operation, coordinated…
8 articles · Updated November 13, 2025 -
Over 10,000 Linux Servers Infected by SystemBC Botnet Variant
A new Linux variant of the SystemBC remote access trojan has infected over 10,000 IP addresses worldwide, primarily targeting web servers. Discovered by Silent Push, the compromised servers include those hosting…
6 articles · Updated February 4, 2026 -
Operation Endgame 3.0 Disrupts Major Malware Networks
Europol and law enforcement agencies from 11 countries executed Operation Endgame 3.0 from November 10 to 13, 2025, dismantling the infrastructure of three major malware operations: Rhadamanthys, VenomRAT, and Elysium.…
20 articles · Updated November 24, 2025
Recent Intelligence Reports
- T1204 — attack.mitre.org · August 7, 2026
- T1620 — attack.mitre.org · July 23, 2026
- Police cleans nearly 15,000 SocGholish — Bleepingcomputer · June 18, 2026
- Over 10,000 SystemBC Botnet Infections Identified Globally — Technadu · February 4, 2026
- Police disrupts Rhadamanthys, VenomRAT, and Elysium malware operations — Bleepingcomputer · November 13, 2025
- Dark Covenant 3.0: Controlled Impunity and Russia’s Cybercriminals — Recordedfuture · October 23, 2025