Related Threat Clusters
-
China-Linked QTFY Group Targets Critical Infrastructure with Advanced Exploits
The Joint Cybersecurity Advisory JCSA-20260826-01, released on August 26, 2026, details ongoing activities by the China-linked hacking group QTFY, attributed to Nanjing Xinjiuwei Network Technology Co. Active since…
7 articles · Updated September 2, 2026 -
MuddyWater Targets U.S. Entities Amid Geopolitical Tensions
In early 2026, the Iranian APT group MuddyWater launched cyberattacks against U.S. banking, a major airport, and Israeli operations of a U.S.-based software company. The attacks intensified in March, coinciding with…
16 articles · Updated July 22, 2026 -
OceanLotus Shifts Focus to Domestic Espionage with SPECTRALVIPER Attacks
From mid-2024 to early 2026, the Vietnam-aligned APT group OceanLotus has intensified its focus on domestic espionage, utilizing the SPECTRALVIPER backdoor in two major campaigns. The first campaign targeted a…
17 articles · Updated June 11, 2026 -
China-nexus Threat Actor Deploys PlugX in Persian Gulf Amid Middle East Conflict
On March 1, 2026, a China-nexus threat actor launched a cyber campaign targeting countries in the Persian Gulf region, coinciding with renewed conflict in the Middle East. The attack utilized social engineering tactics,…
2 articles · Updated March 12, 2026 -
TA416 Resumes Cyber Espionage Against European Governments Amid Geopolitical Tensions
Chinese state-backed group TA416 has reemerged with intensified cyber espionage campaigns targeting European governments, following a quiet period since 2023. Proofpoint reported that the group's renewed activity began…
9 articles · Updated April 1, 2026 -
Webworm APT Expands Operations to Europe with New Backdoors
The China-aligned APT group Webworm has shifted its focus from Asia to Europe, targeting government organizations in Belgium, Italy, Poland, Serbia, and Spain during 2025. ESET researchers identified new backdoors,…
12 articles · Updated May 20, 2026 -
HoneyMyte APT Upgrades CoolClient Backdoor with Kernel Driver for Enhanced Stealth
The HoneyMyte APT group has deployed an upgraded variant of the CoolClient backdoor in cyber-espionage campaigns targeting organizations in Myanmar, Mongolia, Pakistan, India, and Russia. This new variant introduces a…
10 articles · Updated August 14, 2026 -
Mustang Panda Launches PlugX RAT Campaign via Fake Browser Update
Mustang Panda, a Chinese state-sponsored threat group, has initiated a cyberattack campaign deploying the PlugX remote access tool (RAT). The attack utilizes a fake browser updater to trick users into downloading a…
2 articles · Updated June 2, 2026 -
Showboat Malware Targets Telecoms in China-Aligned Cyber Espionage Campaign
A new Linux malware family named Showboat has been discovered, targeting telecommunications firms primarily in the Middle East and Central Asia since mid-2022. Researchers from Lumen's Black Lotus Labs and PwC…
9 articles · Updated May 21, 2026 -
China-Nexus Hackers Target Hospitals and Governments with TriBack Loader Malware
A China-linked cyber espionage operation has compromised a Vietnamese public hospital's imaging systems, infiltrated Malaysia's Ministry of Foreign Affairs, and targeted Honduras's National Congress using a new malware…
2 articles · Updated July 23, 2026
Recent Intelligence Reports
- T1583.001 Acquire Infrastructure: Domains — attack.mitre.org · September 9, 2026
- US and European authorities disrupt Sality botnet after 23 years — Cyberinsider · September 2, 2026
- 001 — attack.mitre.org · September 2, 2026
- New Apt Group Earth Berberoka Targets Gambling Websites With Old — www.trendmicro.com · September 2, 2026
- How China industrialized the infrastructure behind state hacking — Csoonline · September 2, 2026
- China Hacked NASA, Federal Reserve: FBI Seizes Platforms Behind Eight — Techtimes · August 27, 2026
- Chinese state-sponsored hackers — thenationaldesk.com · August 27, 2026
- DOJ says China-linked hackers breached NASA, Federal Reserve and Senate networks — Katu · August 26, 2026