Related Threat Clusters
-
MuddyWater Targets U.S. Entities Amid Geopolitical Tensions
In early 2026, the Iranian APT group MuddyWater launched cyberattacks against U.S. banking, a major airport, and Israeli operations of a U.S.-based software company. The attacks intensified in March, coinciding with…
16 articles · Updated July 22, 2026 -
Widespread Abuse of ScreenConnect to Deploy AsyncRAT via Fake Installers
A significant cybersecurity campaign has emerged, exploiting the legitimate remote access tool ScreenConnect to deploy AsyncRAT malware. Attackers utilized spoofed websites and typosquatted domains, masquerading as…
7 articles · Updated July 1, 2026 -
Exploitation of Client Software Vulnerabilities and User Execution Techniques
Recent cybersecurity reports detail the exploitation of software vulnerabilities in client applications, particularly targeting web browsers and Microsoft Office. Adversaries utilize techniques such as Drive-by…
2 articles · Updated June 8, 2026 -
GrayAlpha Threat Actor Uses MaskBat Loader for NetSupport RAT Deployments
Insikt Group identified GrayAlpha, a threat actor linked to FIN7, utilizing a custom loader named MaskBat to deploy NetSupport RAT through various infection vectors. These include fake browser update pages, fake 7-Zip…
2 articles · Updated August 6, 2026 -
Russian-linked Threat Actors Deploy SocGholish Malware via Fake Browser Updates
Cybersecurity researchers at Arctic Wolf Labs have identified a cyberattack campaign utilizing fake browser update notifications to distribute SocGholish malware. This campaign is linked to Russian threat actors and…
12 articles · Updated November 26, 2025
Recent Intelligence Reports
- T1204 — attack.mitre.org · August 7, 2026
- T1102 — attack.mitre.org · July 23, 2026
- 012 — attack.mitre.org · July 1, 2026
- Russian RomCom Uses SocGholish to Deploy Malware on Ukraine Supporters — Technadu · November 27, 2025