Related Threat Clusters
-
China-linked Cyber Group Expands Targeting to Southeastern Europe
A sophisticated threat actor known as UAT-7290, tracked by Cisco Talos, has expanded its operations to target telecommunications providers in Southeastern Europe. This group, which has been active since at least 2022,…
1 article · Updated January 8, 2026 -
China-Nexus APT UAT-7290 Targets South Asia Telecoms in Cyber Espionage Campaign
A new threat actor, UAT-7290, has been identified conducting cyberattacks on telecommunications infrastructure in South Asia. This operation is linked to a China-Nexus state-sponsored advanced persistent threat (APT)…
1 article · Updated January 9, 2026 -
China-linked UAT-7290 Targets Telcos in Cyberespionage Campaign
Telecommunications providers in South Asia and Southeastern Europe have been targeted by the China-linked threat operation UAT-7290 in a series of cyberespionage attacks. The intrusions involved extensive reconnaissance…
1 article · Updated January 9, 2026 -
UAT-7290 Cyber Espionage Targets South Asian Telecoms
UAT-7290, a China-linked advanced persistent threat group, has been active since at least 2022, focusing on espionage against telecommunications providers in South Asia. The group employs a range of Linux and Windows…
2 articles · Updated January 12, 2026 -
SHADOW-EARTH-053 Exploits Microsoft Exchange Vulnerabilities in Asia
The China-aligned threat group SHADOW-EARTH-053 has been exploiting unpatched Microsoft Exchange and IIS server vulnerabilities, specifically the ProxyLogon vulnerability chain, to conduct cyberespionage. This group has…
2 articles · Updated May 5, 2026 -
FortiWeb WAF Vulnerability Enables Full Admin Control Exploitation
A critical vulnerability in FortiWeb Web Application Firewall (WAF) has been actively exploited, allowing attackers to gain full administrative access to affected systems. Organizations using FortiWeb are at risk of…
100 articles · Updated November 15, 2025 -
Jewelbug APT Group Engages in Espionage and Cryptocurrency Fraud
The Jewelbug APT group, based in China, has been conducting simultaneous cyber espionage and cryptocurrency fraud operations. Utilizing a single command-and-control platform named XG-Web, the group has compromised over…
15 articles · Updated August 13, 2026 -
Operation TrueChaos: Exploitation of TrueConf Zero-Day Vulnerability
In early 2026, a series of targeted attacks named Operation TrueChaos exploited a zero-day vulnerability in TrueConf software, tracked as CVE-2026-3502, which allows attackers to execute arbitrary files on connected…
5 articles · Updated April 1, 2026 -
FamousSparrow APT Expands Targeting to Azerbaijani Energy Sector
FamousSparrow, a China-aligned APT group, launched a multi-wave cyberespionage campaign against an Azerbaijani oil and gas company from late December 2025 to February 2026. The attackers employed an evolved DLL…
10 articles · Updated May 13, 2026 -
Showboat Malware Targets Telecoms in China-Aligned Cyber Espionage Campaign
A new Linux malware family named Showboat has been discovered, targeting telecommunications firms primarily in the Middle East and Central Asia since mid-2022. Researchers from Lumen's Black Lotus Labs and PwC…
9 articles · Updated May 21, 2026
Recent Intelligence Reports
- Jewelbug Apt Russia — www.security.com · August 16, 2026
- Hunt.io, July 23, 2026 — hunt.io · July 30, 2026
- Threat Actor Ran Open-Source Hermes AI Agent in 'YOLO Mode' Against Thai Finance Ministry — Aiweekly.Co · July 25, 2026
- Weekly Threat Bulletin February 11th 2026 — www.f5.com · July 2, 2026
- Mustang Panda targets India's government and energy sectors with ZOHOMURK and MINIRECON — Acronis · June 29, 2026
- Fishmongers Arsenal Upgraded Sprysocks Windows — www.welivesecurity.com · June 19, 2026
- Advanced Kernel — Rescana · June 17, 2026
- SprySOCKS Backdoor Expands From Linux to Windows — Infosecurity-Magazine · June 16, 2026