Related Threat Clusters
-
GhostShell Malware Targets Ukraine's UAV and Defense Supply Chain
The GhostShell malware cluster is actively targeting Ukraine’s UAV operations and defense supply chain. Utilizing advanced techniques such as mTLS-authenticated implants and Telegram-based loaders, the attackers gain…
2 articles · Updated June 25, 2026 -
Operation Endgame Disrupts Evil Corp's SocGholish Malware Network
On June 18, 2026, international law enforcement agencies launched Operation Endgame, disrupting the SocGholish malware infrastructure linked to the Russian cybercrime group Evil Corp. The operation resulted in the…
67 articles · Updated June 18, 2026 -
Russian Cyber Espionage Clusters Targeting Diplomats and Academics
Google's Threat Intelligence Group is monitoring three suspected Russian cyber espionage clusters, including UNC6293, UNC7005, and UNC5976, which are targeting individuals in academia, government, and defense sectors…
7 articles · Updated August 21, 2026 -
Torg Grabber Malware Targets 728 Crypto Wallets with Advanced Techniques
Torg Grabber, a new infostealer malware, is actively targeting 728 cryptocurrency wallet extensions and other applications, including password managers and communication tools. The malware employs the ClickFix technique…
2 articles · Updated March 27, 2026 -
SparkKitty Malware Targets Crypto Users via App Stores and Photo Galleries
SparkKitty is a newly identified cross-platform malware that targets cryptocurrency users by scanning photos on both iOS and Android devices for wallet recovery phrases. It spreads through trojanized applications…
15 articles · Updated July 27, 2026 -
Chronus Group Breach Exposes 36 Million Mexican Citizens' Data
In January 2026, the Chronus Group executed a significant data breach against the Mexican government, compromising 2.3 terabytes of sensitive data from at least 25 agencies. The breach exposed personal information of up…
2 articles · Updated May 28, 2026 -
Vidar Infostealer Adopts Fileless Techniques Using JPEG and TXT Payloads
The Vidar infostealer has evolved into a sophisticated multi-stage attack framework that utilizes fileless techniques to evade detection. Attackers embed malicious payloads within JPEG images and TXT documents,…
9 articles · Updated April 28, 2026 -
FBI Investigates Malware Embedded in Steam Games Affecting Millions of Players
The FBI is investigating a malware campaign targeting Steam users, with evidence suggesting that a single hacker has embedded malicious software in multiple games over a two-year period. The affected games include…
40 articles · Updated March 13, 2026 -
Microsoft Disrupts Fox Tempest Malware-Signing Service for Ransomware Gangs
On May 19, 2026, Microsoft disrupted Fox Tempest, a malware-signing-as-a-service (MSaaS) operation that provided over 1,000 fraudulent code-signing certificates to cybercriminals, enabling them to disguise malware as…
33 articles · Updated May 19, 2026 -
OXLOADER Malware Loader Delivers CASTLESTEALER via Malicious Google Ads
A new Windows loader named OXLOADER is delivering the CASTLESTEALER infostealer through malicious Google Ads. This previously undocumented malware employs advanced obfuscation techniques and abuses the Windows .reloc…
4 articles · Updated June 22, 2026
Recent Intelligence Reports
- Hackers Use Fake Google Gemini Installer to Deploy Vidar Stealer and Steal Browser Credentials — Gbhackers · August 21, 2026
- Distinct Clusters Target Individuals Of Interest To Russia — cloud.google.com · August 21, 2026
- Fake Gemini installer delivers Vidar infostealer via Google Colab lure — Feeds2.Feedburner · August 20, 2026
- Dark Web Data Pricing 2026 — www.stingrai.io · August 12, 2026
- SparkKitty Malware Found in App Stores Targets Crypto Wallet Seed Phrases — Decrypt.Co · July 27, 2026
- Introducing Cavalier's New Threat Feeds: Comprehensive Visibility into Attacker Infrastructure — Infostealers · July 23, 2026
- Introducing Cavalier's 'New Threat' Feeds: Deep Dive into Infostealer C2 Intelligence — Infostealers · July 21, 2026
- Vidar Infostealer Hammers SMBs via Malvertising Campaign — Darkreading · July 8, 2026