Related Threat Clusters
-
Sandworm Launches Wiper Malware Campaign Against Ukrainian Organizations
The Russian state-backed hacking group Sandworm has intensified its operations against Ukrainian organizations by deploying data-wiping malware. This campaign targets critical sectors, including the grain industry, and…
6 articles · Updated November 7, 2025 -
EU Sanctions Russia Over Ongoing Cyber Espionage Campaign
The European Union has condemned and sanctioned Russia for a prolonged cyber espionage campaign targeting its member states. The campaign, orchestrated by the 16th Centre of the FSB, has involved infiltrating government…
172 articles · Updated July 13, 2026 -
MuddyWater Targets U.S. Entities Amid Geopolitical Tensions
In early 2026, the Iranian APT group MuddyWater launched cyberattacks against U.S. banking, a major airport, and Israeli operations of a U.S.-based software company. The attacks intensified in March, coinciding with…
16 articles · Updated July 22, 2026 -
GRU Cyber Operations Targeting Ukraine and NATO Allies
The UK government has published a report detailing the cyber and hybrid threat operations of the Russian GRU, specifically focusing on Unit 29155. This unit has been linked to various cyber-attacks against Ukraine,…
2 articles · Updated August 25, 2026 -
Data Destruction and Disk Wiping Techniques Targeting Organizations
Adversaries are employing data destruction and disk wiping techniques to disrupt organizational operations. Techniques include overwriting files and disk data, with malware exhibiting worm-like propagation capabilities.…
2 articles · Updated July 22, 2026 -
China-aligned APT Groups Target Global Maritime and Tech Sectors Amid Geopolitical Tensions
ESET's latest APT Activity Report reveals that from October 2025 to March 2026, China-aligned threat actors engaged in extensive espionage campaigns, particularly in Venezuela and the Gulf region. Following U.S.…
6 articles · Updated May 28, 2026 -
Widespread Abuse of ScreenConnect to Deploy AsyncRAT via Fake Installers
A significant cybersecurity campaign has emerged, exploiting the legitimate remote access tool ScreenConnect to deploy AsyncRAT malware. Attackers utilized spoofed websites and typosquatted domains, masquerading as…
7 articles · Updated July 1, 2026 -
CallPhantom Fraudulent Apps Scam Millions of Android Users
A series of fraudulent apps named CallPhantom were discovered on Google Play, promising access to call histories for any phone number. Users were tricked into paying for subscriptions, only to receive fabricated data.…
7 articles · Updated May 7, 2026 -
Sandworm Hackers Target Ukraine's Grain Sector with Data-Wiping Malware
The Russian state-backed hacker group Sandworm has launched a campaign using data-wiping malware against Ukrainian organizations, particularly focusing on the grain sector. This attack aims to disrupt critical…
9 articles · Updated November 8, 2025
Recent Intelligence Reports
- Profile Gru Cyber And Hybrid Threat Operations — www.gov.uk · August 25, 2026
- T1102 — attack.mitre.org · July 23, 2026
- T1485 — attack.mitre.org · July 23, 2026
- EU and UK officially blame Russian spies for cyberattack on Poland's power grid — Theregister · July 13, 2026
- 012 — attack.mitre.org · July 1, 2026
- ESET APT Reports — www.globenewswire.com · May 28, 2026
- ESET Threat Intelligence — www.eset.com · May 7, 2026
- Sandworm hackers use data wipers to disrupt Ukraine's grain sector — Bleepingcomputer · November 6, 2025