XenoRAT is a malware family tracked across 4 threat clusters and 5 intelligence report mentions on ThreatCluster. First observed January 23, 2026; most recent activity May 30, 2026.
A sophisticated malware campaign targeting users in South Korea has been identified, utilizing malicious LNK files that leverage GitHub as a command and control (C2) infrastructure. The campaign, attributed to North…
The North Korean hacking group Kimsuky is utilizing generative AI to create malware aimed at South Korean government systems, as reported by Kaspersky on May 14, 2026. The malware, named HelloDoor, is a Rust-based…
A Pakistan-linked threat actor, SideCopy, has initiated a spear-phishing campaign against Afghanistan's Ministry of Finance, targeting all 34 provincial revenue directorates. The campaign utilizes a ZIP archive…
A malware campaign has emerged, utilizing LNK shortcut files to distribute MoonPeak, a remote access trojan linked to North Korean threat actors. The primary targets of this attack are South Korean investors and…