Lateral Movement - MITRE ATT&CK

Threat entity extracted from intelligence sources

Frequency
22
occurrences
First Seen
October 31, 2025
Last Seen
January 30, 2026

Lateral Movement is a mitre_attack tracked across 22 threat clusters and 22 intelligence report mentions on ThreatCluster. First observed October 31, 2025; most recent activity January 30, 2026.

Related Threat Clusters

  • CISA Warns of Active Exploitation of CVE-2024-1086 in Ransomware Attacks

    The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued an alert regarding the active exploitation of a critical vulnerability in the Linux kernel, tracked as CVE-2024-1086. This privilege escalation…

    5 articles · Updated November 4, 2025
  • APT41 Cyber-Espionage Tactics Explored in Ransomware Emulations

    The article discusses the fifth volume of AttackIQ’s Ransom Tales series, which simulates the tactics of ransomware families REvil, DarkSide, and BlackMatter. These emulations are designed to help organizations validate…

    14 articles · Updated January 6, 2026
  • Cisco ASA Zero-Day Exploited in State-Espionage Campaign

    Cisco disclosed a state-espionage campaign targeting its Adaptive Security Appliances (ASA), which are used for firewall and VPN functions. Attackers exploited two zero-day vulnerabilities to infiltrate government…

    27 articles · Updated December 18, 2025
  • Gentlemen Ransomware Targets Global Industries Amid LLM Integration

    The Gentlemen ransomware operation has affected at least 17 countries across the Americas, Asia-Pacific, and the Middle East, targeting sectors such as manufacturing, healthcare, construction, and insurance. This…

    26 articles · Updated December 17, 2025
  • Chinese Hackers Target US Communications Networks: Salt Typhoon Operation

    Chinese hackers, identified as part of the Salt Typhoon operation, have infiltrated at least nine major U.S. communications networks, raising alarms among U.S. policymakers. The operation has been characterized by…

    22 articles · Updated January 30, 2026
  • Hackers Exploit Misconfigured Cloud Training Apps in Fortune 500 Firms

    Pentera Labs has reported that threat actors are exploiting misconfigured cloud training applications used by Fortune 500 companies and cybersecurity vendors. These vulnerabilities allow attackers to gain unauthorized…

    5 articles · Updated January 21, 2026
  • AI Tools Generate Ransomware Payloads Instantly

    Malicious AI tools such as WormGPT 4 and KawaiiGPT have emerged, capable of generating ransomware payloads, data exfiltration scripts, and lateral movement scripts on-the-fly. These developments pose significant risks…

    1 article · Updated November 26, 2025
  • Massive Power Outage Affects Spain, Portugal, and France

    In late April, a significant power outage impacted Spain, Portugal, and parts of southwestern France, leaving tens of millions without electricity for hours. The outage caused widespread disruptions, including halted…

    2 articles · Updated November 3, 2025
  • CISA Warns of Ransomware Exploiting CVE-2024-1086 in Linux Kernel

    The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued an alert regarding the exploitation of a critical vulnerability in the Linux kernel, tracked as CVE-2024-1086, by ransomware groups. This…

    4 articles · Updated November 3, 2025
  • Nevada Ransomware Attack Timeline and Impact

    A ransomware attack on Nevada's state systems began in May 2023 after an employee downloaded malicious software. Discovered in August 2023, the attack disrupted essential services and cost the state at least $1.5…

    2 articles · Updated November 6, 2025

Recent Intelligence Reports

  • China's Typhoon hackers have changed the rules of cybersecurity — Scworld · January 30, 2026
  • Pentera Discovers Exposed Cloud Training Applications Actively Exploited with Crypto — Prnewswire · January 21, 2026
  • Pentera Discovers Exposed Cloud Training Applications Actively Exploited with Crypto — Prnewswire · January 21, 2026
  • New Chinese-Made Malware Framework Targets Linux — Infosecurity-Magazine · January 13, 2026
  • Has cyber insurance lost the war with AI? — Globalreinsurance · January 7, 2026
  • 10,000+ Fortinet Firewalls Still Exposed to 5 — Cybersecuritynews · January 2, 2026
  • 2026 Will Break Long-Held CISO Security Assumptions — Msspalert · December 31, 2025
  • ArcaneDoor Attack (Cisco ASA Zero-Day) — Filestore.Fortinet · December 18, 2025

CVSS v3.1 Breakdown