T1014 - Rootkit is a mitre_attack tracked across 8 threat clusters and 14 intelligence report mentions on ThreatCluster. First observed December 30, 2025; most recent activity July 6, 2026.
A significant wave of cyberattacks has targeted ComfyUI servers, converting them into a botnet for cryptomining and proxy operations. Researchers from Censys reported that since March 12, 2026, over 1,000 publicly…
In 2026, global cybersecurity spending is projected to reach $244 billion, driven by tighter regulations and the emergence of AI-driven vulnerabilities. The U.S. Intelligence Community's 2026 Annual Threat Assessment…
A new supply chain attack, dubbed 'Mini Shai-Hulud', has compromised multiple npm packages related to SAP's Cloud Application Programming Model (CAP). This attack involves injecting malicious preinstall scripts into…
The SilverFox APT group has upgraded its ValleyRAT malware into a sophisticated eight-stage malware chain, culminating in a kernel-mode rootkit. This evolution enhances post-exploitation persistence and evasion…
In mid-2025, the Chinese APT group Mustang Panda launched cyber-espionage attacks using a signed kernel-mode rootkit to deploy the ToneShell backdoor. The attacks targeted government organizations in Southeast and East…
A Chinese-linked threat group, associated with HoneyMyte, is utilizing a new kernel rootkit to obscure its ToneShell backdoor. This cyber campaign has primarily targeted government networks in Southeast and East Asia,…
In July 2025, an advanced persistent threat actor known as UNC3886 targeted Singapore's four telecommunications companies, compromising critical infrastructure. The attack was detected by the Infocomm Media Development…
The Chinese-linked group Mustang Panda has utilized a kernel-level rootkit to implant undetectable TONESHELL malware in Windows systems. This attack primarily targets Southeast Asian nations, indicating a strategic…