T1027 - Obfuscated/Compressed Files and Information is a mitre_attack tracked across 15 threat clusters and 12 intelligence report mentions on ThreatCluster. First observed October 31, 2025; most recent activity January 25, 2026.
A multi-stage phishing campaign is targeting Russian organizations with Amnesia RAT and Hakuna Matata ransomware. The attackers use social engineering tactics to deliver malicious files disguised as business documents,…
APT24, a China-linked hacking group, has been utilizing a previously undocumented malware named BadAudio in a three-year espionage campaign. This malware has been delivered through various methods, including…
The TamperedChef malware campaign has been identified as targeting organizations in healthcare, construction, and manufacturing sectors by distributing malicious software disguised as legitimate applications. Attackers…
The North Korean hacker group Konni is utilizing AI-generated PowerShell malware to target developers and engineers in the blockchain sector. This campaign is linked to APT37 and Kimsuky activity clusters, with Konni…
The Open VSX registry faced a supply chain attack after access tokens were leaked, allowing threat actors to publish malicious extensions. The GlassWorm malware campaign has returned with new extensions targeting…
The APT24 threat group, linked to China, has been conducting a cyberespionage campaign utilizing a newly discovered malware called BadAudio. This campaign has targeted over 20 legitimate public websites to deliver the…
The Rhysida ransomware group is exploiting fake advertisements for Microsoft Teams to distribute malware, specifically targeting users searching for the software. This campaign employs malvertising techniques,…
The Open VSX registry experienced a security incident where access tokens were leaked by developers in public repositories. This exposure allowed threat actors to publish malicious extensions, affecting projects with…
In late December 2025, EmEditor, a widely used text and code editor, reported that its download page had been compromised. This incident involved a watering hole attack that aimed to distribute multistage malware…
The Rhysida ransomware gang is exploiting fake ads for Microsoft Teams to distribute malware. Users searching for Microsoft Teams may encounter these deceptive links, which lead to data exfiltration or encryption…