Related Threat Clusters
-
Mirage Kitten Targets Aviation and FinTech with New Cross-Platform Malware
The Iranian cyberespionage group Mirage Kitten has launched a campaign targeting technology professionals in the aviation and FinTech sectors across the Middle East and Africa. This operation involves the use of two…
6 articles · Updated September 1, 2026 -
Critical cPanel Vulnerability Exploited in Southeast Asia Cyber Attacks
A sophisticated cyber campaign has exploited a critical cPanel vulnerability (CVE-2026-41940) to breach government and military servers in Southeast Asia, particularly targeting Indonesia. The attackers utilized a…
3 articles · Updated May 4, 2026 -
Operation Endgame Disrupts Evil Corp's SocGholish Malware Network
On June 18, 2026, international law enforcement agencies launched Operation Endgame, disrupting the SocGholish malware infrastructure linked to the Russian cybercrime group Evil Corp. The operation resulted in the…
67 articles · Updated June 18, 2026 -
Jewelbug APT Group Engages in Espionage and Cryptocurrency Fraud
The Jewelbug APT group, based in China, has been conducting simultaneous cyber espionage and cryptocurrency fraud operations. Utilizing a single command-and-control platform named XG-Web, the group has compromised over…
15 articles · Updated August 13, 2026 -
Chinese APT CL-STA-1062 Deploys TinyRCT Backdoor Against Southeast Asian Targets
The Chinese-speaking threat group CL-STA-1062 has been actively deploying a new .NET backdoor named TinyRCT against government and critical energy infrastructure in Southeast Asia throughout 2025. This campaign utilizes…
6 articles · Updated June 26, 2026 -
MuddyWater Targets U.S. Entities Amid Geopolitical Tensions
In early 2026, the Iranian APT group MuddyWater launched cyberattacks against U.S. banking, a major airport, and Israeli operations of a U.S.-based software company. The attacks intensified in March, coinciding with…
16 articles · Updated July 22, 2026 -
Rapid7 Reports State-Sponsored Espionage in Global Telecoms
Rapid7 Labs has identified a sustained espionage campaign by a China-nexus threat actor, Red Menshen, targeting global telecommunications infrastructure. The research, titled 'Sleeper Cells in the Telecom Backbone,'…
4 articles · Updated March 26, 2026 -
Fire Ant Threat Actor Targets Trusted Infrastructure in 2026
The China-nexus threat actor known as Fire Ant has evolved its tactics in 2026, transitioning from targeting VMware hypervisors to compromising trusted infrastructure, including Cisco routers, TACACS authentication…
20 articles · Updated August 30, 2026 -
ShinyHunters Exploits Oracle PeopleSoft Zero-Day Vulnerability
A critical zero-day vulnerability (CVE-2026-35273) in Oracle PeopleSoft has been exploited by the ShinyHunters group, leading to breaches of over 100 organizations, primarily in the education sector. The vulnerability…
65 articles · Updated June 11, 2026 -
Kimsuky Exploits South Korean Groupware Vendors with New Gomir Variants
The Kimsuky group, linked to North Korea, targeted South Korean groupware vendors from late 2025 to early 2026, deploying new malware variants BirdTroy and DriveTroy. These Linux backdoors utilized Google Drive for…
4 articles · Updated July 24, 2026
Recent Intelligence Reports
- New Linux toolkit found in trojanized HAProxy targeting South Korean organizations — Scworld · September 4, 2026
- New Ted Backdoor Hides Inside Victims' Own HAProxy Builds to Intercept Web Traffic — Thehackernews · September 4, 2026
- Contagious Interview Operators Move Beyond Git Hooks With Trojanized Mac Applications — Gbhackers · September 4, 2026
- New browser malware uses remote commands to control Windows systems — Scworld · September 4, 2026
- From the frontline: Ukraine's cyber security learnings for EU founders | EU — Eu-Startups · September 3, 2026
- Microsoft identifies 'TerminalFix' campaign spreading Python reverse tunnel — Scworld · September 2, 2026
- Fake Software Update Installs a Real Crypto Wallet — Itsecurityguru · September 2, 2026
- Hackers Hide a Full Remote Access Trojan Inside a Real Exodus Crypto Wallet — Cybersecuritynews · September 2, 2026