Related Threat Clusters
-
Gamaredon Exploits WinRAR Vulnerability in Ongoing Ukraine Campaign
Gamaredon, a Russian state-backed APT group, is actively exploiting a WinRAR vulnerability (CVE-2025-8088) to deploy malware against Ukrainian government and military targets. The attack begins with a spearphishing…
7 articles · Updated June 2, 2026 -
Kimsuky Expands AI Capabilities for Cyberattacks
The North Korean hacking group Kimsuky has developed local AI tools to enhance its cyberattack capabilities, as reported by Genians Security Center on August 10, 2026. The group is utilizing large language models (LLMs)…
49 articles · Updated August 10, 2026 -
MuddyWater Targets U.S. Entities Amid Geopolitical Tensions
In early 2026, the Iranian APT group MuddyWater launched cyberattacks against U.S. banking, a major airport, and Israeli operations of a U.S.-based software company. The attacks intensified in March, coinciding with…
16 articles · Updated July 22, 2026 -
OceanLotus Shifts Focus to Domestic Espionage with SPECTRALVIPER Attacks
From mid-2024 to early 2026, the Vietnam-aligned APT group OceanLotus has intensified its focus on domestic espionage, utilizing the SPECTRALVIPER backdoor in two major campaigns. The first campaign targeted a…
17 articles · Updated June 11, 2026 -
Chinese APT Campaign Targets Asia-Pacific with FDMTP Backdoor
A months-long espionage campaign linked to the Chinese group Mustang Panda has been identified, utilizing an updated variant of the FDMTP backdoor. This campaign, tracked by Darktrace, began in late September 2025 and…
3 articles · Updated May 14, 2026 -
FishMonger Expands SprySOCKS Malware to Windows with Kernel-Level Stealth
ESET researchers have identified two new Windows variants of the SprySOCKS backdoor, previously exclusive to Linux, attributed to the Chinese cyberespionage group FishMonger. The variants, labeled WIN_DRV and WIN_PLUS,…
12 articles · Updated June 16, 2026 -
Evolution of Chinese-Nexus Cyber Operations: Strategic Long-Term Threats
Recent research from Darktrace reveals the evolution of Chinese-nexus cyber operations over the past two decades, highlighting a shift from high-volume attacks to more strategic, identity-centric intrusions. This change…
381 articles · Updated April 2, 2026 -
Mustang Panda Espionage Campaigns Target India's Government and Energy Sectors
In June 2026, Mustang Panda launched two espionage campaigns targeting India's hydropower sector and government entities. The attacks utilized lure documents related to cooperation agreements with Taiwan, delivering…
2 articles · Updated June 30, 2026 -
PowMix Botnet Targets Czech Organizations with Malicious LNK Files
The PowMix botnet has been identified as targeting Czech organizations since at least December 2025. Attackers use malicious LNK files to initiate a PowerShell loader that extracts a ZIP archive, bypasses AMSI…
3 articles · Updated April 17, 2026 -
StrikeShark Campaign Unleashes SharkLoader Malware to Deploy Cobalt Strike
A new malware family named SharkLoader has been discovered, linked to a campaign called StrikeShark, which targets various sectors, including a diplomatic organization in Indonesia. SharkLoader acts as a loader to…
14 articles · Updated June 25, 2026
Recent Intelligence Reports
- Jadepuffer Agentic Ransomware For Automated Database Extortion — www.sysdig.com · September 3, 2026
- Microsoft identifies 'TerminalFix' campaign spreading Python reverse tunnel — Scworld · September 2, 2026
- Kimsuky Ai Llm — www.genians.co.kr · August 12, 2026
- APT34 (OilRig): Espionage on Your Infrastructure — Kelacyber · July 22, 2026
- TrickBot Ditches HTTP for DNS Tunneling in Latest Variant — Infosecurity-Magazine · July 22, 2026
- An AI Agent Just Pulled Off a Full Ransomware Attack—and It Didn't Save the Decryption Key — Finance.Biggo · July 3, 2026
- Mustang Panda targets India's government and energy sectors with ZOHOMURK and MINIRECON — Acronis · June 29, 2026
- StrikeShark: investigating a new campaign delivering Cobalt Strike through SharkLoader — Securelist · June 24, 2026