Related Threat Clusters
-
Head Mare Hackers Exploit TrueConf Vulnerabilities to Deploy Backdoors
The Head Mare hacktivist group has breached TrueConf video conferencing servers, exploiting vulnerabilities to replace legitimate client installers with malicious versions containing backdoors. The attackers executed…
23 articles · Updated August 8, 2026 -
Exploitation of WinRAR CVE-2025-8088 Threatens Ukrainian Organizations
Two Russia-aligned cyber campaigns are exploiting the WinRAR vulnerability CVE-2025-8088 against Ukrainian targets nearly a year after it was patched. The flaw, a path traversal vulnerability, allows attackers to write…
19 articles · Updated June 8, 2026 -
Ghost CMS SQL Injection Exploits 700+ Sites in Ongoing ClickFix Campaign
A critical SQL injection vulnerability (CVE-2026-26980) in Ghost CMS is being actively exploited in a large-scale cyberattack affecting over 700 websites, including those of Harvard University, Oxford University, Auburn…
17 articles · Updated May 25, 2026 -
MuddyWater Targets U.S. Entities Amid Geopolitical Tensions
In early 2026, the Iranian APT group MuddyWater launched cyberattacks against U.S. banking, a major airport, and Israeli operations of a U.S.-based software company. The attacks intensified in March, coinciding with…
16 articles · Updated July 22, 2026 -
Destructive Lotus Wiper Targets Venezuelan Energy Sector Amid Geopolitical Tensions
In late 2025 and early 2026, a new data-wiping malware known as Lotus Wiper was identified targeting the energy and utilities sector in Venezuela. The malware was uploaded to a public platform in mid-December 2025 and…
8 articles · Updated April 21, 2026 -
FamousSparrow APT Expands Targeting to Azerbaijani Energy Sector
FamousSparrow, a China-aligned APT group, launched a multi-wave cyberespionage campaign against an Azerbaijani oil and gas company from late December 2025 to February 2026. The attackers employed an evolved DLL…
10 articles · Updated May 13, 2026 -
Iranian APT MuddyWater Uses Chaos Ransomware as a False Flag for Espionage
In early 2026, the Iranian APT group MuddyWater, affiliated with the Ministry of Intelligence and Security, executed a sophisticated cyber operation disguised as a Chaos ransomware attack. Utilizing social engineering…
17 articles · Updated May 7, 2026 -
Tropic Trooper Expands Tactics with Multi-Stage Attacks on Japanese and Taiwanese Targets
On March 12, 2026, Zscaler ThreatLabz reported a campaign by the Tropic Trooper APT targeting Chinese-speaking individuals in Taiwan, Japan, and South Korea. The attack involved a malicious ZIP archive containing…
5 articles · Updated April 24, 2026 -
QuickFox VPN Supply Chain Attack Delivers FDMTP Backdoor to Windows Users
A supply chain attack targeting the QuickFox VPN application has been uncovered, affecting Windows users. The attack, attributed to the Chinese state-sponsored group Mustang Panda, involved a trojanized version of the…
14 articles · Updated August 6, 2026 -
Void Dokkaebi's Malware Campaign Exploits Developer Repositories via Fake Job Interviews
Void Dokkaebi, a North Korean threat actor, has escalated its malware distribution tactics by using fake job interviews to compromise software developers. This campaign, known as the 'Contagious Interview,' targets…
22 articles · Updated April 22, 2026
Recent Intelligence Reports
- Start free — www.action1.com · August 28, 2026
- PavinLoader Malware Spreads via ClickFix and Fake Download Campaigns — Technadu · August 25, 2026
- 89 — cwe.mitre.org · August 25, 2026
- ClearFake Campaigns Use WordlistLoader to Deploy Amatera — Socprime · August 21, 2026
- UAT-10147: Chinese-speaking adversary integrates agentic AI into post — Blog.Talosintelligence · August 20, 2026
- C2Looper Backdoor Uses GitHub for C2 | ThreatLabz - Zscaler, Inc. — Zscaler · August 17, 2026
- Indian Air Force officials — xelemental.github.io · August 13, 2026
- PATCHCORD: New malware cluster targets Afghan telecom and South Asian critical infrastructure — Acronis · August 13, 2026