Related Threat Clusters
-
Gamaredon Exploits WinRAR Vulnerability in Ongoing Ukraine Campaign
Gamaredon, a Russian state-backed APT group, is actively exploiting a WinRAR vulnerability (CVE-2025-8088) to deploy malware against Ukrainian government and military targets. The attack begins with a spearphishing…
7 articles · Updated June 2, 2026 -
GhostShell Malware Targets Ukraine's UAV and Defense Supply Chain
The GhostShell malware cluster is actively targeting Ukraine’s UAV operations and defense supply chain. Utilizing advanced techniques such as mTLS-authenticated implants and Telegram-based loaders, the attackers gain…
2 articles · Updated June 25, 2026 -
Gamaredon APT Escalates Cyber Operations Against Ukraine in 2025
The Gamaredon group, a Russian-aligned APT, has significantly upgraded its cyber capabilities in 2025, focusing on spear-phishing campaigns against Ukrainian targets. ESET Research reports that Gamaredon conducted 35…
7 articles · Updated June 25, 2026 -
Armored Likho APT Targets Power Grids with BusySnake Stealer Malware
A newly identified APT group, Armored Likho, is conducting a phishing campaign targeting government agencies and electric power sectors in Russia, Brazil, and Kazakhstan. The group employs a sophisticated infostealer…
7 articles · Updated July 4, 2026 -
APT28 Exploits Vulnerable Routers for Global DNS Hijacking Campaign
Russian cyber group APT28, also known as Fancy Bear, has been exploiting vulnerabilities in TP-Link and MikroTik routers to conduct large-scale DNS hijacking operations. This campaign, which has affected over 18,000…
100 articles · Updated April 7, 2026 -
MuddyWater Targets U.S. Entities Amid Geopolitical Tensions
In early 2026, the Iranian APT group MuddyWater launched cyberattacks against U.S. banking, a major airport, and Israeli operations of a U.S.-based software company. The attacks intensified in March, coinciding with…
16 articles · Updated July 22, 2026 -
Russian GRU Hackers Use Fake CAPTCHAs to Compromise Ukrainian Users
Ukraine's CERT-UA reported that the Russian GRU-linked hacking group Sandworm is employing fake CAPTCHA prompts to trick users into executing malicious PowerShell commands on their devices. This method, known as…
2 articles · Updated July 21, 2026 -
UAC-0099 Exploits Notepad++ to Distribute Malware in Ukraine
Ukrainian CERT has identified a cyber campaign attributed to the UAC-0099 threat cluster, which targets organizations in Ukraine using the legitimate Notepad++ application to distribute malware. The attackers deliver a…
8 articles · Updated July 23, 2026 -
Supply Chain Attack Compromises Popular Rust Crates to Deliver Malware
On August 20, 2026, a supply chain attack targeted the Rust ecosystem, compromising the widely used crates arrayref, append-only-vec, and internment. The attackers injected a malicious dependency, proc-macro1, which…
22 articles · Updated August 20, 2026 -
North Korean Hackers Target macOS Users in Cryptocurrency Theft Campaign
A sophisticated malware campaign targeting macOS users has been linked to North Korean threat group Sapphire Sleet. This operation focuses on cryptocurrency organizations, venture capital firms, and Web3 developers.…
2 articles · Updated June 3, 2026
Recent Intelligence Reports
- Can 'Gold Eagle' Stay Ahead of Hackers? — Californiaglobe · August 31, 2026
- CRPx0 - Threat Actor Profile — Kelacyber · August 26, 2026
- Hackers Hide Agent Tesla Malware Behind Emojis to Steal Browser and Email Passwords — Gbhackers · August 21, 2026
- Hackers poison arrayref Rust crate to push infostealer malware — Bleepingcomputer · August 20, 2026
- Malicious Rust Crate Arrayref Runs a Build — News.Ycombinator · August 20, 2026
- Cyber Conflict Decoy Document — blog.talosintelligence.com · August 19, 2026
- Fake AI, real malware: Attackers impersonating AI brands — News.Sophos · August 19, 2026
- MacSync Stealer: How a Google Search for Claude Led to a macOS Infostealer — Huntress · August 17, 2026