T1069.002 - Domain Groups - MITRE ATT&CK

Threat entity extracted from intelligence sources

Frequency
9
occurrences
First Seen
June 2, 2026
Last Seen
August 12, 2026

Related Threat Clusters

  • StrikeShark Campaign Unleashes SharkLoader Malware to Deploy Cobalt Strike

    A new malware family named SharkLoader has been discovered, linked to a campaign called StrikeShark, which targets various sectors, including a diplomatic organization in Indonesia. SharkLoader acts as a loader to…

    14 articles · Updated June 25, 2026
  • AI-Driven Malware Framework Automates EDR Evasion Tactics

    Sophos X-Ops analysts uncovered a threat actor utilizing AI technologies to develop a malware-testing framework aimed at evading endpoint detection and response (EDR) systems. The activity was detected on June 2, 2026,…

    16 articles · Updated June 2, 2026
  • New Mistic Backdoor Linked to Ransomware Access Broker Activity

    A new backdoor known as Mistic has been identified in cyberattacks targeting various sectors since April 2026. It is associated with the initial access broker KongTuke, also known as Woodgnat, which sells access to…

    21 articles · Updated June 24, 2026
  • FortiBleed Campaign: AI-Driven Exploitation of Fortinet Firewalls

    The FortiBleed campaign exposed valid credentials for nearly 75,000 Fortinet FortiGate firewalls across 21,632 domains. Threat actors leveraged commoditized supercomputing resources to execute massive cryptographic…

    2 articles · Updated June 21, 2026
  • AI-Generated PowerShell Script Used for Active Directory Reconnaissance

    A threat actor employed an AI-generated PowerShell script to conduct reconnaissance in a compromised Active Directory environment. The attack began with unauthorized access to a domain-joined Windows Server via Remote…

    2 articles · Updated July 14, 2026
  • Ransomware Fuels Surge in Global Cyberattacks

    As of February 12, 2026, organizations worldwide are experiencing an average of 2,090 cyber-attacks per week, largely driven by ransomware incidents. This increase highlights the ongoing challenges faced by businesses…

    1874 articles · Updated February 12, 2026
  • Akira Ransomware Uses Safe Mode to Evade EDR Detection

    In early August 2026, an Akira ransomware affiliate executed an attack leveraging Safe Mode to evade endpoint detection and response (EDR) tools. The attack began with credential spraying against an exposed SonicWall…

    11 articles · Updated August 12, 2026
  • Adaptavist Group Breach: Ransomware Claims Major Data Theft

    The Adaptavist Group, a UK enterprise software consultancy, is investigating a security breach that occurred in late March 2026, when an attacker gained unauthorized access using stolen credentials. CEO Simon…

    4 articles · Updated April 21, 2026

Recent Intelligence Reports

  • Akira ransomware attacker uses Safe Mode reboot to evade EDR | news — Scworld · August 12, 2026
  • Unmasking The Gentlemen Ransomware — www.trendmicro.com · August 8, 2026
  • Attacker Used AI to Build Custom PowerShell Recon Malware — Securityaffairs.Co · July 14, 2026
  • StrikeShark Campaign Uses New SharkLoader Malware to Deploy Cobalt Strike Beacon — Gbhackers · June 25, 2026
  • Backdoor.Mistic: New Backdoor May be Linked to Ransomware Access Broker — Security · June 24, 2026
  • Nation — Infostealers · June 21, 2026
  • Attackers Use AI Tools to Automate Active Directory Attacks | Let's Data Science — Letsdatascience · June 3, 2026
  • Pointing a Cursor at evading detection — News.Sophos · June 2, 2026

CVSS v3.1 Breakdown