Related Threat Clusters
-
Jewelbug APT Group Engages in Espionage and Cryptocurrency Fraud
The Jewelbug APT group, based in China, has been conducting simultaneous cyber espionage and cryptocurrency fraud operations. Utilizing a single command-and-control platform named XG-Web, the group has compromised over…
15 articles · Updated August 13, 2026 -
OceanLotus Shifts Focus to Domestic Espionage with SPECTRALVIPER Attacks
From mid-2024 to early 2026, the Vietnam-aligned APT group OceanLotus has intensified its focus on domestic espionage, utilizing the SPECTRALVIPER backdoor in two major campaigns. The first campaign targeted a…
17 articles · Updated June 11, 2026 -
LongNosedGoblin and UAT-8302: New China-Aligned APT Threats Targeting Governments
In 2024, ESET identified a new China-aligned APT group named LongNosedGoblin, which targets governmental entities in Southeast Asia and Japan. The group employs a custom toolset, primarily using C#/.NET applications, to…
8 articles · Updated May 5, 2026 -
Italy Extradites Chinese Hacker Xu Zewei to the U.S. for COVID-19 Research Theft
Xu Zewei, a 33-year-old Chinese national, was extradited from Italy to the United States on April 27, 2026, following his arrest in Milan on July 3, 2025. He is accused of participating in cyberattacks directed by the…
51 articles · Updated April 26, 2026 -
Ransomware Group Targets SonicWall Gen 7 Firewalls via CVE-2024-40766
In June 2026, a surge in attacks targeting SonicWall Gen 7 firewalls has been reported, exploiting CVE-2024-40766, an improper access control flaw. This vulnerability allows threat actors to gain unauthorized access,…
2 articles · Updated June 23, 2026 -
Russian Drone Attack on Chernobyl's New Safe Confinement Raises Nuclear Safety Concerns
On February 14, 2025, a Russian drone struck the New Safe Confinement (NSC) at the Chernobyl Nuclear Power Plant, damaging its structure and raising alarms about potential radiation leaks. The NSC, designed to contain…
146 articles · Updated April 14, 2026 -
PaperCut NG/MF Vulnerability Under Active Exploitation
On August 27, 2026, PaperCut issued an urgent advisory regarding a zero-day vulnerability affecting its NG and MF print management software. This flaw allows unauthenticated attackers to execute arbitrary Java code…
50 articles · Updated August 27, 2026 -
Payload Ransomware Targets Global Organizations with ChaCha20 Encryption
Payload ransomware, first identified in February 2026, has rapidly expanded its operations, targeting logistics, real estate, and manufacturing sectors worldwide. The malware employs ChaCha20 encryption and Curve25519…
2 articles · Updated May 26, 2026 -
Torg Grabber Malware Targets 728 Crypto Wallets with Advanced Techniques
Torg Grabber, a new infostealer malware, is actively targeting 728 cryptocurrency wallet extensions and other applications, including password managers and communication tools. The malware employs the ClickFix technique…
2 articles · Updated March 27, 2026 -
Toy Ghouls Launch GenieLocker Ransomware Targeting Russian Manufacturing
The Toy Ghouls group, also known as Bearlyfy, has introduced a new ransomware called GenieLocker, active since March 2026. This ransomware targets Windows, Linux, and VMware ESXi systems, primarily affecting the…
5 articles · Updated July 30, 2026
Recent Intelligence Reports
- Patch now! Attackers targeting PaperCut NG/MF — Heise.De · August 28, 2026
- Over 500 Critical Infrastructure Organizations Hit by Medusa Ransomware — Infosecurity-Magazine · August 19, 2026
- Jewelbug Apt Russia — www.security.com · August 16, 2026
- DeadLock Ransomware Disables Windows Defender, Backups and Event Logs Before Encrypting Files — Gbhackers · August 11, 2026
- DeadLock ransomware turns recovery chat into a decentralized takedown challenge — Feeds.4Sysops · August 10, 2026
- 115909 — securelist.ru · July 30, 2026
- Go-Based Gentlemen Ransomware Uses PsExec, WMIC, and PowerShell Remoting for ... — Gbhackers · July 6, 2026
- Exploitation Of Sonicwall Vpn — www.huntress.com · June 23, 2026