T1071.004 - DNS is a mitre_attack tracked by ThreatCluster, appearing in 27 threat clusters built from 37 intelligence report mentions.
T1071.004 - DNS is a mitre_attack tracked across 27 threat clusters and 37 intelligence report mentions on ThreatCluster. First observed January 19, 2026; most recent activity July 23, 2026.
A joint advisory from 21 global cybersecurity agencies warns that Russian state hackers from the FSB's Center 16 are exploiting poorly configured routers to infiltrate critical infrastructure networks worldwide. The…
A newly identified APT group, Armored Likho, is conducting a phishing campaign targeting government agencies and electric power sectors in Russia, Brazil, and Kazakhstan. The group employs a sophisticated infostealer…
Russian cyber group APT28, also known as Fancy Bear, has been exploiting vulnerabilities in TP-Link and MikroTik routers to conduct large-scale DNS hijacking operations. This campaign, which has affected over 18,000…
In early 2026, the Iranian APT group MuddyWater launched cyberattacks against U.S. banking, a major airport, and Israeli operations of a U.S.-based software company. The attacks intensified in March, coinciding with…
From mid-2024 to early 2026, the Vietnam-aligned APT group OceanLotus has intensified its focus on domestic espionage, utilizing the SPECTRALVIPER backdoor in two major campaigns. The first campaign targeted a…
On March 12, 2026, Zscaler ThreatLabz reported a campaign by the Tropic Trooper APT targeting Chinese-speaking individuals in Taiwan, Japan, and South Korea. The attack involved a malicious ZIP archive containing…
In 2024, Iranian APT group BladedFeline launched a cyber campaign against Kurdish and Iraqi government officials, utilizing advanced malware tools including the Shahmaran backdoor and the Whisper backdoor. The attacks…
The SUNBURST backdoor, discovered by FireEye, exploits trojanized updates to SolarWinds Orion software, affecting numerous public and private organizations globally. The attack vector involves a malicious DLL,…
In 2026, Iranian APT groups, notably Cavern Manticore and OilRig, have intensified cyber operations against Israeli organizations, primarily in the IT and government sectors. Cavern Manticore employs a modular…
AWS has highlighted the risks associated with unmonitored outbound traffic in cloud environments, particularly in light of the CVE-2025-55182 vulnerability affecting React Server Components. This vulnerability allows…
T1071.004 - DNS is a mitre_attack tracked by ThreatCluster, appearing in 27 threat clusters built from 37 intelligence report mentions.
The most recent intelligence report mentioning T1071.004 - DNS on ThreatCluster is dated July 23, 2026. Activity was first observed January 19, 2026, giving a tracked span from then to July 23, 2026.
Across ThreatCluster reporting, T1071.004 - DNS most frequently co-occurs with Apt28, Apt32, Apt34, Apt36, APT41, among 12 tracked related entities.
The most significant recent cluster is “Russian FSB Exploits Vulnerable Routers to Target Critical Infrastructure” (76 articles · Updated July 13, 2026). T1071.004 - DNS appears across 27 threat clusters in total, listed above with sources.
T1071.004 - DNS appears in 37 intelligence report mentions across 27 deduplicated threat clusters, aggregated from 17,000+ monitored sources.