Related Threat Clusters
-
Lazarus Group Exploits Windows Zero-Day to Target Defense Sector
The North Korean hacking group Lazarus exploited a zero-day vulnerability (CVE-2026-68820) in the Windows Ancillary Function Driver for WinSock (afd.sys) to gain SYSTEM-level access to defense sector systems. This…
33 articles · Updated August 12, 2026 -
Chinese APT CL-STA-1062 Deploys TinyRCT Backdoor Against Southeast Asian Targets
The Chinese-speaking threat group CL-STA-1062 has been actively deploying a new .NET backdoor named TinyRCT against government and critical energy infrastructure in Southeast Asia throughout 2025. This campaign utilizes…
6 articles · Updated June 26, 2026 -
Russian GRU Hackers Use Fake CAPTCHAs to Compromise Ukrainian Users
Ukraine's CERT-UA reported that the Russian GRU-linked hacking group Sandworm is employing fake CAPTCHA prompts to trick users into executing malicious PowerShell commands on their devices. This method, known as…
2 articles · Updated July 21, 2026 -
Tortoiseshell Expands Malware Arsenal with New Backdoor and SSH Tunneling Tool
The Iranian-linked Tortoiseshell APT group has expanded its malware toolkit, introducing a new backdoor and reverse SSH tunneling utility. Group-IB Threat Intelligence identified these developments following a report by…
6 articles · Updated August 26, 2026 -
China-Linked Cyber Espionage Targets India's Tax Ecosystem
Seqrite has reported a cyber-espionage campaign named Operation DragonReturn, targeting India's taxpayer ecosystem by impersonating the Income Tax Department during the income tax return (ITR) filing season. The…
2 articles · Updated August 31, 2026 -
Russia's Bauman University: Training Ground for GRU Hackers and Spies
Bauman Moscow State Technical University is revealed to host a secret department training students for the GRU, Russia's military intelligence. Leaked documents show that over 2,000 students have been trained in…
15 articles · Updated May 7, 2026 -
ScarCruft's Supply-Chain Attack Targets Yanbian Gaming Platform with BirdCall Malware
ESET researchers reported a supply-chain attack by the North Korean APT group ScarCruft, targeting a gaming platform in the Yanbian region of China. The attack, ongoing since late 2024, involved trojanizing both Windows…
10 articles · Updated May 5, 2026 -
New NarwhalRAT Malware Targets Korean Users via Phishing Emails
A new malware named NarwhalRAT has been discovered targeting Korean users through phishing emails impersonating the Microsoft security team. The malware, linked to the North Korean hacking group APT37, can perform over…
9 articles · Updated June 15, 2026 -
Mirage Kitten Malware Targets Middle East and Africa with New Toolset
The Mirage Kitten APT group has deployed a sophisticated malware suite, including the NightLedger backdoor, across the Middle East and Africa. This campaign has successfully infiltrated sensitive sectors such as…
2 articles · Updated July 30, 2026 -
Showboat Malware Targets Telecoms in China-Aligned Cyber Espionage Campaign
A new Linux malware family named Showboat has been discovered, targeting telecommunications firms primarily in the Middle East and Central Asia since mid-2022. Researchers from Lumen's Black Lotus Labs and PwC…
9 articles · Updated May 21, 2026
Recent Intelligence Reports
- ValleyRAT: When Legitimate Software Becomes a Malware Delivery Tool — Securityaffairs.Co · August 31, 2026
- ValleyRAT Backdoor Hides in Signed Adware That Users Add to Antivirus Exclusions — Thehackernews · August 31, 2026
- Suspected China-linked espionage campaign targets India's finance ecosystem: Seqrite — Crnasia · August 31, 2026
- Seqrite Uncovers China-Linked Cyber Espionage Campaign Targeting India's Tax Ecosystem — Itvoice.In · August 31, 2026
- Warning: Two particularly dangerous malware strains. — Vietnam.Vn · August 27, 2026
- Securelist — securelist.com · August 26, 2026
- Hanoi police warn of a particularly dangerous strain of malware. — Vietnam.Vn · August 26, 2026
- 'Grandoreiro' Malware Resurfaces With Mexico Campaign — Darkreading · August 20, 2026