T1218.005 - Mshta is a mitre_attack tracked across 24 threat clusters and 36 intelligence report mentions on ThreatCluster. First observed November 6, 2025; most recent activity July 20, 2026.
Gamaredon, a Russian state-backed APT group, is actively exploiting a WinRAR vulnerability (CVE-2025-8088) to deploy malware against Ukrainian government and military targets. The attack begins with a spearphishing…
From mid-2024 to early 2026, the Vietnam-aligned APT group OceanLotus has intensified its focus on domestic espionage, utilizing the SPECTRALVIPER backdoor in two major campaigns. The first campaign targeted a…
UAC-0184 has deployed a multi-stage malware chain that utilizes the Windows bitsadmin tool and HTA files to deliver obfuscated payloads. This campaign primarily targets Ukrainian military networks, specifically accounts…
In January 2026, the Chronus Group executed a significant data breach against the Mexican government, compromising 2.3 terabytes of sensitive data from at least 25 agencies. The breach exposed personal information of up…
On May 14, 2026, the SmartApeSG threat actor launched a supply chain attack by injecting malicious JavaScript into the Okendo Reviews widget, which is used by over 18,000 brands. This compromise allowed the delivery of…
On May 19, 2026, Microsoft disrupted Fox Tempest, a malware-signing-as-a-service (MSaaS) operation that provided over 1,000 fraudulent code-signing certificates to cybercriminals, enabling them to disguise malware as…
From late April to mid-June 2026, ACR Stealer, a malware-as-a-service operation, has ramped up its activity targeting enterprise users by stealing browser credentials, session tokens, and sensitive documents. The attack…
Kaspersky has uncovered a targeted Horabot campaign primarily affecting victims in Mexico, with 93% of the 5,384 recorded victims located there. The attack employs a fake CAPTCHA page that instructs users to execute a…
Cybercriminals are increasingly using legitimate system tools like PowerShell and WMI to deploy malware, creating stealthy threats that evade traditional defenses. The ANY.RUN Q1 2026 Cyber Risk report highlights a…
The InstallFix campaign targets users by creating fake installation pages for Anthropic's Claude AI, tricking them into executing malware. This sophisticated social engineering tactic exploits the growing reliance on AI…