T1219 - Remote Access Tools is a mitre_attack tracked across 6 threat clusters and 6 intelligence report mentions on ThreatCluster. First observed March 20, 2026; most recent activity July 9, 2026.
Researchers found an exposed server on a Russian bulletproof hosting provider containing a complete ransomware toolkit linked to TheGentlemen affiliate. The toolkit includes various utilities for credential dumping,…
A new phishing campaign distributing a variant of the Remcos RAT has been identified, targeting Microsoft Windows users. The attack utilizes a fake shipping document to deliver a malicious Word file that exploits…
Scattered Spider, a cybercrime entity linked to various high-profile attacks since 2022, has been reclassified as a decentralized collective rather than a unified group. Group-IB's analysis indicates that it consists of…
Recent research indicates a significant evolution in phishing tactics, with threat actors moving from generic attacks to sophisticated, platform-aware campaigns. These modern phishing operations utilize user-agent data…
As of February 12, 2026, organizations worldwide are experiencing an average of 2,090 cyber-attacks per week, largely driven by ransomware incidents. This increase highlights the ongoing challenges faced by businesses…
An open server linked to the Beast ransomware group was discovered, revealing their extensive toolkit and attack methods. This ransomware-as-a-service (RaaS) group, active since June 2024, is believed to be a successor…