Related Threat Clusters
-
Lazarus Group Exploits Windows Zero-Day to Target Defense Sector
The North Korean hacking group Lazarus exploited a zero-day vulnerability (CVE-2026-68820) in the Windows Ancillary Function Driver for WinSock (afd.sys) to gain SYSTEM-level access to defense sector systems. This…
33 articles · Updated August 12, 2026 -
Storm-1175 Deploys New StormEncryptor Ransomware Targeting N-central Systems
A financially motivated threat actor, Storm-1175, previously linked to Medusa ransomware, has begun deploying a new ransomware strain named StormEncryptor. This campaign was initiated after exploiting an…
11 articles · Updated August 10, 2026 -
Head Mare Hackers Exploit TrueConf Vulnerabilities to Deploy Backdoors
The Head Mare hacktivist group has breached TrueConf video conferencing servers, exploiting vulnerabilities to replace legitimate client installers with malicious versions containing backdoors. The attackers executed…
23 articles · Updated August 8, 2026 -
TeamPCP's CanisterWorm Targets Iranian Systems with Destructive Kubernetes Wiper
TeamPCP has launched a new cyber campaign deploying a destructive payload that targets Kubernetes clusters configured for Iran. This wiper malware, part of the ongoing CanisterWorm campaign, uses the same…
4 articles · Updated March 23, 2026 -
Critical Vulnerabilities in Yarbo Robot Firmware Expose Devices to Remote Attacks
AHA! disclosed three critical vulnerabilities in Yarbo robot firmware v2.3.9, identified as CVE-2026-7413, CVE-2026-7414, and CVE-2026-7415. The vulnerabilities include a hidden backdoor, hardcoded credentials, and an…
3 articles · Updated May 7, 2026 -
Lazarus Group Escalates Attacks with Fileless RemotePE Trojan Targeting Crypto and Banks
The Lazarus Group, a North Korea-linked cybercrime organization, has intensified its operations against financial and cryptocurrency sectors using a sophisticated fileless Remote Access Trojan (RAT) called RemotePE.…
12 articles · Updated May 25, 2026 -
MuddyWater Targets U.S. Entities Amid Geopolitical Tensions
In early 2026, the Iranian APT group MuddyWater launched cyberattacks against U.S. banking, a major airport, and Israeli operations of a U.S.-based software company. The attacks intensified in March, coinciding with…
16 articles · Updated July 22, 2026 -
Destructive Lotus Wiper Targets Venezuelan Energy Sector Amid Geopolitical Tensions
In late 2025 and early 2026, a new data-wiping malware known as Lotus Wiper was identified targeting the energy and utilities sector in Venezuela. The malware was uploaded to a public platform in mid-December 2025 and…
8 articles · Updated April 21, 2026 -
Fire Ant Threat Actor Targets Trusted Infrastructure in 2026
The China-nexus threat actor known as Fire Ant has evolved its tactics in 2026, transitioning from targeting VMware hypervisors to compromising trusted infrastructure, including Cisco routers, TACACS authentication…
8 articles · Updated August 30, 2026 -
Kimsuky Exploits South Korean Groupware Vendors with New Gomir Variants
The Kimsuky group, linked to North Korea, targeted South Korean groupware vendors from late 2025 to early 2026, deploying new malware variants BirdTroy and DriveTroy. These Linux backdoors utilized Google Drive for…
4 articles · Updated July 24, 2026
Recent Intelligence Reports
- New Ploutus Variant — cloud.google.com · August 31, 2026
- Chinese Fire Ant hackers turn Cisco routers into spying platforms — Bleepingcomputer · August 31, 2026
- Suspected China-linked espionage campaign targets India's finance ecosystem: Seqrite — Crnasia · August 31, 2026
- Seqrite Uncovers China-Linked Cyber Espionage Campaign Targeting India's Tax Ecosystem — Itvoice.In · August 31, 2026
- Zbt Darklantern Speakingstone — www.vulncheck.com · August 27, 2026
- Cambodia-focused cluster uses multistage infection chain with localized lures — Acronis · August 26, 2026
- BTR Reforged: Weaponizing Defender’s Remediation Driver as a Kernel Operation Primitive — Research.Checkpoint · August 20, 2026
- UAT-10147 deploys SPECTRE: A cross — Blog.Talosintelligence · August 20, 2026