Related Threat Clusters
-
Gamaredon Exploits WinRAR Vulnerability in Ongoing Ukraine Campaign
Gamaredon, a Russian state-backed APT group, is actively exploiting a WinRAR vulnerability (CVE-2025-8088) to deploy malware against Ukrainian government and military targets. The attack begins with a spearphishing…
7 articles · Updated June 2, 2026 -
Exploitation of WinRAR CVE-2025-8088 Threatens Ukrainian Organizations
Two Russia-aligned cyber campaigns are exploiting the WinRAR vulnerability CVE-2025-8088 against Ukrainian targets nearly a year after it was patched. The flaw, a path traversal vulnerability, allows attackers to write…
19 articles · Updated June 8, 2026 -
Ghost CMS SQL Injection Exploits 700+ Sites in Ongoing ClickFix Campaign
A critical SQL injection vulnerability (CVE-2026-26980) in Ghost CMS is being actively exploited in a large-scale cyberattack affecting over 700 websites, including those of Harvard University, Oxford University, Auburn…
17 articles · Updated May 25, 2026 -
MuddyWater Targets U.S. Entities Amid Geopolitical Tensions
In early 2026, the Iranian APT group MuddyWater launched cyberattacks against U.S. banking, a major airport, and Israeli operations of a U.S.-based software company. The attacks intensified in March, coinciding with…
16 articles · Updated July 22, 2026 -
North Korean Hackers Target Open Source Software Supply Chain via npm Packages
Amazon's threat intelligence has linked a series of compromises of popular npm packages—axios, debug, chalk, and typo-crypto—to a North Korean hacking group known as Sapphire Sleet. The group employed social engineering…
11 articles · Updated July 29, 2026 -
Belarus-Aligned Ghostwriter Group Targets Ukraine with Phishing Campaign
A phishing campaign targeting Ukrainian government organizations has been attributed to the Belarus-aligned Ghostwriter group, also known as UAC-0057. The campaign involves sending emails with PDF attachments that lead…
3 articles · Updated May 22, 2026 -
Russian GRU Hackers Use Fake CAPTCHAs to Compromise Ukrainian Users
Ukraine's CERT-UA reported that the Russian GRU-linked hacking group Sandworm is employing fake CAPTCHA prompts to trick users into executing malicious PowerShell commands on their devices. This method, known as…
2 articles · Updated July 21, 2026 -
OceanLotus Shifts Focus to Domestic Espionage with SPECTRALVIPER Attacks
From mid-2024 to early 2026, the Vietnam-aligned APT group OceanLotus has intensified its focus on domestic espionage, utilizing the SPECTRALVIPER backdoor in two major campaigns. The first campaign targeted a…
17 articles · Updated June 11, 2026 -
Tropic Trooper Expands Tactics with Multi-Stage Attacks on Japanese and Taiwanese Targets
On March 12, 2026, Zscaler ThreatLabz reported a campaign by the Tropic Trooper APT targeting Chinese-speaking individuals in Taiwan, Japan, and South Korea. The attack involved a malicious ZIP archive containing…
5 articles · Updated April 24, 2026 -
Harvester APT Group Unveils New GoGra Linux Backdoor Using Microsoft Graph API
The Harvester APT group has launched a Linux variant of its GoGra backdoor, utilizing the Microsoft Graph API and Outlook mailboxes for covert command-and-control operations. This malware is designed to evade…
13 articles · Updated April 22, 2026
Recent Intelligence Reports
- VU#718077: UEFI Shell module embedded in SPI Flash can be used to bypass Secure Boot — Kb.Cert · September 8, 2026
- BSI explains first attack vector on Berlin authorities — Heise.De · September 7, 2026
- Attackers use rogue ScreenConnect clients to spread malware — Helpnetsecurity · September 7, 2026
- Analysis Of Ongoing Ousaban Attacks Targeting The Iberian Peninsula — www.fortinet.com · September 3, 2026
- Attackers Turn Trusted Node.js Runtime Into Malware Delivery Tool in Targeted Attacks — Thehackernews · September 3, 2026
- Node.js: Old Technique Makes a Comeback — Security · September 3, 2026
- Impersonating IT support: how threat actors turn a remote session into enterprise — Blogs.Microsoft · September 2, 2026
- Microsoft identifies 'TerminalFix' campaign spreading Python reverse tunnel — Scworld · September 2, 2026