Related Threat Clusters
-
Gamaredon Exploits WinRAR Vulnerability in Ongoing Ukraine Campaign
Gamaredon, a Russian state-backed APT group, is actively exploiting a WinRAR vulnerability (CVE-2025-8088) to deploy malware against Ukrainian government and military targets. The attack begins with a spearphishing…
7 articles · Updated June 2, 2026 -
Gamaredon APT Escalates Cyber Operations Against Ukraine in 2025
The Gamaredon group, a Russian-aligned APT, has significantly upgraded its cyber capabilities in 2025, focusing on spear-phishing campaigns against Ukrainian targets. ESET Research reports that Gamaredon conducted 35…
7 articles · Updated June 25, 2026 -
MuddyWater Targets U.S. Entities Amid Geopolitical Tensions
In early 2026, the Iranian APT group MuddyWater launched cyberattacks against U.S. banking, a major airport, and Israeli operations of a U.S.-based software company. The attacks intensified in March, coinciding with…
16 articles · Updated July 22, 2026 -
Russian GRU Hackers Use Fake CAPTCHAs to Compromise Ukrainian Users
Ukraine's CERT-UA reported that the Russian GRU-linked hacking group Sandworm is employing fake CAPTCHA prompts to trick users into executing malicious PowerShell commands on their devices. This method, known as…
2 articles · Updated July 21, 2026 -
Massive Ransomware Attack Targets Critical Infrastructure in March 2026
In March 2026, a sophisticated ransomware attack impacted multiple critical infrastructure sectors across the United States, including energy and healthcare. The attack exploited vulnerabilities in outdated software…
2 articles · Updated March 12, 2026 -
ScarCruft's Supply-Chain Attack Targets Yanbian Gaming Platform with BirdCall Malware
ESET researchers reported a supply-chain attack by the North Korean APT group ScarCruft, targeting a gaming platform in the Yanbian region of China. The attack, ongoing since late 2024, involved trojanizing both Windows…
10 articles · Updated May 5, 2026 -
Webworm APT Expands Operations to Europe with New Backdoors
The China-aligned APT group Webworm has shifted its focus from Asia to Europe, targeting government organizations in Belgium, Italy, Poland, Serbia, and Spain during 2025. ESET researchers identified new backdoors,…
12 articles · Updated May 20, 2026 -
China-Nexus Hackers Target Hospitals and Governments with TriBack Loader Malware
A China-linked cyber espionage operation has compromised a Vietnamese public hospital's imaging systems, infiltrated Malaysia's Ministry of Foreign Affairs, and targeted Honduras's National Congress using a new malware…
2 articles · Updated July 23, 2026 -
Critical Vulnerability in Cline Kanban Exposes AI Coding Agents to Hijacking
A critical vulnerability (CVSS 9.7) in the Cline Kanban server allows any website a developer visits to silently exfiltrate workspace data and inject commands into the AI agent's terminal. This flaw affects version…
5 articles · Updated May 7, 2026 -
BLUERABBIT Backdoor Targets Windows Systems with Encryption and Wiping Capabilities
The BLUERABBIT backdoor, a Golang-based malware, has been identified targeting Windows systems since March 2026. It combines data theft, file encryption, and destructive disk wiping, primarily affecting Israeli…
2 articles · Updated June 11, 2026
Recent Intelligence Reports
- McKesson discloses breach after ShinyHunters claims patient data theft — Bleepingcomputer · August 28, 2026
- How AI Coding Agents Can Accidentally Leak Your Secrets — Hackernoon · August 24, 2026
- Cryptographic Context Injection Grok Data Theft — adversa.ai · August 20, 2026
- Storm-0501 — attack.mitre.org · August 18, 2026
- Akira hackers disable EDR with Safe Mode, steal data but fail to encrypt — Bleepingcomputer · August 13, 2026
- Akira Affiliate Crashes Ransomware After Attempting EDR Evasion — Infosecurity-Magazine · August 13, 2026
- Uber Freight reportedly investigating after hacking group claims data breach — Techcrunch · August 12, 2026
- Wesco Cloud CRM Data Breach: ExfilSquad Data Theft and Supply Chain Risks Analyzed — Rescana · August 12, 2026