Related Threat Clusters
-
Lazarus Group Exploits Windows Zero-Day to Target Defense Sector
The North Korean hacking group Lazarus exploited a zero-day vulnerability (CVE-2026-68820) in the Windows Ancillary Function Driver for WinSock (afd.sys) to gain SYSTEM-level access to defense sector systems. This…
33 articles · Updated August 12, 2026 -
Exploitation of WinRAR CVE-2025-8088 Threatens Ukrainian Organizations
Two Russia-aligned cyber campaigns are exploiting the WinRAR vulnerability CVE-2025-8088 against Ukrainian targets nearly a year after it was patched. The flaw, a path traversal vulnerability, allows attackers to write…
19 articles · Updated June 8, 2026 -
EU Sanctions Russia Over Ongoing Cyber Espionage Campaign
The European Union has condemned and sanctioned Russia for a prolonged cyber espionage campaign targeting its member states. The campaign, orchestrated by the 16th Centre of the FSB, has involved infiltrating government…
172 articles · Updated July 13, 2026 -
Jewelbug APT Group Engages in Espionage and Cryptocurrency Fraud
The Jewelbug APT group, based in China, has been conducting simultaneous cyber espionage and cryptocurrency fraud operations. Utilizing a single command-and-control platform named XG-Web, the group has compromised over…
15 articles · Updated August 13, 2026 -
Iranian Hackers Target US Aviation with New Malware and SEO Poisoning
Iranian state-aligned hackers, known as Nimbus Manticore (UNC1549), have intensified cyberattacks against the US aviation sector amid the ongoing US-Iran military conflict. Utilizing career-themed phishing and a novel…
6 articles · Updated May 26, 2026 -
Chinese APT CL-STA-1062 Deploys TinyRCT Backdoor Against Southeast Asian Targets
The Chinese-speaking threat group CL-STA-1062 has been actively deploying a new .NET backdoor named TinyRCT against government and critical energy infrastructure in Southeast Asia throughout 2025. This campaign utilizes…
6 articles · Updated June 26, 2026 -
MuddyWater Targets U.S. Entities Amid Geopolitical Tensions
In early 2026, the Iranian APT group MuddyWater launched cyberattacks against U.S. banking, a major airport, and Israeli operations of a U.S.-based software company. The attacks intensified in March, coinciding with…
16 articles · Updated July 22, 2026 -
Operation TrueChaos: Exploitation of TrueConf Zero-Day Vulnerability
In early 2026, a series of targeted attacks named Operation TrueChaos exploited a zero-day vulnerability in TrueConf software, tracked as CVE-2026-3502, which allows attackers to execute arbitrary files on connected…
5 articles · Updated April 1, 2026 -
UAC-0099 Exploits Notepad++ to Distribute Malware in Ukraine
Ukrainian CERT has identified a cyber campaign attributed to the UAC-0099 threat cluster, which targets organizations in Ukraine using the legitimate Notepad++ application to distribute malware. The attackers deliver a…
8 articles · Updated July 23, 2026 -
Tortoiseshell Expands Malware Arsenal with New Backdoor and SSH Tunneling Tool
The Iranian-linked Tortoiseshell APT group has expanded its malware toolkit, introducing a new backdoor and reverse SSH tunneling utility. Group-IB Threat Intelligence identified these developments following a report by…
6 articles · Updated August 26, 2026
Recent Intelligence Reports
- ValleyRAT: When Legitimate Software Becomes a Malware Delivery Tool — Securityaffairs.Co · August 31, 2026
- Attack hides malware in PNGs and drops custom reverse tunnel on victims' machines — Theregister · August 31, 2026
- Communication Channel Identity Risks — unit42.paloaltonetworks.com · August 31, 2026
- ValleyRAT Backdoor Hides in Signed Adware That Users Add to Antivirus Exclusions — Thehackernews · August 31, 2026
- DLL sideloading — encyclopedia.kaspersky.com · August 31, 2026
- ValleyRAT masquerading as adware — Securelist · August 31, 2026
- TerminalFix Uses Fake CAPTCHA, DLL Sideloading and Steganography to Breach Networks — Gbhackers · August 31, 2026
- PSIRT WatchGuard CVE-2026-13086 — psirt.watchguard.com · August 29, 2026