T1574.001 - DLL is a mitre_attack tracked by ThreatCluster, appearing in 21 threat clusters built from 23 intelligence report mentions.
T1574.001 - DLL is a mitre_attack tracked across 21 threat clusters and 23 intelligence report mentions on ThreatCluster. First observed February 4, 2026; most recent activity July 21, 2026.
Iranian state-aligned hackers, known as Nimbus Manticore (UNC1549), have intensified cyberattacks against the US aviation sector amid the ongoing US-Iran military conflict. Utilizing career-themed phishing and a novel…
Russian cyber group APT28, also known as Fancy Bear, has been exploiting vulnerabilities in TP-Link and MikroTik routers to conduct large-scale DNS hijacking operations. This campaign, which has affected over 18,000…
A months-long espionage campaign linked to the Chinese group Mustang Panda has been identified, utilizing an updated variant of the FDMTP backdoor. This campaign, tracked by Darktrace, began in late September 2025 and…
APT-C-20, also known as Fancy Bear or APT28, has launched a new intrusion campaign utilizing advanced techniques to evade detection. The group employs LSB steganography to hide shellcode within PNG images, allowing them…
In 2026, Iranian APT groups, notably Cavern Manticore and OilRig, have intensified cyber operations against Israeli organizations, primarily in the IT and government sectors. Cavern Manticore employs a modular…
ESET researchers have identified two new Windows variants of the SprySOCKS backdoor, previously exclusive to Linux, attributed to the Chinese cyberespionage group FishMonger. The variants, labeled WIN_DRV and WIN_PLUS,…
SAP has released security updates addressing 16 vulnerabilities, including three critical flaws in its NetWeaver, Commerce Cloud, and AppRouter products. The most severe, CVE-2026-44747, allows authenticated attackers…
In July 2026, Zscaler ThreatLabz identified a targeted cyber campaign by an East Asian threat actor against government entities in the Middle East. The attack utilized a multi-stage chain to compromise systems,…
In June 2026, Mustang Panda launched two espionage campaigns targeting India's hydropower sector and government entities. The attacks utilized lure documents related to cooperation agreements with Taiwan, delivering…
A new malware family named SharkLoader has been discovered, linked to a campaign called StrikeShark, which targets various sectors, including a diplomatic organization in Indonesia. SharkLoader acts as a loader to…
T1574.001 - DLL is a mitre_attack tracked by ThreatCluster, appearing in 21 threat clusters built from 23 intelligence report mentions.
The most recent intelligence report mentioning T1574.001 - DLL on ThreatCluster is dated July 21, 2026. Activity was first observed February 4, 2026, giving a tracked span from then to July 21, 2026.
Across ThreatCluster reporting, T1574.001 - DLL most frequently co-occurs with Apt28, Cl-unk-1068, Fancy Bear, Fishing Elephant, Forest Blizzard, among 12 tracked related entities.
The most significant recent cluster is “Iranian Hackers Target US Aviation with New Malware and SEO Poisoning” (6 articles · Updated May 26, 2026). T1574.001 - DLL appears across 21 threat clusters in total, listed above with sources.
T1574.001 - DLL appears in 23 intelligence report mentions across 21 deduplicated threat clusters, aggregated from 17,000+ monitored sources.