Discord is a technology platform tracked across 50 threat clusters and 128 intelligence report mentions on ThreatCluster. First observed November 20, 2025; most recent activity July 26, 2026.
In early 2026, the Iranian APT group MuddyWater launched cyberattacks against U.S. banking, a major airport, and Israeli operations of a U.S.-based software company. The attacks intensified in March, coinciding with…
The Google Threat Intelligence Group (GTIG) reports that North Korean threat actor UNC5342 has adopted a new technique called EtherHiding to deliver malware and facilitate cryptocurrency theft. This method embeds…
The China-aligned APT group Webworm has shifted its focus from Asia to Europe, targeting government organizations in Belgium, Italy, Poland, Serbia, and Spain during 2025. ESET researchers identified new backdoors,…
The TeamPCP threat group has expanded its supply chain attack campaign, compromising the Microsoft DurableTask Python client with versions v1.4.1, v1.4.2, and v1.4.3 found to contain a credential-stealing worm. This…
Researchers at SOCRadar have identified a new social engineering campaign by North Korea's Famous Chollima group, targeting Web3 and cryptocurrency professionals. The operation, dubbed ClickFake, employs fraudulent job…
Torg Grabber, a new infostealer malware, is actively targeting 728 cryptocurrency wallet extensions and other applications, including password managers and communication tools. The malware employs the ClickFix technique…
Bitdefender has reported a new AI-driven attack model termed 'vibeware', which generates numerous disposable malware variants. This tactic is linked to APT36 (Transparent Tribe), a Pakistan-aligned threat actor that has…
In March 2026, cybersecurity researchers discovered CrystalX RAT, a new malware-as-a-service (MaaS) being promoted in private Telegram channels. This malware offers a wide range of capabilities, including remote access,…
A new threat actor, JINX-0164, has been identified targeting cryptocurrency firms using custom macOS malware and social engineering tactics. Active since mid-2025, the group employs fake recruiter approaches to gain…
A malicious campaign has exploited vulnerable OpenWebUI servers, turning them into a network of cryptocurrency mining machines and information stealers. The campaign has been active since late 2024, affecting thousands…