HTA is a technology platform tracked across 3 threat clusters and 3 intelligence report mentions on ThreatCluster. First observed January 26, 2026; most recent activity July 16, 2026.
A Russian threat actor known as UAT-11795 has been deploying the Starland RAT and WLDR agent since June 2025, primarily targeting users in the U.S., Germany, Romania, and Venezuela. The group uses trojanized installers…
A multi-stage phishing campaign has been detected distributing the XWorm remote access trojan (RAT) via malicious Excel attachments. The attack leverages CVE-2018-0802 in Microsoft Equation Editor to execute a fileless…
PeckBirdy is a JScript-based command-and-control framework utilized by China-aligned APT groups to exploit LOLBins. Since 2023, it has been deployed against gambling industries and Asian government entities, delivering…