Tor is a technology platform tracked across 50 threat clusters and 79 intelligence report mentions on ThreatCluster. First observed November 6, 2025; most recent activity July 25, 2026.
Ukraine's CERT-UA reported that the Russian GRU-linked hacking group Sandworm is employing fake CAPTCHA prompts to trick users into executing malicious PowerShell commands on their devices. This method, known as…
On July 14, 2026, the US Justice Department unsealed an indictment against three Russian nationals—Alexander Volosovik, Kirill Zatolokin, and Yulia Pankova—accused of operating bulletproof hosting services that…
ESET's latest APT Activity Report reveals that from October 2025 to March 2026, China-aligned threat actors engaged in extensive espionage campaigns, particularly in Venezuela and the Gulf region. Following U.S.…
In March 2026, a suspected Iranian APT group, identified as Gray Sandstorm, initiated a password spraying campaign targeting Microsoft 365 accounts of over 300 organizations in Israel and more than 25 in the UAE. The…
The Cloud Atlas APT group has been observed employing a sophisticated cyber espionage campaign targeting government and commercial entities in Russia and Belarus. This campaign, active since 2025 and continuing into…
The JDY botnet, linked to Chinese state-sponsored actors, has expanded to over 1,500 compromised small office and IoT devices, primarily in the U.S. and Brazil. This botnet scans for newly disclosed vulnerabilities…
Cloud Atlas, an advanced persistent threat group, has intensified its cyberespionage activities against government and commercial entities in Russia and Belarus since late 2025. The group employs phishing emails…
The Tails operating system has released version 7.8.1 as an emergency update to address critical security vulnerabilities in the Linux kernel and the Tor client. The update includes the Linux kernel version 6.12.90-2,…
On April 15, 2026, Tails released version 7.6.2 as an emergency update to address a significant security vulnerability in the Tor Browser's confinement. This vulnerability could potentially be exploited by an attacker…
Sandworm (APT-C-13), a state-sponsored cyber threat group, has advanced its tactics by employing SSH-over-Tor tunneling to maintain long-term, covert access to targeted networks. This new technique represents a…