Related Threat Clusters
-
Russian GRU Hackers Use Fake CAPTCHAs to Compromise Ukrainian Users
Ukraine's CERT-UA reported that the Russian GRU-linked hacking group Sandworm is employing fake CAPTCHA prompts to trick users into executing malicious PowerShell commands on their devices. This method, known as…
2 articles · Updated July 21, 2026 -
US Indicts Russian Nationals for $62M Cybercrime Scheme Targeting Critical Infrastructure
On July 14, 2026, the US Justice Department unsealed an indictment against three Russian nationals—Alexander Volosovik, Kirill Zatolokin, and Yulia Pankova—accused of operating bulletproof hosting services that…
29 articles · Updated July 14, 2026 -
China-aligned APT Groups Target Global Maritime and Tech Sectors Amid Geopolitical Tensions
ESET's latest APT Activity Report reveals that from October 2025 to March 2026, China-aligned threat actors engaged in extensive espionage campaigns, particularly in Venezuela and the Gulf region. Following U.S.…
6 articles · Updated May 28, 2026 -
Iranian APT Group Conducts Password Spray Attacks on Microsoft 365 Accounts
In March 2026, a suspected Iranian APT group, identified as Gray Sandstorm, initiated a password spraying campaign targeting Microsoft 365 accounts of over 300 organizations in Israel and more than 25 in the UAE. The…
9 articles · Updated April 1, 2026 -
Cloud Atlas APT Group Exploits CVE-2018-0802 and Modifies termsrv.dll for RDP Access
The Cloud Atlas APT group has been observed employing a sophisticated cyber espionage campaign targeting government and commercial entities in Russia and Belarus. This campaign, active since 2025 and continuing into…
4 articles · Updated May 25, 2026 -
JDY Botnet Grows to 1,500 Devices for Rapid Vulnerability Mapping
The JDY botnet, linked to Chinese state-sponsored actors, has expanded to over 1,500 compromised small office and IoT devices, primarily in the U.S. and Brazil. This botnet scans for newly disclosed vulnerabilities…
12 articles · Updated June 10, 2026 -
Cloud Atlas APT Targets Russia and Belarus with New Tools and Techniques
Cloud Atlas, an advanced persistent threat group, has intensified its cyberespionage activities against government and commercial entities in Russia and Belarus since late 2025. The group employs phishing emails…
2 articles · Updated May 23, 2026 -
Tails 7.8.1 Released to Patch Critical Security Vulnerabilities
The Tails operating system has released version 7.8.1 as an emergency update to address critical security vulnerabilities in the Linux kernel and the Tor client. The update includes the Linux kernel version 6.12.90-2,…
3 articles · Updated June 5, 2026 -
Critical Tails Linux Vulnerability Exposes Users to Deanonymization Risks
Tails Linux has released an emergency patch for a critical kernel vulnerability (CVE-2026-64560) that could allow malicious websites to deanonymize users. The flaw, present since Linux kernel version 5.7, enables…
2 articles · Updated August 5, 2026 -
Emergency Release of Tails 7.6.2 to Address Critical Tor Browser Vulnerability
On April 15, 2026, Tails released version 7.6.2 as an emergency update to address a significant security vulnerability in the Tor Browser's confinement. This vulnerability could potentially be exploited by an attacker…
5 articles · Updated April 15, 2026
Recent Intelligence Reports
- Liberty Darknet Market: Overview & Access — Darkweb-Darknet-Markets · September 8, 2026
- [DIREWOLF] – Ransomware Victim: Precision Vehicle Logistics — Redpacketsecurity · September 7, 2026
- [METAENCRYPTOR] – Ransomware Victim: EllisDon Corporation — Redpacketsecurity · September 7, 2026
- [METAENCRYPTOR] – Ransomware Victim: ST Engineering — Redpacketsecurity · September 7, 2026
- [DIREWOLF] – Ransomware Victim: Lightcast — Redpacketsecurity · September 7, 2026
- awesome — Sploitus · September 7, 2026
- Incident Report Unsanctioned Agent Behaviour During Cyber Testing — www.aisi.gov.uk · September 4, 2026
- Exfilsquad Targets New Victims Shares Data Via Torrents — www.resecurity.com · September 2, 2026