Related Threat Clusters
-
MuddyWater Targets U.S. Entities Amid Geopolitical Tensions
In early 2026, the Iranian APT group MuddyWater launched cyberattacks against U.S. banking, a major airport, and Israeli operations of a U.S.-based software company. The attacks intensified in March, coinciding with…
16 articles · Updated July 22, 2026 -
GrayAlpha Threat Actor Uses MaskBat Loader for NetSupport RAT Deployments
Insikt Group identified GrayAlpha, a threat actor linked to FIN7, utilizing a custom loader named MaskBat to deploy NetSupport RAT through various infection vectors. These include fake browser update pages, fake 7-Zip…
2 articles · Updated August 6, 2026 -
Akira Ransomware Uses Safe Mode to Evade EDR Detection
In early August 2026, an Akira ransomware affiliate executed an attack leveraging Safe Mode to evade endpoint detection and response (EDR) tools. The attack began with credential spraying against an exposed SonicWall…
11 articles · Updated August 12, 2026 -
Cyber Adversaries Exploit File Enumeration and Data Collection Techniques
Recent reports detail the tactics employed by various cyber adversaries to enumerate files and directories on compromised systems. Adversaries utilize command shell utilities and custom tools to gather sensitive…
2 articles · Updated April 22, 2026 -
Ukrainian National Extradited for Conti Ransomware Charges Facing 25 Years in Prison
Oleksii Oleksiyovych Lytvynenko, a 43-year-old Ukrainian national, has been extradited from Ireland to the United States on charges related to the Conti ransomware group. He allegedly controlled stolen data and sent…
2 articles · Updated October 31, 2025 -
Ukrainian Extradited to US for Role in Conti Ransomware Operation
Oleksii Lytvynenko, a 43-year-old Ukrainian national, has been extradited from Ireland to the United States to face charges related to the Conti ransomware operation. He is accused of participating in cybercrimes that…
4 articles · Updated November 4, 2025
Recent Intelligence Reports
- Akira hackers disable EDR with Safe Mode, steal data but fail to encrypt — Bleepingcomputer · August 13, 2026
- Akira Affiliate Crashes Ransomware After Attempting EDR Evasion — Infosecurity-Magazine · August 13, 2026
- Akira ransomware attacker uses Safe Mode reboot to evade EDR | news — Scworld · August 12, 2026
- MITRE ATT&CK T1688 — attack.mitre.org · August 12, 2026
- Akira Hits Safe Mode: Ransomware Rebooting Around EDR — Huntress · August 12, 2026
- T1036 — attack.mitre.org · August 7, 2026
- T1027 — attack.mitre.org · August 7, 2026
- 001 — attack.mitre.org · July 23, 2026