Related Threat Clusters
-
Persistent Firestarter Malware Targets Cisco Firepower Devices in US Agencies
A sophisticated backdoor malware named Firestarter has been discovered on Cisco Firepower devices, attributed to the state-sponsored threat actor UAT-4356. The malware exploits two vulnerabilities, CVE-2025-20333 and…
37 articles · Updated April 23, 2026 -
MuddyWater Targets U.S. Entities Amid Geopolitical Tensions
In early 2026, the Iranian APT group MuddyWater launched cyberattacks against U.S. banking, a major airport, and Israeli operations of a U.S.-based software company. The attacks intensified in March, coinciding with…
16 articles · Updated July 22, 2026 -
FamousSparrow APT Expands Targeting to Azerbaijani Energy Sector
FamousSparrow, a China-aligned APT group, launched a multi-wave cyberespionage campaign against an Azerbaijani oil and gas company from late December 2025 to February 2026. The attackers employed an evolved DLL…
10 articles · Updated May 13, 2026 -
Widespread Abuse of ScreenConnect to Deploy AsyncRAT via Fake Installers
A significant cybersecurity campaign has emerged, exploiting the legitimate remote access tool ScreenConnect to deploy AsyncRAT malware. Attackers utilized spoofed websites and typosquatted domains, masquerading as…
7 articles · Updated July 1, 2026 -
Microsoft Disrupts Fox Tempest Malware-Signing Service for Ransomware Gangs
On May 19, 2026, Microsoft disrupted Fox Tempest, a malware-signing-as-a-service (MSaaS) operation that provided over 1,000 fraudulent code-signing certificates to cybercriminals, enabling them to disguise malware as…
33 articles · Updated May 19, 2026 -
Towne Mortgage Data Breach Linked to Ransomware Attack
Towne Mortgage Company confirmed a data breach resulting from a ransomware attack detected on June 7, 2025. The breach compromised personal information, including Social Security numbers and financial accounts,…
3 articles · Updated December 2, 2025 -
Ukrainian National Pleads Guilty in Conti Ransomware Case
Oleksii Oleksiyovych Lytvynenko, a 44-year-old Ukrainian national, pleaded guilty to conspiracy to commit wire fraud related to the Conti ransomware operation. This group was responsible for over 1,000 attacks…
17 articles · Updated June 12, 2026 -
Mexico's Cybersecurity Strategy Faces Challenges Amid Rising Threats
Mexico's National Cybersecurity Strategy, initiated in 2017, has seen stalled progress under President Andrés Manuel López Obrador (AMLO). The country faces significant cybersecurity threats, including ransomware,…
5 articles · Updated June 25, 2026 -
Ransomware Fuels Surge in Global Cyberattacks
As of February 12, 2026, organizations worldwide are experiencing an average of 2,090 cyber-attacks per week, largely driven by ransomware incidents. This increase highlights the ongoing challenges faced by businesses…
1922 articles · Updated February 12, 2026 -
Everest ransomware gang claims breach of SIAD Group, Italian gas producer
The Everest ransomware gang has claimed to have stolen 159 GB of data from SIAD Group, a major Italian industrial gas producer. The gang has threatened to publicly release the data within eight days, although SIAD Group…
2 articles · Updated November 12, 2025
Recent Intelligence Reports
- Everest Ransomware — www.provendata.com · July 24, 2026
- 001 — attack.mitre.org · July 23, 2026
- 012 — attack.mitre.org · July 1, 2026
- Evaluating Mexico’s New Cybersecurity Plan — Recordedfuture · June 25, 2026
- Ukrainian national pleads guilty to role in Conti ransomware operation — Bleepingcomputer · June 12, 2026
- Ukrainian national pleads guilty to role in Conti ransomware operation — Bleepingcomputer · June 12, 2026
- Cybercrime service disrupted for abusing Microsoft platform to sign malware — Bleepingcomputer · May 19, 2026
- T1505.003 Web Shell — attack.mitre.org · May 13, 2026