Related Threat Clusters
-
MuddyWater Targets U.S. Entities Amid Geopolitical Tensions
In early 2026, the Iranian APT group MuddyWater launched cyberattacks against U.S. banking, a major airport, and Israeli operations of a U.S.-based software company. The attacks intensified in March, coinciding with…
16 articles · Updated July 22, 2026 -
Operation Saffron: First VPN Dismantled in Major Cybercrime Takedown
On May 19-20, 2026, an international law enforcement operation, dubbed Operation Saffron, successfully dismantled First VPN, a virtual private network service heavily utilized by cybercriminals for ransomware, fraud,…
32 articles · Updated May 21, 2026 -
Data Destruction and Disk Wiping Techniques Targeting Organizations
Adversaries are employing data destruction and disk wiping techniques to disrupt organizational operations. Techniques include overwriting files and disk data, with malware exhibiting worm-like propagation capabilities.…
2 articles · Updated July 22, 2026 -
Critical RCE Vulnerability in Veeam Backup Exposes Organizations to Attacks
Veeam has disclosed a critical vulnerability (CVE-2026-44963) affecting its Backup & Replication software, allowing authenticated domain users to execute remote code on domain-joined backup servers. This flaw impacts…
11 articles · Updated June 9, 2026 -
Qilin and Warlock Ransomware Exploit Vulnerable Drivers to Compromise EDR Tools
Qilin and Warlock ransomware variants have been identified exploiting vulnerable drivers to disable over 300 endpoint detection and response (EDR) tools. This exploitation allows the ransomware to evade detection and…
2 articles · Updated April 6, 2026 -
GrayAlpha Threat Actor Uses MaskBat Loader for NetSupport RAT Deployments
Insikt Group identified GrayAlpha, a threat actor linked to FIN7, utilizing a custom loader named MaskBat to deploy NetSupport RAT through various infection vectors. These include fake browser update pages, fake 7-Zip…
2 articles · Updated August 6, 2026 -
Qilin Ransomware Targets Retelit, Major Telecom Provider in Italy
The Qilin ransomware group has reportedly targeted Retelit SpA, a leading telecommunications operator in Italy. This attack is part of a broader campaign that has seen a significant increase in ransomware incidents…
2 articles · Updated September 10, 2026 -
Critical RCE Vulnerability in BeyondTrust Software Requires Immediate Patching
BeyondTrust has issued a warning regarding a critical remote code execution (RCE) vulnerability in its Remote Support and Privileged Remote Access software. The flaw, tracked as CVE-2026-1731, allows unauthenticated…
1495 articles · Updated February 9, 2026 -
Critical Vulnerabilities Discovered in Mozilla Products
Multiple vulnerabilities have been identified in Mozilla products, with the most severe allowing for arbitrary code execution. Exploitation could enable attackers to install programs, access, modify, or delete data, and…
44 articles · Updated April 8, 2026 -
U.S. Sanctions Xinbi Guarantee Cyber Scam Marketplace
On September 9, 2026, the U.S. Department of the Treasury sanctioned the Chinese-language platform Xinbi Guarantee, linked to extensive cyber scams targeting Americans. The operation resulted in the seizure of $52.8…
6 articles · Updated September 9, 2026
Recent Intelligence Reports
- ACN bulletin on Qilin — www.acn.gov.it · September 10, 2026
- OFAC Sanctions Chinese Scam Platform Xinbi Guarantee — Infosecurity-Magazine · September 10, 2026
- Russian Motivations Hanoi Convention Cybercrime — www.justsecurity.org · August 22, 2026
- AvosLocker — www.sophos.com · August 12, 2026
- MITRE ATT&CK T1688 — attack.mitre.org · August 12, 2026
- T1189 — attack.mitre.org · August 7, 2026
- recordedfuture.com — www.recordedfuture.com · August 7, 2026
- Ransom Cartel operator Maksim Silnikau jailed for 16 years — Bitdefender · August 6, 2026