Related Threat Clusters
-
Jewelbug APT Group Engages in Espionage and Cryptocurrency Fraud
The Jewelbug APT group, based in China, has been conducting simultaneous cyber espionage and cryptocurrency fraud operations. Utilizing a single command-and-control platform named XG-Web, the group has compromised over…
15 articles · Updated August 13, 2026 -
UAC-0099 Exploits Notepad++ to Distribute Malware in Ukraine
Ukrainian CERT has identified a cyber campaign attributed to the UAC-0099 threat cluster, which targets organizations in Ukraine using the legitimate Notepad++ application to distribute malware. The attackers deliver a…
8 articles · Updated July 23, 2026 -
7-Zip RCE Vulnerability CVE-2025-11001 Actively Exploited
A remote code execution vulnerability in 7-Zip, tracked as CVE-2025-11001, is being actively exploited by attackers. This flaw allows remote attackers to execute arbitrary code on affected installations, with a CVSS…
4 articles · Updated November 20, 2025 -
HoneyMyte APT Upgrades CoolClient Backdoor with Kernel Driver for Enhanced Stealth
The HoneyMyte APT group has deployed an upgraded variant of the CoolClient backdoor in cyber-espionage campaigns targeting organizations in Myanmar, Mongolia, Pakistan, India, and Russia. This new variant introduces a…
10 articles · Updated August 14, 2026 -
LongNosedGoblin and UAT-8302: New China-Aligned APT Threats Targeting Governments
In 2024, ESET identified a new China-aligned APT group named LongNosedGoblin, which targets governmental entities in Southeast Asia and Japan. The group employs a custom toolset, primarily using C#/.NET applications, to…
8 articles · Updated May 5, 2026 -
7-Zip RCE Vulnerability CVE-2025-11001 Actively Exploited
A remote code execution vulnerability in 7-Zip, tracked as CVE-2025-11001, is currently being exploited by attackers. This flaw allows remote attackers to execute arbitrary code on affected installations, impacting…
4 articles · Updated November 20, 2025 -
Anonymous Researcher Publishes Zero-Day Exploits for Major Software Projects
An anonymous researcher known as Bikini has released exploit code for over a dozen zero-day vulnerabilities affecting 15 popular open-source projects, including the Linux kernel and Libssh2. The exploits were disclosed…
4 articles · Updated July 1, 2026 -
Italy Extradites Chinese Hacker Xu Zewei to the U.S. for COVID-19 Research Theft
Xu Zewei, a 33-year-old Chinese national, was extradited from Italy to the United States on April 27, 2026, following his arrest in Milan on July 3, 2025. He is accused of participating in cyberattacks directed by the…
51 articles · Updated April 26, 2026 -
Critical Vulnerabilities in 7-Zip Enable Code Execution Attacks
A critical heap buffer overflow vulnerability has been identified in 7-Zip version 26.00, allowing attackers to execute arbitrary code through a vtable hijack. This flaw, tracked as CVE-2026-48095 and assigned advisory…
6 articles · Updated May 26, 2026 -
GoSerpent Backdoor Steals Sensitive Data from Southeast Asian Governments
A cyber espionage campaign utilizing the GoSerpent backdoor has infiltrated government networks in Southeast Asia for over five years, harvesting sensitive police and biometric data. The operation, revealed by…
8 articles · Updated July 17, 2026
Recent Intelligence Reports
- Jewelbug Apt Russia — www.security.com · August 16, 2026
- Earth Preta Updated Stealthy Strategies — www.trendmicro.com · August 15, 2026
- Six Agencies Warn Gunra Ransomware Hacked MFA at Server Level; Linux Victims May ... — Techtimes · August 11, 2026
- T1036 — attack.mitre.org · August 7, 2026
- recordedfuture.com — www.recordedfuture.com · August 7, 2026
- MaskBat — Mallory.Ai · August 6, 2026
- Notepad++ used in new stealthy attacks targeting Ukraine — Feeds.Feedburner · July 23, 2026
- Hackers abuse Notepad++ plugins to stealthily install malware — Bleepingcomputer · July 23, 2026