Related Threat Clusters
-
Akira Ransomware Group Targets Critical Infrastructure, Extracts $42 Million
The Akira ransomware group has been identified as a significant threat to critical infrastructure, with the U.S. Cybersecurity and Infrastructure Security Agency (CISA) and the FBI warning of its active ransomware…
9 articles · Updated November 14, 2025 -
Storm-1175 Deploys New StormEncryptor Ransomware Targeting N-central Systems
A financially motivated threat actor, Storm-1175, previously linked to Medusa ransomware, has begun deploying a new ransomware strain named StormEncryptor. This campaign was initiated after exploiting an…
11 articles · Updated August 10, 2026 -
Operation Escaneo Targets Latin American Critical Infrastructure
Operation Escaneo is a coordinated cyberattack attributed to the MexicanMafia group, targeting critical infrastructure across Latin America, primarily Mexico. The campaign, which spanned from 2025 to 2026, utilized…
4 articles · Updated June 18, 2026 -
Jewelbug APT Group Engages in Espionage and Cryptocurrency Fraud
The Jewelbug APT group, based in China, has been conducting simultaneous cyber espionage and cryptocurrency fraud operations. Utilizing a single command-and-control platform named XG-Web, the group has compromised over…
15 articles · Updated August 13, 2026 -
MuddyWater Targets U.S. Entities Amid Geopolitical Tensions
In early 2026, the Iranian APT group MuddyWater launched cyberattacks against U.S. banking, a major airport, and Israeli operations of a U.S.-based software company. The attacks intensified in March, coinciding with…
16 articles · Updated July 22, 2026 -
Iranian APT MuddyWater Uses Chaos Ransomware as a False Flag for Espionage
In early 2026, the Iranian APT group MuddyWater, affiliated with the Ministry of Intelligence and Security, executed a sophisticated cyber operation disguised as a Chaos ransomware attack. Utilizing social engineering…
17 articles · Updated May 7, 2026 -
LongNosedGoblin and UAT-8302: New China-Aligned APT Threats Targeting Governments
In 2024, ESET identified a new China-aligned APT group named LongNosedGoblin, which targets governmental entities in Southeast Asia and Japan. The group employs a custom toolset, primarily using C#/.NET applications, to…
8 articles · Updated May 5, 2026 -
Storm-0501 Cybercrime Group Targets Azure with Ransomware Tactics
Storm-0501, a financially motivated cybercrime group, has been active since 2021 and is known for conducting ransomware operations using various Ransomware-as-a-Service (RaaS) variants. They have recently expanded their…
2 articles · Updated August 17, 2026 -
Anonymous Researcher Publishes Zero-Day Exploits for Major Software Projects
An anonymous researcher known as Bikini has released exploit code for over a dozen zero-day vulnerabilities affecting 15 popular open-source projects, including the Linux kernel and Libssh2. The exploits were disclosed…
4 articles · Updated July 1, 2026 -
Ransomware Group Targets SonicWall Gen 7 Firewalls via CVE-2024-40766
In June 2026, a surge in attacks targeting SonicWall Gen 7 firewalls has been reported, exploiting CVE-2024-40766, an improper access control flaw. This vulnerability allows threat actors to gain unauthorized access,…
2 articles · Updated June 23, 2026
Recent Intelligence Reports
- Kimsuky Abuses Remote Access Tools Across Northeast Asia — Socprime · August 26, 2026
- Storm-0501 — attack.mitre.org · August 18, 2026
- PurpleDelta's Fraudulent Employment Operations — Recordedfuture · August 18, 2026
- Jewelbug Apt Russia — www.security.com · August 16, 2026
- Targeted Campaign Us Law Firms — cloud.google.com · August 16, 2026
- Akira hackers disable EDR with Safe Mode, steal data but fail to encrypt — Bleepingcomputer · August 13, 2026
- Akira ransomware attacker uses Safe Mode reboot to evade EDR | news — Scworld · August 12, 2026
- AvosLocker — www.sophos.com · August 12, 2026