Related Threat Clusters
-
MuddyWater Targets U.S. Entities Amid Geopolitical Tensions
In early 2026, the Iranian APT group MuddyWater launched cyberattacks against U.S. banking, a major airport, and Israeli operations of a U.S.-based software company. The attacks intensified in March, coinciding with…
16 articles · Updated July 22, 2026 -
Chronus Group Breach Exposes 36 Million Mexican Citizens' Data
In January 2026, the Chronus Group executed a significant data breach against the Mexican government, compromising 2.3 terabytes of sensitive data from at least 25 agencies. The breach exposed personal information of up…
2 articles · Updated May 28, 2026 -
New Remcos RAT Campaign Exploits CVE-2017-11882 via Phishing
A new phishing campaign distributing a variant of the Remcos RAT has been identified, targeting Microsoft Windows users. The attack utilizes a fake shipping document to deliver a malicious Word file that exploits…
2 articles · Updated May 29, 2026 -
Global Phishing Campaign Uses Lua Loader Disguised as TrueType Font Files
Since late March 2026, a large-scale phishing campaign has been observed utilizing disguised TrueType Font (.ttf) files to deliver Lua-based loaders and various malware, including Agent Tesla and Remcos. The attackers…
5 articles · Updated July 16, 2026 -
Lumma Stealer Malware Spread via Fake Downloads of The Odyssey
Following the release of The Odyssey, cybersecurity researchers have identified fake pirated copies distributing Lumma Stealer malware. Users searching for illegal downloads are at risk as these malicious files…
8 articles · Updated August 6, 2026 -
Vidar Stealer 2.0 Spreads via Fake Game Cheats on GitHub and Reddit
Acronis Threat Research Unit reported that the Vidar Stealer 2.0 is being distributed through hundreds of fake game cheat repositories on GitHub and targeted posts on Reddit. The malware masquerades as free cheating…
3 articles · Updated March 18, 2026 -
Chime Faces Lawsuits After Alleged Iran-Linked Cyberattack
On April 1, 2026, Chime Financial's mobile app experienced a significant outage attributed to a cyberattack by the pro-Iranian hacker group Team 313. Customers reported being unable to access their accounts, leading to…
4 articles · Updated May 4, 2026 -
WhatsApp Malware Campaign Targets Brazilian Crypto Users
A sophisticated malware campaign in Brazil is exploiting WhatsApp to target cryptocurrency users, deploying a banking trojan named 'Eternidade Stealer.' This malware hijacks devices, steals financial data, and spreads…
19 articles · Updated November 26, 2025 -
LummaStealer Infections Rise Following CastleLoader Campaigns
LummaStealer infections have surged due to social engineering campaigns utilizing the ClickFix technique to distribute CastleLoader malware. This infostealer, operating as a malware-as-a-service platform, had previously…
7 articles · Updated February 11, 2026 -
Five Plead Guilty in North Korean IT Worker Fraud Scheme
Five individuals have pleaded guilty to facilitating North Korean operatives in obtaining remote IT jobs at U.S. companies by using false and stolen identities. The U.S. Department of Justice has also seized $15 million…
39 articles · Updated November 17, 2025
Recent Intelligence Reports
- The Odyssey Piracy Downloads Already Deliver Lumma Stealer Malware — Bitdefender · August 6, 2026
- 001 — attack.mitre.org · July 23, 2026
- The Ttf Trap A Global Campaign Of A Low Detection Lua Loader — www.fortinet.com · July 21, 2026
- Phishing Campaign Hides Lua Loader as TrueType Font File — Infosecurity-Magazine · July 16, 2026
- Deceptively Sweet: DonutLoader Reloaded in a modern Remcos RAT Infection — Feeds.Feedburner · May 29, 2026
- MITRE ATT&CK S1213 — attack.mitre.org · May 28, 2026
- 313team Threat Advisory — hawk-eye.io · May 4, 2026
- Vidar Stealer 2.0 Exploits GitHub, Reddit to Deliver Malware via Fake Game Cheats — Infosecurity-Magazine · March 18, 2026