Related Threat Clusters
-
UAT-7290 Cyber Espionage Targets South Asian Telecoms
UAT-7290, a China-linked advanced persistent threat group, has been active since at least 2022, focusing on espionage against telecommunications providers in South Asia. The group employs a range of Linux and Windows…
2 articles · Updated January 12, 2026 -
Critical Vulnerabilities in BusyBox Affecting openSUSE Systems
A security update for BusyBox addresses multiple vulnerabilities, including CVE-2023-42363, CVE-2023-42364, CVE-2023-42365, CVE-2025-46394, CVE-2025-60876, CVE-2026-26157, and CVE-2026-26158. These vulnerabilities…
3 articles · Updated March 12, 2026 -
Chinese State Hackers Target South American Telcos with Advanced Malware
The advanced persistent threat group UAT-9244, linked to Chinese state-sponsored operations, has been targeting telecommunications providers in South America since 2024. Utilizing sophisticated techniques such as DLL…
3 articles · Updated March 5, 2026 -
Evooo1Bot: New Mirai-Based Linux Botnet Exploiting Edge Devices
FortiGuard Labs has identified a new Linux botnet named Evooo1Bot, which is based on the Mirai malware framework. This botnet targets internet-facing edge devices, exploiting multiple vulnerabilities since July 2026.…
17 articles · Updated August 14, 2026 -
Hackers Exploit QEMU VMs to Evade Detection and Deploy Ransomware
Hackers are utilizing QEMU, an open-source virtual machine emulator, to create hidden Linux environments within Windows systems, effectively evading endpoint security tools. This method allows for long-term access,…
8 articles · Updated April 17, 2026 -
CISA Issues Update on RESURGE Malware Targeting Ivanti Devices
CISA has released updated findings on RESURGE, a malware implant exploiting CVE-2025-0282 to compromise Ivanti Connect Secure devices. This malware can remain undetected and utilize advanced evasion techniques for…
11 articles · Updated February 27, 2026
Recent Intelligence Reports
- Multi-Functional Linux Botnet “Evooo1Bot” | FortiGuard Labs — Fortinet · August 13, 2026
- Payouts King ransomware uses QEMU VMs to bypass endpoint security — Bleepingcomputer · April 17, 2026
- openSUSE Leap 15.5 BusyBox Security Warning — Linuxsecurity · March 12, 2026
- Chinese state hackers target telcos with new malware toolkit — Bleepingcomputer · March 5, 2026
- UAT — Blog.Talosintelligence · March 5, 2026
- CISA warns that RESURGE malware can be dormant on Ivanti devices — Bleepingcomputer · February 27, 2026
- New CISA guidance targets persistent RESURGE implant as Ivanti Connect Secure threat ... — Industrialcyber.Co · February 27, 2026
- UAT-7290 Targets South Asian Telecoms with Linux Implants — Socprime · January 12, 2026