Certutil is a tool tracked by ThreatCluster, appearing in 11 threat clusters built from 17 intelligence report mentions.
Certutil is a tool tracked across 11 threat clusters and 17 intelligence report mentions on ThreatCluster. First observed May 5, 2026; most recent activity July 24, 2026.
The North Korean hacking group Kimsuky is utilizing generative AI to create malware aimed at South Korean government systems, as reported by Kaspersky on May 14, 2026. The malware, named HelloDoor, is a Rust-based…
Recent research from Darktrace reveals the evolution of Chinese-nexus cyber operations over the past two decades, highlighting a shift from high-volume attacks to more strategic, identity-centric intrusions. This change…
In 2026, the average time from vulnerability disclosure to exploitation has drastically decreased to around 8 hours, down from 53 days in 2024. This rapid weaponization is attributed to advancements in AI, which can…
A new backdoor known as Mistic has been identified in cyberattacks targeting various sectors since April 2026. It is associated with the initial access broker KongTuke, also known as Woodgnat, which sells access to…
Cybercriminals are increasingly using legitimate system tools like PowerShell and WMI to deploy malware, creating stealthy threats that evade traditional defenses. The ANY.RUN Q1 2026 Cyber Risk report highlights a…
The Mistic malware, a newly identified Windows backdoor, has been active since April 2026, utilizing DLL sideloading to infiltrate enterprise environments. It exploits a legitimate executable, MpExtMs.exe, to load a…
In June 2026, a malware campaign was identified that spreads malicious VBScript files through WhatsApp direct messages. The campaign primarily targets users of WhatsApp Desktop and WhatsApp Web, with the highest number…
An exposed server functioning as a malware delivery lab was discovered following an MDR alert. The lab contained over 1,000 artifacts, showcasing how attackers are leveraging generative AI for rapid lure generation and…
As of February 12, 2026, organizations worldwide are experiencing an average of 2,090 cyber-attacks per week, largely driven by ransomware incidents. This increase highlights the ongoing challenges faced by businesses…
Swiss rail manufacturer Stadler Rail confirmed a cyberattack by the Everest ransomware gang, which demanded a ransom of CHF 10 million ($12.3 million) after breaching a data exchange platform shared with a supplier. The…
Certutil is a tool tracked by ThreatCluster, appearing in 11 threat clusters built from 17 intelligence report mentions.
The most recent intelligence report mentioning Certutil on ThreatCluster is dated July 24, 2026. Activity was first observed May 5, 2026, giving a tracked span from then to July 24, 2026.
Across ThreatCluster reporting, Certutil most frequently co-occurs with Apt43, Black Banshee, Kimsuky, KongTuke, Lazarus Group, among 12 tracked related entities.
The most significant recent cluster is “Kimsuky Group Leverages AI for Malware Targeting South Korean Government” (5 articles · Updated May 14, 2026). Certutil appears across 11 threat clusters in total, listed above with sources.
Certutil appears in 17 intelligence report mentions across 11 deduplicated threat clusters, aggregated from 17,000+ monitored sources.