Related Threat Clusters
-
Kimsuky Exploits South Korean Groupware Vendors with New Gomir Variants
The Kimsuky group, linked to North Korea, targeted South Korean groupware vendors from late 2025 to early 2026, deploying new malware variants BirdTroy and DriveTroy. These Linux backdoors utilized Google Drive for…
4 articles · Updated July 24, 2026 -
Iranian APT MuddyWater Uses Chaos Ransomware as a False Flag for Espionage
In early 2026, the Iranian APT group MuddyWater, affiliated with the Ministry of Intelligence and Security, executed a sophisticated cyber operation disguised as a Chaos ransomware attack. Utilizing social engineering…
17 articles · Updated May 7, 2026 -
Operation Double Barrel: State-Sponsored Exploitation of Korean Financial Software
From 2025 to mid-2026, a state-sponsored threat group exploited vulnerabilities in Korean financial security software, utilizing watering hole attacks and spear phishing to deploy backdoors named Struggle and Brandoor.…
7 articles · Updated July 30, 2026 -
Smoke#Screen Campaign Uses Fake Updates to Install Remote Access Tool
The Smoke#Screen campaign exploits social engineering tactics to install the legitimate ScreenConnect RMM tool on compromised systems, providing attackers with remote access. Targeting both Windows and macOS, the…
8 articles · Updated August 4, 2026 -
Vishing Campaigns Target Organizations via Microsoft Teams and New Operator Console
A vishing campaign, tracked as STAC4749, targeted North American organizations from February to June 2026, using Microsoft Teams to impersonate IT personnel and gain remote access. Attackers deployed a modular toolset,…
9 articles · Updated July 29, 2026
Recent Intelligence Reports
- 826591 — www.cybersecuritydive.com · August 5, 2026
- State Hackers Made South Korea's Mandatory Banking Software Into Zero — Techtimes · July 30, 2026
- Chaos in Teams vishing — Sophos · July 28, 2026
- Analysis Of Kimsuky S Attack On A South Korean Groupware Vendor Using A New Gomir Family Variant — www.enki.co.kr · July 24, 2026
- North Korea Hid New Google Drive Backdoors Inside South Korean Groupware Firms — Techtimes · July 24, 2026
- Kimsuky Targets South Korean Groupware with Gomir — Socprime · July 23, 2026
- Tr Muddying Tracks State Sponsored Shadow Behind Chaos Ransomware — www.rapid7.com · May 11, 2026
- MuddyWater Behind Chaos Ransomware False Flag — Socprime · May 7, 2026