Related Threat Clusters
-
OceanLotus Shifts Focus to Domestic Espionage with SPECTRALVIPER Attacks
From mid-2024 to early 2026, the Vietnam-aligned APT group OceanLotus has intensified its focus on domestic espionage, utilizing the SPECTRALVIPER backdoor in two major campaigns. The first campaign targeted a…
17 articles · Updated June 11, 2026 -
China-Nexus Hackers Target Hospitals and Governments with TriBack Loader Malware
A China-linked cyber espionage operation has compromised a Vietnamese public hospital's imaging systems, infiltrated Malaysia's Ministry of Foreign Affairs, and targeted Honduras's National Congress using a new malware…
2 articles · Updated July 23, 2026 -
New Remcos RAT Campaign Exploits CVE-2017-11882 via Phishing
A new phishing campaign distributing a variant of the Remcos RAT has been identified, targeting Microsoft Windows users. The attack utilizes a fake shipping document to deliver a malicious Word file that exploits…
2 articles · Updated May 29, 2026 -
OXLOADER Malware Loader Delivers CASTLESTEALER via Malicious Google Ads
A new Windows loader named OXLOADER is delivering the CASTLESTEALER infostealer through malicious Google Ads. This previously undocumented malware employs advanced obfuscation techniques and abuses the Windows .reloc…
4 articles · Updated June 22, 2026 -
New Agent Tesla Malware Variant Uses Emojis for Evasion in BEC Campaign
A new variant of the Agent Tesla malware, identified as version 4, employs Unicode emoji characters to obfuscate its JScript dropper in a business email compromise (BEC) campaign targeting finance departments. The…
7 articles · Updated August 21, 2026 -
LummaStealer Infections Rise Following CastleLoader Campaigns
LummaStealer infections have surged due to social engineering campaigns utilizing the ClickFix technique to distribute CastleLoader malware. This infostealer, operating as a malware-as-a-service platform, had previously…
7 articles · Updated February 11, 2026
Recent Intelligence Reports
- New Agent Tesla Malware Variant Boosts Evasion Capabilities — Infosecurity-Magazine · August 21, 2026
- China-Nexus Hackers Breached Hospital X-Rays, Embassy, and Congress With New ... — Techtimes · July 23, 2026
- Oxloader Malware Loader Infostealer — www.elastic.co · June 22, 2026
- OXLOADER: New Windows Loader Drops CASTLESTEALER via Google Ads — Technadu · June 22, 2026
- Elastic Security Labs: SPECTRALVIPER — www.elastic.co · June 11, 2026
- Deceptively Sweet: DonutLoader Reloaded in a modern Remcos RAT Infection — Feeds.Feedburner · May 29, 2026
- LummaStealer Is Getting a Second Life Alongside CastleLoader — Bitdefender · February 11, 2026