Related Threat Clusters
-
MuddyWater Targets U.S. Entities Amid Geopolitical Tensions
In early 2026, the Iranian APT group MuddyWater launched cyberattacks against U.S. banking, a major airport, and Israeli operations of a U.S.-based software company. The attacks intensified in March, coinciding with…
16 articles · Updated July 22, 2026 -
Kimsuky Exploits South Korean Groupware Vendors with New Gomir Variants
The Kimsuky group, linked to North Korea, targeted South Korean groupware vendors from late 2025 to early 2026, deploying new malware variants BirdTroy and DriveTroy. These Linux backdoors utilized Google Drive for…
4 articles · Updated July 24, 2026 -
Google and FBI Disrupt NetNut Proxy Network Linked to 2 Million Devices
On July 3, 2026, Google, in coordination with the FBI and other partners, disrupted the NetNut residential proxy network, also known as the Popa botnet. This operation targeted over 2 million compromised consumer…
54 articles · Updated July 2, 2026 -
OceanLotus Shifts Focus to Domestic Espionage with SPECTRALVIPER Attacks
From mid-2024 to early 2026, the Vietnam-aligned APT group OceanLotus has intensified its focus on domestic espionage, utilizing the SPECTRALVIPER backdoor in two major campaigns. The first campaign targeted a…
17 articles · Updated June 11, 2026 -
TA416 Resumes Cyber Espionage Against European Governments Amid Geopolitical Tensions
Chinese state-backed group TA416 has reemerged with intensified cyber espionage campaigns targeting European governments, following a quiet period since 2023. Proofpoint reported that the group's renewed activity began…
9 articles · Updated April 1, 2026 -
HoneyMyte APT Upgrades CoolClient Backdoor with Kernel Driver for Enhanced Stealth
The HoneyMyte APT group has deployed an upgraded variant of the CoolClient backdoor in cyber-espionage campaigns targeting organizations in Myanmar, Mongolia, Pakistan, India, and Russia. This new variant introduces a…
10 articles · Updated August 14, 2026 -
GREYVIBE: AI-Driven Cyberattacks Targeting Ukraine by Russian Hackers
The GREYVIBE group, a previously unknown Russian hacking entity, has been actively targeting Ukrainian military, government, and civilian sectors since August 2025. Utilizing sophisticated AI tools like ChatGPT and…
10 articles · Updated May 29, 2026 -
Mustang Panda Espionage Campaigns Target India's Government and Energy Sectors
In June 2026, Mustang Panda launched two espionage campaigns targeting India's hydropower sector and government entities. The attacks utilized lure documents related to cooperation agreements with Taiwan, delivering…
2 articles · Updated June 30, 2026 -
Google Sues Chinese Cybercrime Network for AI-Powered Phishing Operations
Google has filed a lawsuit against the 'Outsider Enterprise', a China-based cybercrime network, for allegedly using AI tools, including its Gemini platform, to conduct large-scale phishing operations. The operation has…
57 articles · Updated June 12, 2026 -
Icarus Group Exploits Klue OAuth Breach to Steal Salesforce Data
In June 2026, a significant security incident involving Klue, a market intelligence platform, allowed the Icarus threat actor group to exfiltrate Salesforce CRM data from multiple organizations, including Huntress. The…
80 articles · Updated June 18, 2026
Recent Intelligence Reports
- Un PC personnel, sept failles et les fichiers de la police au bout : autopsie d'un piratage — Macg.Co · August 21, 2026
- SilkParasite Threatens Central Asian Orgs With Flurry of RATs — Darkreading · August 19, 2026
- Copilot tricked into telling reseachers how to hack itself — Theregister · August 18, 2026
- Targeted Campaign Us Law Firms — cloud.google.com · August 16, 2026
- Earth Preta Updated Stealthy Strategies — www.trendmicro.com · August 15, 2026
- OpenAI's AI models teamed up to hack their way online. Then Meta admitted a breach of its own — Insurancebusinessmag · August 6, 2026
- Analysis Of Kimsuky S Attack On A South Korean Groupware Vendor Using A New Gomir Family Variant — www.enki.co.kr · July 24, 2026
- AgentForger proves AI agents can become persistent insider threats — Csoonline · July 24, 2026