Related Threat Clusters
-
Lazarus Group Exploits Windows Zero-Day to Target Defense Sector
The North Korean hacking group Lazarus exploited a zero-day vulnerability (CVE-2026-68820) in the Windows Ancillary Function Driver for WinSock (afd.sys) to gain SYSTEM-level access to defense sector systems. This…
33 articles · Updated August 12, 2026 -
Jewelbug APT Group Engages in Espionage and Cryptocurrency Fraud
The Jewelbug APT group, based in China, has been conducting simultaneous cyber espionage and cryptocurrency fraud operations. Utilizing a single command-and-control platform named XG-Web, the group has compromised over…
15 articles · Updated August 13, 2026 -
Harvester APT Group Unveils New GoGra Linux Backdoor Using Microsoft Graph API
The Harvester APT group has launched a Linux variant of its GoGra backdoor, utilizing the Microsoft Graph API and Outlook mailboxes for covert command-and-control operations. This malware is designed to evade…
13 articles · Updated April 22, 2026 -
Webworm APT Expands Operations to Europe with New Backdoors
The China-aligned APT group Webworm has shifted its focus from Asia to Europe, targeting government organizations in Belgium, Italy, Poland, Serbia, and Spain during 2025. ESET researchers identified new backdoors,…
12 articles · Updated May 20, 2026 -
CAV3RN Framework Upgrades to Outlook Calendar for C2 Communication
The Project CAV3RN cyberespionage framework has evolved with the introduction of a new communication module, AzureCommunication.dll, which replaces the previous HTTP/WebSocket component. This module utilizes Outlook…
2 articles · Updated July 21, 2026 -
LongNosedGoblin and UAT-8302: New China-Aligned APT Threats Targeting Governments
In 2024, ESET identified a new China-aligned APT group named LongNosedGoblin, which targets governmental entities in Southeast Asia and Japan. The group employs a custom toolset, primarily using C#/.NET applications, to…
8 articles · Updated May 5, 2026 -
HOLLOWGRAPH Malware Exploits Microsoft 365 Calendars for Espionage
Group-IB has identified HOLLOWGRAPH, a sophisticated Windows malware that abuses the Microsoft Graph API to covertly exfiltrate files and receive commands through compromised Microsoft 365 calendar events. The malware…
10 articles · Updated July 20, 2026 -
Evolution of Chinese-Nexus Cyber Operations: Strategic Long-Term Threats
Recent research from Darktrace reveals the evolution of Chinese-nexus cyber operations over the past two decades, highlighting a shift from high-volume attacks to more strategic, identity-centric intrusions. This change…
381 articles · Updated April 2, 2026 -
Storm-2949 Cyberattack Targets Microsoft 365 and Azure Data
Microsoft has reported a significant cyberattack by the threat actor Storm-2949, which exploited Microsoft Entra ID accounts to conduct a large-scale data theft from Microsoft 365 and Azure environments. The attack…
6 articles · Updated May 19, 2026 -
Phishing Campaign Exploits Google Services to Evade Detection
A sophisticated phishing campaign has been identified that routes victims through Google services, including Google Meet and Google Ads, before landing on a credential-harvesting page for Microsoft 365. This method…
2 articles · Updated August 7, 2026
Recent Intelligence Reports
- Silent 'TwinLoot' Cyber Threat Operates Entirely From Microsoft's Cloud — Darkreading · August 18, 2026
- New Malware turns Microsoft cloud into its control center — Csoonline · August 18, 2026
- Jewelbug Apt Russia — www.security.com · August 16, 2026
- Graph API command-and-control abuse — www.group-ib.com · August 16, 2026
- Symantec published August 13, 2026 — www.security.com · August 16, 2026
- Trend Micro's TrendAI — www.trendmicro.com · August 15, 2026
- Researchers Link 'Jewelbug' Chinese APT to Hack-for — Infosecurity-Magazine · August 14, 2026
- Jewelbug APT: China-Based Govt Espionage and Crypto Fraud Exposed — Technadu · August 14, 2026