Related Threat Clusters
-
Operation Escaneo Targets Latin American Critical Infrastructure
Operation Escaneo is a coordinated cyberattack attributed to the MexicanMafia group, targeting critical infrastructure across Latin America, primarily Mexico. The campaign, which spanned from 2025 to 2026, utilized…
4 articles · Updated June 18, 2026 -
FamousSparrow APT Expands Targeting to Azerbaijani Energy Sector
FamousSparrow, a China-aligned APT group, launched a multi-wave cyberespionage campaign against an Azerbaijani oil and gas company from late December 2025 to February 2026. The attackers employed an evolved DLL…
10 articles · Updated May 13, 2026 -
Cloud Atlas APT Group Exploits CVE-2018-0802 and Modifies termsrv.dll for RDP Access
The Cloud Atlas APT group has been observed employing a sophisticated cyber espionage campaign targeting government and commercial entities in Russia and Belarus. This campaign, active since 2025 and continuing into…
4 articles · Updated May 25, 2026 -
Cloud Atlas APT Targets Russia and Belarus with New Tools and Techniques
Cloud Atlas, an advanced persistent threat group, has intensified its cyberespionage activities against government and commercial entities in Russia and Belarus since late 2025. The group employs phishing emails…
2 articles · Updated May 23, 2026 -
Iranian APT Groups Target Israeli Organizations with Modular C2 Frameworks
In 2026, Iranian APT groups, notably Cavern Manticore and OilRig, have intensified cyber operations against Israeli organizations, primarily in the IT and government sectors. Cavern Manticore employs a modular…
10 articles · Updated July 6, 2026 -
Warlock Ransomware Group Enhances Attack Techniques with BYOVD and Remote Access Tools
The Warlock ransomware group, also known as Water Manaul, has escalated its attack methods by exploiting unpatched Microsoft SharePoint servers and employing new tactics for persistence and lateral movement. Recent…
5 articles · Updated March 16, 2026 -
Toy Ghouls Launch GenieLocker Ransomware Targeting Russian Manufacturing
The Toy Ghouls group, also known as Bearlyfy, has introduced a new ransomware called GenieLocker, active since March 2026. This ransomware targets Windows, Linux, and VMware ESXi systems, primarily affecting the…
5 articles · Updated July 30, 2026 -
ModHeader Extension Removed for Covert Data Collection
The ModHeader browser extension, used by approximately 1.6 million users across Chrome and Edge, was removed after researchers discovered a dormant data-collection capability embedded in its signed release. The…
8 articles · Updated July 14, 2026 -
EvilTokens Phishing Kit Exploits Microsoft 365 with AI-Driven BEC Tactics
In March 2026, the EvilTokens phishing kit emerged as a significant threat, allowing cybercriminals to bypass multi-factor authentication (MFA) and compromise Microsoft 365 accounts. This Phishing-as-a-Service (PhaaS)…
44 articles · Updated July 1, 2026 -
Gentlemen Ransomware Uses Advanced Techniques for Network Attacks
The Gentlemen ransomware, a Go-based RaaS, has been active since mid-2025 and employs aggressive propagation methods. It utilizes 21 remote execution techniques, including PsExec, WMIC, and PowerShell Remoting, to…
3 articles · Updated July 6, 2026
Recent Intelligence Reports
- AvosLocker — www.sophos.com · August 12, 2026
- Unmasking The Gentlemen Ransomware — www.trendmicro.com · August 8, 2026
- T1036 — attack.mitre.org · August 7, 2026
- Toy Ghouls’ new toy: the GenieLocker ransomware — Securelist · July 30, 2026
- LevelBlue found that phishing started 65% of intrusions — www.levelblue.com · July 25, 2026
- New Spirals Ransomware Deployed Across South Asian IT Firm in Under 24 Hours — www.security.com · July 19, 2026
- Attackers execute a complete ransomware operation in under 24 hours | news — Scworld · July 16, 2026
- New Spirals ransomware can lock down an entire network in under 24 hours — Pcquest · July 16, 2026