Related Threat Clusters
-
Iranian Cyberespionage Targets Iraqi Government Officials
In 2024, Iranian APT group BladedFeline launched a cyber campaign against Kurdish and Iraqi government officials, utilizing advanced malware tools including the Shahmaran backdoor and the Whisper backdoor. The attacks…
2 articles · Updated May 13, 2026 -
VerdantBamboo's 18-Month Cyber Campaign Targets Managed Service Providers
A Chinese threat actor known as VerdantBamboo compromised a company's network through a managed service provider (MSP) over 18 months. The initial breach involved a Linux-based Egnyte Storage Sync appliance, which was…
2 articles · Updated June 5, 2026 -
AI-Driven Cyber Attacks Target Latin American Governments and Financial Sectors
Trendmicro's TrendAI™ Research has identified two AI-augmented threat campaigns, SHADOW-AETHER-040 and SHADOW-AETHER-064, targeting government and financial organizations in Latin America. These campaigns began in late…
4 articles · Updated May 11, 2026 -
BlankGrabber Malware Exploits Fake Certificate Loader for Stealthy Attacks
BlankGrabber's operators are utilizing a fake certificate loader to conceal a sophisticated multi-stage infection chain involving Rust and Python. This method leverages built-in Windows tools like certutil.exe and…
3 articles · Updated March 28, 2026 -
Russian Hackers Target Ukrainian Military with Charity-Themed Malware Campaign
Between October and December 2025, Ukrainian Defense Forces were targeted by a cyberattack disguised as a charitable foundation. The attack, attributed to the Russian group Void Blizzard (Laundry Bear), installed…
3 articles · Updated January 14, 2026 -
VVS Stealer Malware Targets Discord Accounts with Python Code
VVS Stealer is a Python-based malware designed to steal Discord credentials and tokens. It has been available for purchase on Telegram since at least April 2025, posing a risk to Discord users. Palo Alto Networks…
7 articles · Updated January 5, 2026 -
New PDFly Malware Variant Employs Custom PyInstaller Modifications
A new variant of the PDFly malware has been identified, utilizing a modified PyInstaller executable to obscure its payload and complicate analysis efforts. This advanced technique hinders security teams from effectively…
2 articles · Updated February 3, 2026
Recent Intelligence Reports
- China’s VerdantBamboo Experimented With Three Re — Thecyberexpress · June 5, 2026
- Iranian Malware Attacks Iraqi Government — research.checkpoint.com · May 13, 2026
- Vibe Hacking: Two AI — Trendmicro · May 11, 2026
- Vibe Hacking: Two AI — Trendmicro · May 11, 2026
- Fake Certificate Loader Hides BlankGrabber Malware Chain — Gbhackers · March 28, 2026
- PDFly Variant Uses Custom PyInstaller Modification, Forcing Analysts to Reverse — Cybersecuritynews · February 3, 2026
- PDFly Variant Uses Custom PyInstaller Tweaks to Obfuscate Payload, Thwarting Analysis — Gbhackers · February 3, 2026
- Ukraine defense officials targeted by PluggyApe malware campaign — Scworld · January 14, 2026