Related Threat Clusters
-
North Korean Sapphire Sleet Targets macOS Users in New Social Engineering Campaign
A North Korean cybercrime group known as Sapphire Sleet has launched a social engineering campaign targeting macOS users, as reported by Microsoft's Threat Intelligence unit. The campaign involves tricking users into…
7 articles · Updated April 17, 2026 -
New macOS Gaslight Malware Targets AI Analysis Tools
A new macOS malware named 'Gaslight' has been identified, attributed to North Korean threat actors. This malware employs prompt injection techniques to confuse AI-assisted malware analysis tools, embedding 38 fake…
13 articles · Updated June 25, 2026 -
AI-Driven Malware Framework Automates EDR Evasion Tactics
Sophos X-Ops analysts uncovered a threat actor utilizing AI technologies to develop a malware-testing framework aimed at evading endpoint detection and response (EDR) systems. The activity was detected on June 2, 2026,…
16 articles · Updated June 2, 2026 -
Millenium RAT 4.*: Evolving Threat with Global Impact
The Millenium RAT, particularly version 4.*, has seen a significant rise in exploitation, affecting over 62,000 endpoints across 160 countries. This remote access trojan, now written in C++, utilizes the Telegram Bot…
3 articles · Updated June 25, 2026 -
Rise of AI-Driven Scams Targeting UK SMEs
UK small and medium-sized enterprises (SMEs) are increasingly vulnerable to sophisticated AI-driven scams, as highlighted by recent reports. The emergence of 'AI scams 2.0' combines traditional social engineering…
840 articles · Updated March 12, 2026 -
Threat Actors Exploit Vercel's GenAI for Phishing Campaigns
Threat actors are increasingly using Vercel's generative AI tool, v0[.]dev, to create realistic phishing websites that mimic well-known brands. Cofense has observed a rise in campaigns utilizing this tool, which allows…
5 articles · Updated May 7, 2026 -
ResokerRAT: New Telegram-Based Remote Access Trojan Targets Windows Systems
A new Windows malware named ResokerRAT has emerged, utilizing the Telegram Bot API for communication. This Remote Access Trojan (RAT) allows attackers to remotely control infected systems without relying on traditional…
4 articles · Updated March 31, 2026 -
Weaponized Microsoft Outlook Add-ins Exploit User Credentials
A dormant Microsoft Outlook add-in has been weaponized, leading to the theft of thousands of login credentials and credit card numbers. This incident marks the first known malicious Office add-in discovered in the wild,…
9 articles · Updated February 12, 2026 -
RedKitten Campaign Targets Iranian Protest Monitors with AI Malware
The RedKitten campaign has emerged, utilizing AI-driven malware to target individuals and organizations monitoring human rights violations during the Dey 1404 protests in Iran. Discovered by HarfangLab, the campaign…
4 articles · Updated February 2, 2026 -
Phishing Campaign Targets European Organizations Using HTML Attachments and Telegram Bots
A sophisticated phishing campaign has been identified in Central and Eastern Europe, targeting various sectors including manufacturing and government. Cybercriminals are using HTML attachments with embedded JavaScript…
3 articles · Updated November 12, 2025
Recent Intelligence Reports
- Gaslight: New macOS malware tries to deceive AI-based analysis systems — Tech.News.Am · June 26, 2026
- Millenium: A RAT Rewritten, A Threat Multiplied | Group — Group-Ib · June 25, 2026
- macOS Backdoor Uses Prompt Injection to Evade AI Triage — Infosecurity-Magazine · June 24, 2026
- Attackers Use AI Tools to Automate Active Directory Attacks | Let's Data Science — Letsdatascience · June 3, 2026
- Steal Smarter Not Harder Malicious Use Of Vercel For Credential Phishing — cofense.com · May 7, 2026
- New Sapphire Sleet attack against macOS users detailed | brief — Scworld · April 17, 2026
- Hackers Deploy Telegram — Cybersecuritynews · March 31, 2026
- Telegram — Gbhackers · March 31, 2026