Skip to content
Product
Use it
Threat intelligence API
Free key, 70+ endpoints, OpenAPI. The product.
Get started
Pick your stack, make your first call.
Live feed
The console: incidents, filters, entities, search.
Recipes
Runnable examples for the free key.
Free feeds
RSS, ransomware feed, IOC blocklist, MISP — no key.
CLI & agents
tc from a terminal; agent keys with scoped budgets.
The data
Incident records
900 articles a day become ~70 scored incidents.
Dark web
First-party leak-site collection: victims, groups, markets.
Validated IOCs
Indicators with a false-positive gate; STIX, MISP, CSV.
Vulnerabilities
CVEs with EPSS, KEV and exploit status.
Entity graph
Actors, malware, CVEs, companies — pivotable.
For teams
For service providers
Per-client feeds, alerts and branded digests.
Use cases
How teams and builders use the corpus.
About ThreatCluster
What it is and how it is built.
Pricing
Docs
Reference
OpenAPI (Swagger)
Every endpoint, parameter and response model.
ReDoc
The same reference, long-form.
Examples on GitHub
curl, Python and Node quickstarts; daily spec snapshot.
Guides
Quickstart & plans
Key, scopes, budgets, tiers.
Integrations
Splunk, Sentinel, Elastic, agents and terminals, step by step
Export formats
STIX 2.1, MISP, CSV, text.
CLI setup
Install, log in, wire an agent.
No results found
Sign in
Get a free key
No results found
Product
Threat intelligence API
Get started
Live feed
Recipes
Free feeds
CLI & agents
The data
Incident records
Dark web
Validated IOCs
Vulnerabilities
Entity graph
For teams
For service providers
Use cases
About ThreatCluster
Docs
OpenAPI (Swagger)
ReDoc
Examples on GitHub
Quickstart & plans
Integrations
Export formats
CLI setup
Pricing
Contact
Get a free key
Sign in
Back
EternalBlue
Vulnerability
Threat entity extracted from intelligence sources
Sep 5: 0 mentions
Sep 6: 0 mentions
Sep 7: 0 mentions
Sep 8: 2 mentions
Sep 9: 0 mentions
Sep 10: 0 mentions
Sep 11: 0 mentions
Sep 5
Sep 8
Sep 11
Entities
›
vulnerability
›
EternalBlue
Frequency
21
occurrences
First Seen
March 3, 2026
Last Seen
September 8, 2026
API
Overview
Recent Events
Profile
Profile
MITRE ATT&CK
1 / 2
Exploited By
Voodoo Bear
Apt44
Seashell Blizzard
Mexican Mafia
Sandworm
MexicanMafia
Pancho Villa
PanchoVilla
Salty Spider
Unc6353
Associated Malware
NotPetya
Coruna
Chisel
Neo-reGeorg
Sality
Cobalt Strike
CryptoWaters
EggJagger
Tools Used
Kimera
Coruna Exploit Kit
Impacket
PSExec
AnyDesk
Bloodhound
Dalfox
Dnsx
Related CVEs
CVE-2026-41091
CVE-2026-42897
CVE-2026-42985
CVE-2026-44815
CVE-2026-45586
CVE-2026-45648
CVE-2026-45657
CVE-2026-47288
MITRE Techniques
T1021 - Remote Services
T1190 - Exploit Public-Facing Application
T1189 - Drive-by Compromise
T1505.003 - Web Shell
T1003 - OS Credential Dumping
T1566 - Phishing
T1566.001 - Spearphishing Attachment
T1486 - Data Encrypted for Impact
Campaigns
Operation Escaneo
Operation Triangulation
EternalSilence
Operation Epic Fury
Operation Zero
Triangulation
Affected Platforms
Windows
IOS
Active Directory
Apache Tomcat
Ivanti Connect Secure
Linux
Regions
Mexico
China
Russia
United States
Thailand
Sectors Affected
Government
Financial
Manufacturing
Transportation
Computer Equipment
Energy
-
REC
Recon
No techniques detected
-
RD
Resource Dev
No techniques detected
2
IA
Initial Access
T1190 - Exploit Public-Facing Application
T1566 - Phishing
3
EX
Execution
T1203 - Exploitation for Client Execution
T1059.001 - PowerShell
T1204 - User Execution
1
PE
Persistence
T1505.003 - Web Shell
1
PE
Priv Esc
T1068 - Exploitation for Privilege Escalation
-
DE
Defense Evasion
No techniques detected
2
CA
Cred Access
T1003 - OS Credential Dumping
T1110 - Brute Force
-
DI
Discovery
No techniques detected
1
LM
Lateral Mov
T1021 - Remote Services
-
CO
Collection
No techniques detected
2
C2
C2
T1071 - Application Layer Protocol
T1572 - Protocol Tunneling
2
EX
Exfil
T1041 - Exfiltration Over C2 Channel
T1567 - Exfiltration Over Web Service
1
IM
Impact
T1486 - Data Encrypted for Impact
18
techniques detected across
9
tactics
Related Clusters (12)
Operation Escaneo Targets Latin American Critical Infrastructure
Jun 18
·
4 sources
79
Sandworm Targets Critical Infrastructure with Aggressive OT Attacks
May 14
·
5 sources
77
Microsoft March 2026 Patch Tuesday Addresses 79 Vulnerabilities, Including Zero-Days
Mar 10
·
51 sources
74
Microsoft September 2026 Patch Tuesday: Record 974 Vulnerabilities Addressed
2d ago
·
76 sources
73
CISA Includes Coruna Exploit Kit iOS Vulnerabilities in KEV List
Mar 6
·
2 sources
72
Microsoft June 2026 Patch Tuesday: Record 206 Vulnerabilities Addressed
Jun 9
·
57 sources
71
Critical Calix Router Flaw Exposes Home Networks to Attack
Aug 25
·
4 sources
70
Unisoc Modem Vulnerability Allows Remote Code Execution via Video Calls
Aug 17
·
10 sources
68
Unsolved Mystery of the Shadow Brokers: NSA Hacking Tools Leak
May 26
·
5 sources
64
New Ransomware Scheme Targets Corporate Printers and BitLocker
Jul 21
·
4 sources
52
Sality Botnet Disrupted After 23 Years of Operation
Sep 2
·
36 sources
34
Coruna iOS Exploit Kit Targets Multiple Threat Actors
Mar 3
·
372 sources
33
Prev
1 / 3
Next
Related Articles (21)
Remote Code Execution RCE
www.techtarget.com
·
2d ago
Patch Tuesday
www.techtarget.com
·
2d ago
International Operation Disrupts Notorious Sality Botnet After More Than Two Decades
Linkedin
·
Sep 2
Researchers Take Down 20-Year-Old Russian Botnet
Silicon
·
Sep 2
Researchers Take Down 20-Year-Old Russian Botnet
Silicon
·
Sep 2
BleepingComputer's EternalSilence coverage
www.bleepingcomputer.com
·
Aug 25
WannaCry Ransomware: Infection, Impact, and Prevention
Cyberint
·
Jul 19
Operation Escaneo Signals Shift in LatAm Threat Landscape
Darkreading
·
Jun 18
LATAM Infrastructure Hit by Fortinet and Ivanti Exploits
Infosecurity-Magazine
·
Jun 18
Operation Escaneo: Infrastructure Exposure, TTP Analysis, and Attribution Assessment of an ...
Cloudsek
·
Jun 17
Microsoft Patch Tuesday June 2026: Record 208 CVEs, Wormable Kernel Flaw Demands Patching
Techtimes
·
Jun 10
Ghost hackers: the cybersecurity mystery that nobody has solved
Techcrunch
·
May 26
Sandworm Activity In Industrial Environments What The Data Reveals
www.nozominetworks.com
·
May 14
Sandworm uses pre-compromised OT environments instead of zero
Industrialcyber.Co
·
May 14
March 2026 Patch Tuesday: Critical Microsoft CVEs & Fixes
Absolute
·
Mar 11
3 Apple flaws from Coruna exploit kit added to CISA vulnerability list | news
Scmagazine
·
Mar 6
Coruna exploit kit: Suspected government hacking tools surface in cybercriminal hands
Scworld
·
Mar 4
iVerify Details First Known Mass iOS Attack
Iverify
·
Mar 4
A suite of government hacking tools targeting iPhones is now being used by cybercriminals
Techcrunch
·
Mar 3
Potential US-built hacking tools obtained by foreign spies and cybercriminals, research says
Nextgov
·
Mar 3
Possible U.S.-developed exploits linked to first known ‘mass’ iOS attack
Cyberscoop
·
Mar 3
Prev
1 / 5
Next
Related Entities
Voodoo Bear
Apt44
Seashell Blizzard
Mexican Mafia
Sandworm
MexicanMafia
Pancho Villa
PanchoVilla
Salty Spider
Unc6353
Unc6691
Malware