Skip to main content
← All Articles

Tag

#APT

40 articles

Advertisement

FrostyNeighbor APT Targets Poland/Ukraine Gov with Spear-Phishing
CRITICAL
Threat Intel

FrostyNeighbor APT Targets Poland/Ukraine Gov with Spear-Phishing

Belarussian APT 'FrostyNeighbor' is deploying spear-phishing campaigns against Polish and Ukrainian government entities after unique victim fingerprinting, aiming for

Runtime Rebel Intel
4 min read·May 14, 2026
Ghostwriter Targets Ukraine with Geofenced PDF Phishing & Cobalt Strike
HIGH
Threat Intel

Ghostwriter Targets Ukraine with Geofenced PDF Phishing & Cobalt Strike

Ghostwriter (UAC-0057) leverages geofenced PDF phishing to deliver Cobalt Strike against Ukrainian government entities, combining espionage and influence.

Runtime Rebel Intel
3 min read·May 14, 2026
TH
CRITICAL
Threat Intel

MuddyWater Targets South Korean Electronics Maker in Espionage Campaign

Iran-linked MuddyWater (Seedworm) group launched a cyber-espionage campaign against a major South Korean electronics maker and other global entities. Learn TTPs and

Runtime Rebel Intel
4 min read·May 14, 2026
MuddyWater Exploits Microsoft Teams for False Flag Ransomware
HIGH
Threat Intel

MuddyWater Exploits Microsoft Teams for False Flag Ransomware

Iranian APT MuddyWater is leveraging Microsoft Teams social engineering to deploy false flag ransomware, obscuring state-sponsored espionage activities.

Runtime Rebel Intel
3 min read·May 6, 2026
China-Linked UAT-8302 Targets Governments with Custom APT Malware
HIGH
Threat Intel

China-Linked UAT-8302 Targets Governments with Custom APT Malware

UAT-8302, a China-linked threat group, targets government entities in South America and SE Europe using custom malware and shared APT toolsets.

Runtime Rebel Intel
3 min read·May 5, 2026
Silver Fox APT: Tax-Themed Phishing Delivers ABCDoor to India, Russia
HIGH
Threat Intel

Silver Fox APT: Tax-Themed Phishing Delivers ABCDoor to India, Russia

China-backed Silver Fox APT targets organizations in India and Russia with over 1,600 tax-themed phishing messages to deploy ABCDoor backdoor and ValleyRAT.

Runtime Rebel Intel
4 min read·May 4, 2026
Lazarus Group's $2B+ Crypto Theft: Defending Against Supply Chain Attacks
CRITICAL
Threat Intel

Lazarus Group's $2B+ Crypto Theft: Defending Against Supply Chain Attacks

An analysis of Lazarus Group's persistent and financially motivated cyber operations, highlighting over $2B in crypto theft and critical supply chain attack risks.

Runtime Rebel Intel
5 min read·Apr 28, 2026
TH
INFO
Threat Intel

Alleged Silk Typhoon Hacker Extradited: Cyberespionage Threat

An alleged Silk Typhoon hacker, associated with Chinese intelligence, has been extradited to the US, highlighting persistent nation-state cyberespionage threats.

Runtime Rebel Intel
4 min read·Apr 27, 2026
Chinese State-Backed Actors Industrialize Botnets for Covert Ops
CRITICAL
Threat Intel

Chinese State-Backed Actors Industrialize Botnets for Covert Ops

Chinese state-backed groups are adopting industrialized botnets, utilizing compromised devices for low-cost, low-risk, and deniable cyber operations.

Runtime Rebel Intel
4 min read·Apr 24, 2026
MA
CRITICAL
Malware

FIRESTARTER Backdoor: Persistent Threat to Cisco Firepower & Secure Firewall

CISA and NCSC warn of FIRESTARTER, an APT-deployed backdoor maintaining persistence on Cisco Firepower and Secure Firewall devices post-patching.

Runtime Rebel Intel
6 min read·Apr 23, 2026
TH
CRITICAL
Threat Intel

GopherWhisper APT Abuses Outlook and Slack for Stealthy C2

Newly discovered GopherWhisper APT group uses a Go-based toolkit and legitimate SaaS platforms like Slack and Outlook to conduct espionage against governments.

Runtime Rebel Intel
3 min read·Apr 23, 2026
Sapphire Sleet's ClickFix: North Korea Targets macOS Users
HIGH
Threat Intel

Sapphire Sleet's ClickFix: North Korea Targets macOS Users

North Korea-backed Sapphire Sleet is deploying ClickFix malware via fake job offers and phony Zoom updates to steal macOS user credentials and data. Learn how to detect

Runtime Rebel Intel
4 min read·Apr 16, 2026