Skip to main content
← All Articles

Tag

#APT

32 articles

Advertisement

SideWinder APT Expands Southeast Asia Espionage Campaign
HIGH
Threat Intel

SideWinder APT Expands Southeast Asia Espionage Campaign

SideWinder APT targets government and telecom sectors in Southeast Asia using spear-phishing and rotating infrastructure for persistent espionage operations.

Runtime Rebel Intel
3 min read·Mar 18, 2026
TH
HIGH
Threat Intel

Poland’s Nuclear Center Targeted in Suspected Iranian Cyberattack

Polish officials investigate a cyberattack at the NCBJ nuclear center. Initial evidence points to Iran, but investigators warn of potential false flag tactics.

Runtime Rebel Intel
3 min read·Mar 16, 2026
Iranian MOIS Collusion with Cybercriminals: Evolving Hybrid Threat
HIGH
Threat Intel

Iranian MOIS Collusion with Cybercriminals: Evolving Hybrid Threat

Iranian state-sponsored APTs, linked to MOIS, are now directly collaborating with cybercriminal organizations, escalating hybrid cyber operations. Defenders must adapt.

Runtime Rebel Intel
4 min read·Mar 13, 2026
TH
CRITICAL
Threat Intel

Coruna Exploit Kit: iOS 13-17.2.1 Targeted by Multiple APTs

Google Threat Intelligence Group details Coruna, a powerful iOS exploit kit targeting versions 13.0 to 17.2.1, used by commercial vendors and nation-state actors for

Runtime Rebel Intel
5 min read·Mar 3, 2026
Google Disrupts UNC2814 GRIDTIDE Infrastructure After 53 Breaches
HIGH
Threat Intel

Google Disrupts UNC2814 GRIDTIDE Infrastructure After 53 Breaches

Google disrupts infrastructure of China-nexus threat actor UNC2814 (GRIDTIDE) after 53 breaches across 42 countries targeting government and telecom sectors.

Runtime Rebel Intel
3 min read·Feb 25, 2026
TH
CRITICAL
Threat Intel

UNC6201 Exploits Dell RecoverPoint Zero-Day CVE-2026-22769

Mandiant and GTIG detail UNC6201's exploitation of CVE-2026-22769 in Dell RecoverPoint for VMs, deploying GRIMBOLT backdoor and novel VMware TTPs.

Runtime Rebel Intel
6 min read·Feb 25, 2026
Lazarus Group Shifts to Medusa Ransomware & Multi-Tool Attacks
HIGH
Threat Intel

Lazarus Group Shifts to Medusa Ransomware & Multi-Tool Attacks

North Korea's Lazarus Group now employs Medusa ransomware, Comebacker backdoor, Blindingcan RAT, and Infohook info stealer in recent attacks, signaling an evolving

Runtime Rebel Intel
4 min read·Feb 25, 2026
Iranian APT MuddyWater Orchestrates Operation Olalampo Targeting MENA Infrastructure
HIGH
Threat Intel

Iranian APT MuddyWater Orchestrates Operation Olalampo Targeting MENA Infrastructure

Analysis of a new Iranian cyber-espionage campaign utilizing GhostFetch, CHAR, and HTTP_VIP malware families against organizations in the Middle East and North Africa.

Runtime Rebel Intel
2 min read·Feb 23, 2026