Skip to main content
← All Articles

Tag

#APT

53 articles

Advertisement

Transparent Tribe Targets Afghan and Indian Organizations
MEDIUM
Threat Intel

Transparent Tribe Targets Afghan and Indian Organizations

Pakistan-linked Transparent Tribe updates its malware toolset to target Afghan organizations and government agencies in India.

Runtime Rebel Intel
2 min read · Aug 20, 2026
AI-Driven Cyberattack Targets APAC Government Agencies
HIGH
Threat Intel

AI-Driven Cyberattack Targets APAC Government Agencies

A China-linked actor reportedly deployed a near-autonomous AI framework to compromise government agencies in the APAC region, signaling a new threat landscape.

Runtime Rebel Intel
4 min read · Aug 19, 2026
HIGH
Threat Intel

North Korea Attribution, Data Breaches Impact OnTrac & UK Education

AWS attributes recent hacks to North Korea. OnTrac and the UK Department for Education report significant data breaches, impacting over 600,000 records.

Runtime Rebel Intel
4 min read · Jul 31, 2026
INFO
Threat Intel

Google Unified Threat Actor Naming: TAG and Mandiant Convergence

Google unifies threat actor naming across TAG and Mandiant to streamline attribution and improve intelligence sharing for security operations teams.

Runtime Rebel Intel
3 min read · Jul 28, 2026
HIGH
Threat Intel

Multi-Threat Brief: AI Malware, Zimbra Exploits, Linux Kernel Flaws

Analysis of recent threats including DolphinX AI malware, state-sponsored Zimbra exploits, Siemens industrial switch vulnerabilities, and 400 Linux kernel flaws.

Runtime Rebel Intel
5 min read · Jul 24, 2026
HIGH
Threat Intel

ViPNet Update Mechanism Abused in Russian Government Targeting

Threat actors are leveraging the ViPNet private networking suite's update mechanism to distribute malware to Russian government and financial entities.

Runtime Rebel Intel
3 min read · Jul 19, 2026

Advertisement

Advanced Persistent Threat Tracking: Intelligence for Detection
INFO
Threat Intel

Advanced Persistent Threat Tracking: Intelligence for Detection

Understand the methodologies and critical role of real-time cyber intelligence in detecting and mitigating Advanced Persistent Threat (APT) group activities.

Runtime Rebel Intel
4 min read · Jul 17, 2026
AI-Enhanced Cyber Operations: Analyzing Iran's Asymmetric Playbook
MEDIUM
Threat Intel

AI-Enhanced Cyber Operations: Analyzing Iran's Asymmetric Playbook

Analysis of how Iranian state actors integrate artificial intelligence into cyber operations, influence campaigns, and domestic surveillance for asymmetric gains.

Runtime Rebel Intel
3 min read · Jul 16, 2026
HIGH
Threat Intel

Parallel APT Cyber Espionage Targets Balochistan Police

Analysis of parallel cyber espionage campaigns by China and India-linked APTs against Pakistan's Balochistan Police, detailed by SentinelOne.

Runtime Rebel Intel
4 min read · Jul 10, 2026
Iranian-Nexus TAG-182 Deploys MarkiRAT Android Surveillance
HIGH
Threat Intel

Iranian-Nexus TAG-182 Deploys MarkiRAT Android Surveillance

Runtime Rebel analyzes Iranian-nexus TAG-182's use of MarkiRAT malware. Disguised as fake VPN/media apps, it conducts cyber surveillance against domestic targets.

Runtime Rebel Intel
5 min read · Jul 2, 2026
Mustang Panda Exploits Zoho WorkDrive for C2 in Indian Govt Attacks
HIGH
Threat Intel

Mustang Panda Exploits Zoho WorkDrive for C2 in Indian Govt Attacks

Mustang Panda, a China-aligned APT, targets Indian government and hydropower entities, leveraging Zoho WorkDrive as a C2 channel and deploying new malware.

Runtime Rebel Intel
4 min read · Jun 29, 2026
HIGH
Threat Intel

Turla's STOCKSTAY Backdoor: Analysis of Campaigns & WinRAR Exploit

Google Threat Intelligence details STOCKSTAY, Turla's .NET backdoor for espionage targeting Ukraine and Europe, leveraging RDP & CVE-2025-8088.

Runtime Rebel Intel
13 min read · Jun 26, 2026
North Korean APT Targets Developers via Malicious Tooling
HIGH
Threat Intel

North Korean APT Targets Developers via Malicious Tooling

North Korean threat cluster Contagious Interview exploits developer recruitment and code review phishing to deliver malware via tainted dev tools.

Runtime Rebel Intel
4 min read · Jun 16, 2026
HIGH
Threat Intel

UNC6508: Chinese Cyberespionage Targets North American Research

Google's Threat Intelligence Group tracks UNC6508, a Chinese cyberespionage group targeting North American medical, military, and AI research sectors.

Runtime Rebel Intel
4 min read · Jun 15, 2026
HIGH
Threat Intel

Chinese Hackers Hijack Auth Flow for Decade-Long Espionage

Chinese state-sponsored hackers maintained long-term access to an isolated network by hijacking the authentication flow, enabling a decade of espionage.

Runtime Rebel Intel
5 min read · Jun 13, 2026
Chinese and North Korean APT Activity Surges Across APAC Markets
MEDIUM
Threat Intel

Chinese and North Korean APT Activity Surges Across APAC Markets

Chinese and North Korean threat groups are intensifying operations in Asia-Pacific, impacting regional economies and targeting financial institutions for profit.

Runtime Rebel Intel
3 min read · Jun 11, 2026
HIGH
Threat Intel

Chinese APT UNC5221 Deploys New Malware for M365 Persistence

Chinese APT UNC5221 leverages new malware, Plenet and AgentPSD, alongside Brickstorm backdoor to maintain persistent access in compromised Microsoft 365 environments for…

Runtime Rebel Intel
5 min read · Jun 5, 2026
HIGH
Threat Intel

GreyVibe Threat Actor Leverages AI for Cyberattack Operations

Russia-linked GreyVibe threat actors are using AI tools like ChatGPT and Gemini to enhance cyberattacks, signaling a critical evolution in TTPs.

Runtime Rebel Intel
5 min read · May 28, 2026
Ghostwriter Targets Ukraine Government with Prometheus Phishing
HIGH
Threat Intel

Ghostwriter Targets Ukraine Government with Prometheus Phishing

Belarus-aligned Ghostwriter (UAC-0057) targets Ukrainian government entities with Prometheus-themed phishing emails to deploy sophisticated malware.

Runtime Rebel Intel
4 min read · May 22, 2026
HIGH
Threat Intel

Turla Updates Kazuar Backdoor with Modular P2P Botnet Capabilities

Russian threat actor Turla (Secret Blizzard) has upgraded its Kazuar backdoor with peer-to-peer botnet functionality and modular architecture for stealth.

Runtime Rebel Intel
4 min read · May 16, 2026
FrostyNeighbor APT Targets Poland/Ukraine Gov with Spear-Phishing
HIGH
Threat Intel

FrostyNeighbor APT Targets Poland/Ukraine Gov with Spear-Phishing

Belarussian APT 'FrostyNeighbor' is deploying spear-phishing campaigns against Polish and Ukrainian government entities after unique victim fingerprinting, aiming for…

Runtime Rebel Intel
4 min read · May 14, 2026
Ghostwriter Targets Ukraine with Geofenced PDF Phishing & Cobalt Strike
HIGH
Threat Intel

Ghostwriter Targets Ukraine with Geofenced PDF Phishing & Cobalt Strike

Ghostwriter (UAC-0057) leverages geofenced PDF phishing to deliver Cobalt Strike against Ukrainian government entities, combining espionage and influence.

Runtime Rebel Intel
4 min read · May 14, 2026
HIGH
Threat Intel

MuddyWater Targets South Korean Electronics Maker in Espionage Campaign

Iran-linked MuddyWater (Seedworm) group launched a cyber-espionage campaign against a major South Korean electronics maker and other global entities.

Runtime Rebel Intel
4 min read · May 14, 2026
MuddyWater Exploits Microsoft Teams for False Flag Ransomware
HIGH
Threat Intel

MuddyWater Exploits Microsoft Teams for False Flag Ransomware

Iranian APT MuddyWater is leveraging Microsoft Teams social engineering to deploy false flag ransomware, obscuring state-sponsored espionage activities.

Runtime Rebel Intel
3 min read · May 6, 2026