Advertisement
Transparent Tribe Targets Afghan and Indian Organizations
Pakistan-linked Transparent Tribe updates its malware toolset to target Afghan organizations and government agencies in India.
AI-Driven Cyberattack Targets APAC Government Agencies
A China-linked actor reportedly deployed a near-autonomous AI framework to compromise government agencies in the APAC region, signaling a new threat landscape.
North Korea Attribution, Data Breaches Impact OnTrac & UK Education
AWS attributes recent hacks to North Korea. OnTrac and the UK Department for Education report significant data breaches, impacting over 600,000 records.
Google Unified Threat Actor Naming: TAG and Mandiant Convergence
Google unifies threat actor naming across TAG and Mandiant to streamline attribution and improve intelligence sharing for security operations teams.
Multi-Threat Brief: AI Malware, Zimbra Exploits, Linux Kernel Flaws
Analysis of recent threats including DolphinX AI malware, state-sponsored Zimbra exploits, Siemens industrial switch vulnerabilities, and 400 Linux kernel flaws.
ViPNet Update Mechanism Abused in Russian Government Targeting
Threat actors are leveraging the ViPNet private networking suite's update mechanism to distribute malware to Russian government and financial entities.
Advertisement
Advanced Persistent Threat Tracking: Intelligence for Detection
Understand the methodologies and critical role of real-time cyber intelligence in detecting and mitigating Advanced Persistent Threat (APT) group activities.
AI-Enhanced Cyber Operations: Analyzing Iran's Asymmetric Playbook
Analysis of how Iranian state actors integrate artificial intelligence into cyber operations, influence campaigns, and domestic surveillance for asymmetric gains.
Parallel APT Cyber Espionage Targets Balochistan Police
Analysis of parallel cyber espionage campaigns by China and India-linked APTs against Pakistan's Balochistan Police, detailed by SentinelOne.
Iranian-Nexus TAG-182 Deploys MarkiRAT Android Surveillance
Runtime Rebel analyzes Iranian-nexus TAG-182's use of MarkiRAT malware. Disguised as fake VPN/media apps, it conducts cyber surveillance against domestic targets.
Mustang Panda Exploits Zoho WorkDrive for C2 in Indian Govt Attacks
Mustang Panda, a China-aligned APT, targets Indian government and hydropower entities, leveraging Zoho WorkDrive as a C2 channel and deploying new malware.
Turla's STOCKSTAY Backdoor: Analysis of Campaigns & WinRAR Exploit
Google Threat Intelligence details STOCKSTAY, Turla's .NET backdoor for espionage targeting Ukraine and Europe, leveraging RDP & CVE-2025-8088.
North Korean APT Targets Developers via Malicious Tooling
North Korean threat cluster Contagious Interview exploits developer recruitment and code review phishing to deliver malware via tainted dev tools.
UNC6508: Chinese Cyberespionage Targets North American Research
Google's Threat Intelligence Group tracks UNC6508, a Chinese cyberespionage group targeting North American medical, military, and AI research sectors.
Chinese Hackers Hijack Auth Flow for Decade-Long Espionage
Chinese state-sponsored hackers maintained long-term access to an isolated network by hijacking the authentication flow, enabling a decade of espionage.
Chinese and North Korean APT Activity Surges Across APAC Markets
Chinese and North Korean threat groups are intensifying operations in Asia-Pacific, impacting regional economies and targeting financial institutions for profit.
Chinese APT UNC5221 Deploys New Malware for M365 Persistence
Chinese APT UNC5221 leverages new malware, Plenet and AgentPSD, alongside Brickstorm backdoor to maintain persistent access in compromised Microsoft 365 environments for…
GreyVibe Threat Actor Leverages AI for Cyberattack Operations
Russia-linked GreyVibe threat actors are using AI tools like ChatGPT and Gemini to enhance cyberattacks, signaling a critical evolution in TTPs.
Ghostwriter Targets Ukraine Government with Prometheus Phishing
Belarus-aligned Ghostwriter (UAC-0057) targets Ukrainian government entities with Prometheus-themed phishing emails to deploy sophisticated malware.
Turla Updates Kazuar Backdoor with Modular P2P Botnet Capabilities
Russian threat actor Turla (Secret Blizzard) has upgraded its Kazuar backdoor with peer-to-peer botnet functionality and modular architecture for stealth.
FrostyNeighbor APT Targets Poland/Ukraine Gov with Spear-Phishing
Belarussian APT 'FrostyNeighbor' is deploying spear-phishing campaigns against Polish and Ukrainian government entities after unique victim fingerprinting, aiming for…
Ghostwriter Targets Ukraine with Geofenced PDF Phishing & Cobalt Strike
Ghostwriter (UAC-0057) leverages geofenced PDF phishing to deliver Cobalt Strike against Ukrainian government entities, combining espionage and influence.
MuddyWater Targets South Korean Electronics Maker in Espionage Campaign
Iran-linked MuddyWater (Seedworm) group launched a cyber-espionage campaign against a major South Korean electronics maker and other global entities.
MuddyWater Exploits Microsoft Teams for False Flag Ransomware
Iranian APT MuddyWater is leveraging Microsoft Teams social engineering to deploy false flag ransomware, obscuring state-sponsored espionage activities.