Skip to main content
← All Articles

Tag

#APT

53 articles

Advertisement

China-Linked UAT-8302 Targets Governments with Custom APT Malware
HIGH
Threat Intel

China-Linked UAT-8302 Targets Governments with Custom APT Malware

UAT-8302, a China-linked threat group, targets government entities in South America and SE Europe using custom malware and shared APT toolsets.

Runtime Rebel Intel
3 min read · May 5, 2026
Silver Fox APT: Tax-Themed Phishing Delivers ABCDoor to India, Russia
HIGH
Threat Intel

Silver Fox APT: Tax-Themed Phishing Delivers ABCDoor to India, Russia

China-backed Silver Fox APT targets organizations in India and Russia with over 1,600 tax-themed phishing messages to deploy ABCDoor backdoor and ValleyRAT.

Runtime Rebel Intel
4 min read · May 4, 2026
20 Years of Threat Intel: Analyzing Adversarial Evolution Since 2006
INFO
Threat Intel

20 Years of Threat Intel: Analyzing Adversarial Evolution Since 2006

Historical analysis of cybersecurity threat evolution over two decades, focusing on the transition from simple exploits to complex APT campaigns.

Runtime Rebel Intel
4 min read · May 1, 2026
Lazarus Group's $2B+ Crypto Theft: Defending Against Supply Chain Attacks
HIGH
Threat Intel

Lazarus Group's $2B+ Crypto Theft: Defending Against Supply Chain Attacks

An analysis of Lazarus Group's persistent and financially motivated cyber operations, highlighting over $2B in crypto theft and critical supply chain attack risks.

Runtime Rebel Intel
5 min read · Apr 28, 2026
INFO
Threat Intel

Alleged Silk Typhoon Hacker Extradited: Cyberespionage Threat

An alleged Silk Typhoon hacker, associated with Chinese intelligence, has been extradited to the US, highlighting persistent nation-state cyberespionage threats.

Runtime Rebel Intel
4 min read · Apr 27, 2026
Chinese State-Backed Actors Industrialize Botnets for Covert Ops
HIGH
Threat Intel

Chinese State-Backed Actors Industrialize Botnets for Covert Ops

Chinese state-backed groups are adopting industrialized botnets, utilizing compromised devices for low-cost, low-risk, and deniable cyber operations.

Runtime Rebel Intel
5 min read · Apr 24, 2026

Advertisement

CRITICAL
Malware

FIRESTARTER Backdoor: Persistent Threat to Cisco Firepower & Secure Firewall

CISA and NCSC warn of FIRESTARTER, an APT-deployed backdoor maintaining persistence on Cisco Firepower and Secure Firewall devices post-patching.

Runtime Rebel Intel
6 min read · Apr 23, 2026
HIGH
Threat Intel

GopherWhisper APT Abuses Outlook and Slack for Stealthy C2

Newly discovered GopherWhisper APT group uses a Go-based toolkit and legitimate SaaS platforms like Slack and Outlook to conduct espionage against governments.

Runtime Rebel Intel
3 min read · Apr 23, 2026
Sapphire Sleet's ClickFix: North Korea Targets macOS Users
HIGH
Threat Intel

Sapphire Sleet's ClickFix: North Korea Targets macOS Users

North Korea-backed Sapphire Sleet is deploying ClickFix malware via fake job offers and phony Zoom updates to steal macOS user credentials and data.

Runtime Rebel Intel
4 min read · Apr 16, 2026
Iran Geopolitical Tensions: Cyber Implications & Preparedness
INFO
Threat Intel

Iran Geopolitical Tensions: Cyber Implications & Preparedness

Examine the potential cybersecurity implications of escalating geopolitical tensions involving Iran, focusing on nation-state TTPs and organizational preparedness…

Runtime Rebel Intel
4 min read · Apr 14, 2026
UAT-10362 Targets Taiwanese NGOs with LucidRook Malware
HIGH
Threat Intel

UAT-10362 Targets Taiwanese NGOs with LucidRook Malware

Runtime Rebel analyzes UAT-10362's sophisticated spear-phishing campaigns deploying new Lua-based LucidRook malware against Taiwanese NGOs and universities.

Runtime Rebel Intel
4 min read · Apr 10, 2026
TA416 Targets European Govts with PlugX & OAuth Phishing
HIGH
Threat Intel

TA416 Targets European Govts with PlugX & OAuth Phishing

China-linked TA416 has resumed targeting European government and diplomatic entities since mid-2025 using PlugX and OAuth-based phishing attacks.

Runtime Rebel Intel
4 min read · Apr 3, 2026
Quantum Geopolitics: Cyber Threats in an Era of Iran Conflict
INFO
Threat Intel

Quantum Geopolitics: Cyber Threats in an Era of Iran Conflict

Analyze how the shift toward quantum geopolitics and Iranian proxy conflicts impact global cyber stability and critical infrastructure protection.

Runtime Rebel Intel
3 min read · Apr 2, 2026
HIGH
Threat Intel

Iranian Hackers Target Kash Patel: US Offers $10M Bounty

The FBI confirms Iranian state-sponsored hackers compromised Kash Patel’s personal email, leading the U.S. to offer a $10M reward for information.

Runtime Rebel Intel
4 min read · Mar 30, 2026
China-Linked APT Clusters Target SE Asian Government via HIUPAN
HIGH
Threat Intel

China-Linked APT Clusters Target SE Asian Government via HIUPAN

Three China-linked threat clusters targeted a Southeast Asian government in 2025 using HIUPAN, PUBLOAD, and EggStremeFuel malware in a complex espionage operation.

Runtime Rebel Intel
3 min read · Mar 30, 2026
Red Menshen APT Deploys Upgraded BPFdoor Backdoor Against Telcos
HIGH
Threat Intel

Red Menshen APT Deploys Upgraded BPFdoor Backdoor Against Telcos

Chinese APT Red Menshen utilizes an upgraded BPFdoor backdoor to target global telecommunication companies, bypassing traditional defenses.

Runtime Rebel Intel
4 min read · Mar 27, 2026
Red Menshen BPFDoor Implants Target Telecom Networks for Espionage
HIGH
Threat Intel

Red Menshen BPFDoor Implants Target Telecom Networks for Espionage

Analysis of China-linked Red Menshen's long-term campaign using stealthy BPFDoor implants within telecom networks to conduct espionage against government entities.

Runtime Rebel Intel
4 min read · Mar 26, 2026
HIGH
Threat Intel

Russian Intelligence Phishing Targets Signal and WhatsApp Users

The FBI warns of sophisticated phishing campaigns by Russian intelligence targeting Signal and WhatsApp users to harvest credentials and bypass encryption.

Runtime Rebel Intel
4 min read · Mar 21, 2026
HIGH
Threat Intel

Bitrefill Attributes Cyberattack to North Korean Lazarus Group

Bitrefill identifies North Korean Lazarus Group as the perpetrator of a recent cyberattack, underscoring the persistent threat to crypto-focused businesses.

Runtime Rebel Intel
3 min read · Mar 19, 2026
SideWinder APT Expands Southeast Asia Espionage Campaign
HIGH
Threat Intel

SideWinder APT Expands Southeast Asia Espionage Campaign

SideWinder APT targets government and telecom sectors in Southeast Asia using spear-phishing and rotating infrastructure for persistent espionage operations.

Runtime Rebel Intel
3 min read · Mar 18, 2026
Konni Group Deploys EndRAT via Phishing and KakaoTalk Hijacking
HIGH
Threat Intel

Konni Group Deploys EndRAT via Phishing and KakaoTalk Hijacking

North Korean threat actor Konni leverages spear-phishing and KakaoTalk desktop exploitation to distribute EndRAT malware and facilitate lateral movement.

Runtime Rebel Intel
3 min read · Mar 17, 2026
HIGH
Threat Intel

Poland’s Nuclear Center Targeted in Suspected Iranian Cyberattack

Polish officials investigate a cyberattack at the NCBJ nuclear center. Initial evidence points to Iran, but investigators warn of potential false flag tactics.

Runtime Rebel Intel
4 min read · Mar 16, 2026
Iranian MOIS Collusion with Cybercriminals: Evolving Hybrid Threat
HIGH
Threat Intel

Iranian MOIS Collusion with Cybercriminals: Evolving Hybrid Threat

Iranian state-sponsored APTs, linked to MOIS, are now directly collaborating with cybercriminal organizations, escalating hybrid cyber operations. Defenders must adapt.

Runtime Rebel Intel
4 min read · Mar 13, 2026
HIGH
Threat Intel

TfL Data Breach and Avira Security Flaws: Weekly Threat Briefing

Analysis of the Transport for London breach affecting 10 million users, Avira antivirus security flaws, and North Korean cyber actor attribution.

Runtime Rebel Intel
3 min read · Mar 6, 2026