Skip to main content
← All Articles

Tag

#State Sponsored

17 articles

Advertisement

PurpleDelta: North Korean IT Workers Exploit Remote Hiring
MEDIUM
Threat Intel

PurpleDelta: North Korean IT Workers Exploit Remote Hiring

Recorded Future exposes PurpleDelta, North Korean IT workers using sophisticated fraudulent employment, AI, and extensive vetting evasion to fund DPRK military programs.

Runtime Rebel Intel
4 min read · Aug 18, 2026
Microsoft OWA Exploit: Russian Hackers Bypass Credential Rotations
HIGH
Threat Intel

Microsoft OWA Exploit: Russian Hackers Bypass Credential Rotations

Russian threat actors exploit a Microsoft Outlook Web Access (OWA) flaw to maintain persistent mailbox access even after passwords are changed or rotated.

Runtime Rebel Intel
4 min read · Jul 30, 2026
Zimbra Zero-Day Exploited by Laundry Bear Against US & Ukraine
HIGH
Threat Intel

Zimbra Zero-Day Exploited by Laundry Bear Against US & Ukraine

Russian state-sponsored group 'Laundry Bear' exploits a Zimbra zero-day via 'half-click' phishing, targeting US and Ukrainian entities for credential theft and backdoor…

Runtime Rebel Intel
4 min read · Jul 24, 2026
Iran-Linked Hackers Deploy New Cavern C2 Against Israeli Targets
HIGH
Threat Intel

Iran-Linked Hackers Deploy New Cavern C2 Against Israeli Targets

Iranian state-sponsored threat actors are using a novel modular C2 framework, Cavern (Cav3rn), to compromise Israeli IT and government entities.

Runtime Rebel Intel
4 min read · Jul 6, 2026
China-Linked APT Targets Southeast Asia Critical Systems with New Backdoor
HIGH
Threat Intel

China-Linked APT Targets Southeast Asia Critical Systems with New Backdoor

A China-linked APT group has compromised ten organizations, including state-owned entities in Southeast Asia, deploying a new backdoor.

Runtime Rebel Intel
4 min read · Jul 1, 2026
HIGH
Threat Intel

US Targets Russian-Linked UNC5792, UNC4221 Hackers of Messaging Apps

US State Dept. offers $10M for info on Russian-linked UNC5792 & UNC4221 groups targeting WhatsApp, Signal users. Learn about nation-state threats.

Runtime Rebel Intel
4 min read · Jun 29, 2026

Advertisement

JDY Botnet Expansion: China-Linked Reconnaissance on SOHO/IoT Devices
HIGH
Threat Intel

JDY Botnet Expansion: China-Linked Reconnaissance on SOHO/IoT Devices

China-linked JDY botnet now controls 1,500+ SOHO/IoT devices, actively expanding cyber reconnaissance for state-sponsored operations.

Runtime Rebel Intel
4 min read · Jun 10, 2026
UAE Critical Infrastructure Faces Surge in Geopolitical Cyberattacks
HIGH
Threat Intel

UAE Critical Infrastructure Faces Surge in Geopolitical Cyberattacks

Breach attempts against the UAE have tripled following regional tensions, specifically targeting critical infrastructure and government sectors.

Runtime Rebel Intel
4 min read · May 6, 2026
HIGH
Malware

DarkSword: Analyzing the GTIG iOS Full-Chain Zero-Day Exploit

Google Threat Intelligence Group uncovers DarkSword, a sophisticated iOS exploit chain leveraging multiple zero-days for state-sponsored surveillance.

Runtime Rebel Intel
3 min read · May 5, 2026
HIGH
Threat Intel

Fast16 Malware: Analyzing the Precursor to Stuxnet Sabotage

Analysis of the Fast16 malware, a state-sponsored tool designed to sabotage high-precision mathematical simulations and physical computation processes.

Runtime Rebel Intel
4 min read · Apr 30, 2026
Grinex Exchange Shuts Down After $13.74M State-Sponsored Hack
MEDIUM
Threat Intel

Grinex Exchange Shuts Down After $13.74M State-Sponsored Hack

Sanctioned exchange Grinex halts operations following a $13.74M hack attributed to Western intelligence agencies. Analysis of TTPs and geopolitical impact.

Runtime Rebel Intel
4 min read · Apr 18, 2026
HIGH
Vulnerabilities

Apple DarkSword Protection Expands: Mitigating CVE-2023-38604 Zero-Click Exploits

Apple expands DarkSword exploit protection to all users, enhancing defenses against state-sponsored and commercial zero-click attacks like CVE-2023-38604.

Runtime Rebel Intel
4 min read · Apr 2, 2026
HIGH
Threat Intel

Coruna: Sophisticated iPhone Hacking Toolkit Bypasses iOS Defenses

Google researchers uncovered "Coruna," a powerful iOS exploit kit leveraging 23 vulnerabilities to silently install malware on iPhones, likely state-sponsored.

Runtime Rebel Intel
5 min read · Apr 2, 2026
HIGH
Threat Intel

Star Blizzard (APT28) Adopts DarkSword iOS Exploit Kit

Russian APT Star Blizzard (APT28) now uses the DarkSword iOS exploit kit to target government, finance, and academia, increasing mobile threat exposure.

Runtime Rebel Intel
5 min read · Mar 30, 2026
HIGH
Threat Intel

Iranian Hackers Target Kash Patel: US Offers $10M Bounty

The FBI confirms Iranian state-sponsored hackers compromised Kash Patel’s personal email, leading the U.S. to offer a $10M reward for information.

Runtime Rebel Intel
4 min read · Mar 30, 2026
MEDIUM
Threat Intel

Iranian Cyber Infrastructure Hardening Ahead of Operation Epic Fury

Analysis of Iran's six-month buildup of US-based shell companies and resilient cyber infrastructure to survive kinetic strikes and maintain hacking operations.

Runtime Rebel Intel
3 min read · Mar 19, 2026
HIGH
Threat Intel

Google Disrupts Chinese Espionage Actor UNC2814 Targeting Telecoms

Google and Mandiant disrupt UNC2814, a Chinese state-sponsored actor active since 2017, targeting 42 countries across telecom and government sectors.

Runtime Rebel Intel
4 min read · Feb 25, 2026