Skip to content
Threat Feed

Tag

Apt

23 briefs RSS
high threat

Mirage Kitten Targets Middle East and Africa with New Malware

Mirage Kitten, an advanced persistent threat (APT) group, is deploying new Windows backdoor (NightLedger) and WebSocket tunnelers (ArcBridge, BridgeHead) via spear-phishing campaigns to conduct cyber-espionage and data exfiltration against aerospace, aviation, defense, and telecommunications sectors in the Middle East and Europe.

Windows Mirage Kitten cyber-espionage apt malware backdoor tunneler dll-hijacking websocket spear-phishing
4r 13t 3i
critical threat

TA488 Exploits Zimbra Mailservers with Half-Click Vulnerability CVE-2025-66376

Russia-aligned threat actor TA488 (Void Blizzard, Laundry Bear) exploited CVE-2025-66376, a critical XSS vulnerability in Zimbra Collaboration Suite webmail, for at least five months in 2025 via crafted emails to gain persistent access, exfiltrate user credentials, 2FA codes, and bulk emails from Ukrainian government and US defense industrial base targets.

PoC Zimbra Collaboration Suite +10 TA488 +2 espionage xss zimbra apt state-sponsored half-click cve-2025-66376
2r 9t 3c 7i updated
high advisory

Midyear Assessment of Iran-Linked Cyber Threat Landscape

SentinelOne Labs' midyear assessment highlights that Iran-linked cyber operations, involving groups like MuddyWater/Seedworm, Screening Serpens, APT42, and persona groups such as Handala, focus on persistent access, espionage, and selective disruption, often leveraging social engineering, compromised service providers, and RMM abuse, with increasing risk to operational technology environments.

iran espionage destructive-malware social-engineering operational-technology rmm supply-chain threat-assessment +1
12t
high advisory

New GoSerpent Malware Targets Southeast Asian Governments and Diplomats for Espionage

A sophisticated Go-based implant, dubbed GoSerpent, has been utilized by an unidentified threat actor since late 2025 to conduct cyber espionage against government and diplomatic entities in Southeast Asia, focusing on long-term access, sensitive data collection, and credential dumping for exfiltration.

espionage malware Go RAT APT Southeast Asia
2r 6t
high advisory

HelloNet Campaign Uses ViPNet Update System for Malicious Module Delivery

An unknown sophisticated threat actor is leveraging DLL sideloading within the ViPNet update system to deploy a multi-stage malware suite, including HelloInjector, HelloProxy, HelloExecutor, HelloCleaner, and HelloBackdoor, to establish persistence, exfiltrate data, and maintain covert access to large Russian organizations in government, energy, and other critical sectors.

ViPNet Update System apt dll-sideloading persistence proxy c2 reconnaissance data-exfiltration russia +1
3r 11t 1i
critical threat

Targeting and Compromise of French Entities Using the Turla Intrusion Set

The Turla intrusion set, operated by the 16th Centre of the Federal Security Service (FSB) of Russia, has been targeting French entities and other strategic organizations globally since at least 2004 for intelligence-gathering purposes, with victims in France including ministries and entities within the diplomatic, defence, justice, and technology sectors.

Turla +4 nation-state espionage APT russia france
high threat

UAT-7810 Expands ORB Networks with New Malware; ARToken Phishing-as-a-Service and Device Vulnerabilities Highlighted

The China-nexus threat actor UAT-7810 is expanding its Operational Relay Box (ORB) networks by exploiting known vulnerabilities in unpatched Ruckus and ASUS routers to deploy custom backdoors like LONGLEASH and DOGLEASH, while other threats include the ARToken Phishing-as-a-Service platform targeting Microsoft 365, critical flaws in AirDrop/Quick Share, and a backdoor in Tenda router firmware.

Ruckus routers +5 UAT-7810 China-nexus APT router-exploitation ORB-network backdoor phishing-as-a-service credential-theft data-exfiltration +3
10t 8i
high threat

Armored Likho APT Leverages BusySnake Stealer with AI-Generated Loaders and Phishing

The Armored Likho APT group is conducting a spear-phishing campaign against government and energy sectors in Russia, Kazakhstan, and Brazil, using AI-generated loaders and the Python-based BusySnake Stealer to exfiltrate credentials and sensitive data.

Armored Likho apt infostealer phishing python windows government energy
2r 10t
high threat

UAT-7810 Expands ORB Networks with New Custom Malware: LONGLEASH, DOGLEASH, and JARLEASH

China-nexus APT actor UAT-7810 is actively expanding its LapDogs Operational Relay Box (ORB) network by exploiting N-day vulnerabilities in Ruckus and ASUS routers to deploy new custom malware families including LONGLEASH, DOGLEASH, and JARLEASH, enabling advanced command and control capabilities for secondary threat actors.

exploited PoC Ruckus Wireless Routers +1 UAT-7810 apt malware backdoor orb-network router-exploitation china-nexus linux embedded
1r 7t 4c 4i updated
critical advisory

Detection of Advanced Persistent Threat (APT) Malware Signatures in Antivirus Logs

This brief details a detection rule for critical antivirus alerts that report Advanced Persistent Threat (APT) malware signatures, enabling detection engineers to identify and investigate sophisticated threats that have reached endpoints.

detection antivirus apt malware endpoint
1r 1t
medium threat

Kimsuky APT Domains and URLs from Maltrail Feed

This brief summarizes newly published IOCs consisting of domains and URLs associated with the Kimsuky APT group as of June 2nd, 2026, sourced from a Maltrail feed.

Kimsuky +4 apt ioc malware
2r 2t 50i
high threat

ESET APT Activity Report Q4 2025–Q1 2026 Highlights Various Threat Actor Campaigns

ESET's APT Activity Report for Q4 2025 and Q1 2026 highlights diverse campaigns by China, Iran, North Korea, and Russia-aligned threat actors, including espionage, supply chain compromise, and destructive attacks.

Ivanti VPN appliances +2 Lazarus Group +4 apt espionage supply-chain wiper
2r 3t
high threat

Screening Serpens APT Targets Tech and Defense Sectors with New RATs

The Iranian APT group Screening Serpens targeted the tech and defense sectors in the U.S., Israel, and the UAE between February and April 2026, deploying six new RAT variants from the MiniUpdate and MiniJunk V2 malware families, using tailored social engineering lures and AppDomainManager hijacking.

MiniUpdate +2 Screening Serpens APT Iran RAT MiniJunk DLL Sideloading AppDomainManager Cyberespionage
2r 3t
high threat

Webworm APT Updates TTPs with Discord and Microsoft Graph C2

The Webworm APT group is using updated tactics, techniques, and procedures, including new backdoors using Discord and Microsoft Graph API for command and control, custom proxy tools, and GitHub for malware staging, shifting focus to European governmental organizations.

Microsoft Graph API +4 Webworm apt discord proxy tool
2r 10t 1c 1i
medium threat

Maltrail IOCs for APT Kimsuky, Lummac2, MagentoCore, and FakeApp Campaigns

This brief summarizes indicators of compromise (IOCs) from a Maltrail feed update on 2026-05-20, detailing network activity associated with APT Kimsuky, Lummac2, MagentoCore, and FakeApp campaigns, providing actionable intelligence for detection and response.

APT Kimsuky ioc apt network_activity kimsuky lummac2 magentocore fakeapp
3r 1t 50i
high threat

Kimsuky Targets Organizations with Evolving PebbleDash-Based Tools

Kimsuky, a North Korean APT group, is actively targeting organizations, primarily in South Korea, with evolving tactics and tools, leveraging spear-phishing emails and messenger contacts to deploy malware such as PebbleDash and AppleSeed for establishing backdoors and stealing information.

VSCode +2 Kimsuky +4 apt spear-phishing malware pebbledash appleseed
2r 4t 5i
high threat

WINDSHIFT APT Abuses Custom URL Schemes for macOS Infection

The WINDSHIFT APT group is infecting Macs by abusing custom URL schemes, where advertising support for a custom URL scheme in an application's Info.plist causes the application to be automatically launched when a URL with that scheme is opened, allowing attackers to remotely compromise systems with minimal user interaction and creating an initial access vector.

macOS WINDSHIFT APT url-scheme apt
2r 1t
high advisory

State-Sponsored Actors Leveraging Vulnerabilities and Identity for Persistent Access (2025)

In 2025, state-sponsored actors from China, Russia, North Korea, and Iran leveraged vulnerabilities and identity compromise for initial access, focusing on persistence for long-term espionage or disruption.

state-sponsored apt persistence vulnerability-exploitation
2r 6t
high threat

Operation GhostMail: Russian APT Exploiting Zimbra XSS to Target Ukraine Government

A Russian APT group is exploiting a Zimbra XSS vulnerability (details unspecified) to target the Ukrainian government in an operation dubbed 'GhostMail'.

Russian APT zimbra xss ukraine apt
2r 1t
medium advisory

Maltrail IOC Feed Update for Multiple Threats

This brief summarizes IOCs extracted from the Maltrail feed on March 15, 2026, covering domains and URLs associated with threats targeting macOS and Android platforms, including OSX_Atomic, FakeApp, Android_Joker, Lummack2, APT_Sidewinder, APT_Kimsuky, and Hak5Cloud_C2.

maltrail ioc osx android apt
3r 6t 40i
medium advisory

Maltrail IOCs Report: Tracking Multiple Threat Actors

This brief analyzes IOCs aggregated by Maltrail on February 27, 2026, highlighting network activity associated with diverse threat actors including APT_UNC2465, Lazarus Group, Gorat, APT_Bitter, Android_Joker, PowerShell Injector, SmokeLoader, and FakeApp campaigns targeting various sectors.

maltrail threat-intelligence apt malware
3r 5t 27i
high threat

WindShift APT Targeting Middle East with OSX.WindTail macOS Implant

The WindShift APT group is targeting Middle Eastern governments with a first-stage macOS implant called OSX.WindTail, abusing custom URL schemes for initial infection and establishing persistence via login items, while decrypting embedded strings to identify file extensions of interest.

OSX.WindTail +2 WindShift macos apt cyber-espionage
2r 1t
high advisory

Detecting Windows Screen Capture via PowerShell Script

This analytic detects the execution of a PowerShell script designed to capture screen images on a host, leveraging PowerShell Script Block Logging to identify specific script block text patterns associated with screen capture activities, potentially indicating an attempt to exfiltrate sensitive information via desktop screenshots.

Windows +2 screen-capture powershell exfiltration apt
2r 1t