Tag
Iranian State-Sponsored Surveillance Malware: Chosen Brick
1 rule 4 TTPsIranian state-sponsored actors are leveraging the 'Chosen Brick' Windows malware to conduct surveillance on global activists and journalists via social engineering and Telegram-based command-and-control.
Nimbus Manticore Targets Developers with Node.js-based Cross-Platform RATs
1 rule 3 TTPs 3 IOCsThe Iranian threat actor Nimbus Manticore is distributing NodeRabbit and PollCat cross-platform RATs via trojanized coding challenges on LinkedIn to compromise developer systems.
BlueDelta Targets European Defense and Diplomacy with HOOKEDGE Backdoor
1 rule 3 TTPs 1 IOCThe Russian threat group BlueDelta is using a custom batch-script backdoor named HOOKEDGE to target European government and diplomatic entities via macro-enabled Microsoft Word documents that leverage legitimate webhook services for C2.
TA4922 Deploys PackClient RAT Framework
1 rule 3 TTPs 3 IOCsThe Chinese-speaking threat actor TA4922 is actively using the modular PackClient C2 framework, delivered via tax-themed spearphishing, to conduct surveillance and deploy follow-on tools like ManageEngine RMM.
Chinese-Speaking Operator Targets Philippine Nuclear and Naval Infrastructure
2 rules 3 TTPs 2 CVEsA suspected Chinese-speaking operator is targeting Philippine governmental and defense entities by exploiting ownCloud and LiteSpeed Cache vulnerabilities to exfiltrate personnel data and deploy loaders.
Dark Caracal Evolving Infrastructure and Targeting
1 TTPArctic Wolf Labs identified 249 Dark Caracal malware samples utilizing an Ethereum-based C2 architecture to target the communications sector in Latin America.
Russian Threat Clusters UNC6293, UNC7005, and UNC5976 Targeted OAuth and Device Code Phishing Campaigns
3 TTPsThree suspected Russian threat clusters are actively conducting targeted phishing campaigns using OAuth abuse, device code manipulation, and AitM attacks via compromised Wi-Fi gateways to hijack credentials and deploy infostealers.
Russian-Linked Clusters Abuse Authentication Flows for Targeted Credential Theft
3 TTPs 1 IOCSuspected Russian threat clusters UNC6293 and UNC7005 are abusing legitimate OAuth, app password, and device code authentication workflows to bypass MFA and compromise high-value targets in academia, government, and defense.
Mustang Panda Deploys Signed Kernel-Mode Rootkit with CoolClient Backdoor
3 TTPs 4 IOCsThe threat actor HoneyMyte (Mustang Panda) is utilizing a signed kernel-mode rootkit named msagent.sys to provide stealth capabilities for its CoolClient backdoor, facilitating process, file, and network hiding on compromised Windows systems.
HoneyMyte CoolClient Backdoor Updated with Kernel-Mode Rootkit
1 rule 3 TTPsThe HoneyMyte APT group has enhanced its CoolClient backdoor with a custom kernel-mode driver that hides malicious artifacts and activity from security software on Windows systems.
Jewelbug APT Dual-Purpose Espionage and Fraud Operations
3 TTPsJewelbug, a China-linked mercenary APT, uses a custom C2 platform called XG-Web to conduct both state-sponsored espionage and large-scale cryptocurrency theft using custom backdoors and malicious browser extensions.
Project CAV3RN Modular Espionage Framework
1 rule 4 TTPs 3 IOCsProject CAV3RN is a modular espionage framework targeting entities in Israel that uses a .NET NativeAOT-compiled communication module to orchestrate DNS-controlled C2 transport switching between direct HTTPS and Google Apps Script relays.
Russian State-Backed 'LAUNDRY BEAR' Exploits Zimbra Zero-Click Vulnerability
3 TTPsThe Russian state-supported threat group LAUNDRY BEAR is exploiting a zero-click vulnerability, dubbed 'beehive,' in the Zimbra Collaboration Suite (ZCS) webmail service, actively stealing sensitive emails and gaining persistent access to compromised networks since July 2025 by merely viewing a malicious email, with Western organizations across various sectors being targeted.
TA488 Exploits Zimbra Mailservers with Half-Click Vulnerability CVE-2025-66376
2 rules 9 TTPs 3 CVEs 7 IOCsRussia-aligned threat actor TA488 (Void Blizzard, Laundry Bear) exploited CVE-2025-66376, a critical XSS vulnerability in Zimbra Collaboration Suite webmail, for at least five months in 2025 via crafted emails to gain persistent access, exfiltrate user credentials, 2FA codes, and bulk emails from Ukrainian government and US defense industrial base targets.
Midyear Assessment of Iran-Linked Cyber Threat Landscape
12 TTPsSentinelOne Labs' midyear assessment highlights that Iran-linked cyber operations, involving groups like MuddyWater/Seedworm, Screening Serpens, APT42, and persona groups such as Handala, focus on persistent access, espionage, and selective disruption, often leveraging social engineering, compromised service providers, and RMM abuse, with increasing risk to operational technology environments.
New GoSerpent Malware Targets Southeast Asian Governments and Diplomats for Espionage
2 rules 6 TTPsA sophisticated Go-based implant, dubbed GoSerpent, has been utilized by an unidentified threat actor since late 2025 to conduct cyber espionage against government and diplomatic entities in Southeast Asia, focusing on long-term access, sensitive data collection, and credential dumping for exfiltration.
Targeting and Compromise of French Entities Using the Turla Intrusion Set
The Turla intrusion set, operated by the 16th Centre of the Federal Security Service (FSB) of Russia, has been targeting French entities and other strategic organizations globally since at least 2004 for intelligence-gathering purposes, with victims in France including ministries and entities within the diplomatic, defence, justice, and technology sectors.
NCSC Warns of State-Sponsored Espionage via IP Cameras Targeting Critical Infrastructure
2 TTPsRussian state-sponsored actors, along with hacktivist groups and cybercriminals, are exploiting IP cameras to spy on critical infrastructure in NATO countries, including the Netherlands, prompting NCSC to advise organizations and home users to secure their devices through updates, network segmentation, and attack surface reduction.
FortiBleed Campaign: 73,932 FortiGate Systems Credentials Exposed
3 rules 9 TTPs 1 IOCA Russian-speaking threat group utilized a large dataset of administrative and VPN credentials, likely sourced from exposed FortiGate configuration files and active credential harvesting, to access government, critical infrastructure, and multinational corporate networks, resulting in widespread data exfiltration.
CrowdStrike 2026 Technology Threat Landscape Report: China's Ambitions Fuel Attacks
2 rules 6 TTPsThe CrowdStrike 2026 Technology Threat Landscape Report highlights the pervasive targeting of the technology sector by China-nexus and eCrime adversaries, employing tactics like password spraying, vulnerability exploitation, supply chain compromises (e.g., Axios npm package, GitHub repositories), and malware distribution (macOS info stealers via OpenClaw lures) to achieve intelligence collection, intellectual property theft, and financial extortion.
Global Stock Exchange Hit by Monthslong Email Campaign
3 rules 7 TTPsAn unknown threat actor gained continuous administrative access to a senior finance executive's Microsoft Outlook mailbox at a global stock exchange for at least five months, deploying custom infostealers via scheduled tasks and exfiltrating sensitive emails through a Dropbox-based command and control channel after an initial lateral movement event.
ESET APT Activity Report Q4 2025–Q1 2026 Highlights Various Threat Actor Campaigns
2 rules 3 TTPsESET's APT Activity Report for Q4 2025 and Q1 2026 highlights diverse campaigns by China, Iran, North Korea, and Russia-aligned threat actors, including espionage, supply chain compromise, and destructive attacks.
Secret Blizzard Upgrades Kazuar Backdoor to Modular P2P Botnet
2 rules 4 TTPsThe Russian hacker group Secret Blizzard has evolved the Kazuar backdoor into a modular P2P botnet designed for persistence, stealth, and data collection, utilizing kernel, bridge, and worker modules for command and control and data exfiltration.
UAT-4356 FIRESTARTER Backdoor Targeting Cisco Firepower Devices
2 rules 2 TTPs 2 CVEs 2 IOCsUAT-4356 is actively targeting Cisco Firepower devices running FXOS, exploiting CVE-2025-20333 and CVE-2025-20362 to deploy the FIRESTARTER backdoor which allows remote access and control by injecting malicious shellcode into the LINA process.