APT List - 2026 2025 2024 2021 2020 2019 2018 2017 2016
DATE | NAME |
Info | CATEG. |
WEB |
|
17.8.26 |
Suspected China-Nexus Actor Exploits VMware vCenter Flaw, Deploys Babuk-Derived Ransomware | Cybersecurity researchers have attributed the exploitation of a newly patched security flaw in Broadcom VMware vCenter to a suspected China- | APT | The Hacker News |
|
16.8.26 |
Lazarus hackers exploited Windows zero-day to target defense firms | North Korean hackers have been exploiting a Windows zero-day vulnerability (CVE-2026-68820) to target defense-sector companies as part of the Operation Dream Job campaign. | APT | BleepingComputer |
|
16.8.26 |
Sandworm hackers target IT pros with trojanized WireGuard VPN client | Hackers associated with the Russian threat group Sandworm have been targeting system administrators and IT professionals through fake job offers since at least May. | APT | BleepingComputer |
|
14.8.26 |
Mustang Panda Adds Signed Windows Rootkit to CoolClient Backdoor for Stealth | The threat actor known as HoneyMyte (aka Mustang Panda ) has been observed deploying an updated version of the CoolClient backdoor with a signed Windows kernel-mode rootkit that can hide and protect malicious | APT | The Hacker News |
|
14.8.26 |
APT group HoneyMyte upgrades CoolClient: the backdoor gets a kernel-level Windows rootkit | Our experts discovered a new CoolClient backdoor variant with a kernel-mode rootkit driver that hides malicious processes, files, and network connections from security tools and threat analysts. | APT | SECURELIST |
|
14.8.26 |
China-Linked Jewelbug Uses XG-Web for Government Espionage and Crypto Fraud | The China-linked threat actor known as Jewelbug has been observed carrying out cyber espionage operations targeting governments and militaries, while simultaneously engaging in cryptocurrency fraud. "Both | APT | The Hacker News |
|
13.8.26 |
North Korean Lazarus Group Uses Windows Zero-Day in Operation Dream Job | Lazarus targets defense professionals with fake Lockheed Martin jobs, exploiting a Windows zero-day to deploy backdoors and evade security controls. Check Point Research has uncovered a new wave | APT | SECURITYAFFAIRS |
|
13.8.26 |
China-Linked Hackers Use AI Agents in Autonomous Attack on Taiwan | China-linked hackers reportedly used eight AI agents to breach a government network, steal data and compromise accounts with minimal human oversight. Israeli cybersecurity firm Dream documented wh ... | APT | SECURITYAFFAIRS |
|
13.8.26 |
North Korean Remote Workers Are Infiltrating Government and Businesses: How to Expose Them Before Hiring | Companies are used to thinking about attackers as outsiders trying to break in. North Korean IT workers flip that model. They apply for jobs, pass | APT | The Hacker News |
|
13.8.26 |
Armored Likho expands its cyber-espionage toolkit | Kaspersky experts break down a new Armored Likho campaign that poses as a fundraising efforts and delivers a new Still Toolkit aimed at stealing Telegram data and eavesdropping on victims. | APT | SECURELIST |
|
12.8.26 |
Smile, You’re on Camera. Part 2: Hiring Lazarus APT’s IT Workers in a Fake DeFi Startup | Researchers created a fake DeFi startup and hired suspected Famous Chollima operatives, providing a rare inside view of a DPRK IT worker operation. | APT | ANYRUN BLOG |
|
12.8.26 |
Inside a Russian-Speaking Operator's Toolkit for Compromising Ukrainian IP Cameras | Disclosure note: Hunt.io notified CERT-UA on July 30, 2026, and held publication for the standard 7-day disclosure window. The affected e-commerce operator was notified via CERT-UA. | APT | HUNT.IO |
|
12.8.26 |
CaptiveCrunch: Midnight Blizzard Weaponizes Hotel Wi-Fi Captive Portals to Steal Microsoft 365 Credentials | On July 31, Microsoft Threat Intelligence reported an ongoing credential theft campaign tracked as CaptiveCrunch. Microsoft attributes this activity to Storm-2945, a sub-cluster of Midnight Blizzard (also known as APT29, Cozy Bear, NOBELIUM, and BlueBravo), a threat group linked to Russia. | APT | Zscaler |
|
11.8.26 |
Head Mare APT is exploiting vulnerabilities in an unpatched TrueConf server to deliver PhantomCore and PhantomGraph to video conference participants | Kaspersky experts have discovered malicious TrueConf software installers. The Head Mare APT group uses them to deliver the PhantomCore and PhantomGraph backdoors to target systems by exploiting vulnerabilities in an unpatched TrueConf server. | APT | SECURELIST |
|
11.8.26 |
Project CAV3RN continues: Google Apps Script as C2 relay and DNS-based C2 channel selection | Project CAV3RN is a modular espionage framework used against targets in Israel. This report expands on two earlier publications: the first was published in June 2026 as part of our Kaspersky Threat Intelligence Reporting service, and the second was published on Securelist the following month, further documenting the framework’s evolving architecture and C2 capabilities. | APT | SECURELIST |
|
11.8.26 |
China-Linked Hackers Deploy New StormEncryptor Ransomware, Likely via N-central Flaw | Microsoft has disclosed that Storm-1175 , a financially motivated threat actor linked to China, has deployed a previously undocumented | APT | The Hacker News |
|
10.8.26 |
DPRK-Related Campaigns with LNK and GitHub C2 | FortiGuard Labs recently detected a series of LNK files targeting users in South Korea. These attacks use a multi-stage scripting process and leverage GitHub as Command and Control (C2) infrastructure to evade detection. | APT | FORTINET BLOG |
|
10.8.26 |
Kimsuky Builds Offline AI Stack to Boost Phishing and Automate Malware Development | North Korea's state hackers are no longer content to type prompts into public chatbots. One of the country's main espionage groups has begun | APT | The Hacker News |
|
9.8.26 |
Hedge fund cyberattacks tied to BlackFile-linked UNC6671 extortion group | A recent wave of cyberattacks targeting hedge funds, private-equity firms, and other financial organizations has been linked to UNC6671, an extortion group reportedly associated with the BlackFile threat actors. | APT | BleepingComputer |
|
8.8.26 |
Hotel Wi-Fi attacks use custom malware to breach Microsoft 365 accounts | Microsoft has linked a global campaign targeting hospitality Wi-Fi networks to the Russian threat actor Midnight Blizzard, also known as APT29. | APT | BleepingComputer |
|
3.8.26 |
Chinese Threat Actor Uses Leaked DarkSword Kit to Deploy GHOSTBLADE on iOS | An unknown Chinese-threat actor has been observed running a campaign targeting Apple iOS devices by leveraging a publicly leaked version of the DarkSword exploit kit. | APT | The Hacker News |
|
2.8.26 |
Amazon links Debug, Chalk NPM supply-chain attacks to North Korean hackers | Amazon linked multiple high-profile open-source software supply chain attacks targeting the Node Package Manager (npm) ecosystem to North Korean hackers. | APT | BleepingComputer |
|
2.8.26 |
Russian hackers exploit Exchange OWA zero-day for long-term mailbox access | The Russian state-sponsored hacking group Laundry Bear, also known as Void Blizzard, is exploiting an Exchange Outlook Web Access vulnerability in email campaigns to deliver a sophisticated backdoor called OWAReaper. | APT | BleepingComputer |
|
1.8.26 |
Suspected Chinese-Speaking Hackers Target Central Asian Governments With OctLurk and SilkLurk |
A Chinese-speaking threat actor is suspected to be behind a fresh wave of cyber attacks targeting government organizations mainly located in |
||
|
31.7.26 |
DPRK-Linked macOS Malvertising Uses Fake Updates to Deliver Crypto-Stealing Malware |
Threat actors with ties to North Korea have been attributed to a sophisticated macOS malvertising campaign that involves redirecting |
||
|
30.7.26 |
Our experts discovered OctLurk and SilkLurk, backdoors operating primarily in memory, targeting Central Asia. They inject plugins to launch shells, scan networks, dump credentials, and keylogging. |
|||
|
30.7.26 |
Hackers Exploit AnySign4PC via Hacked Korean Sites to Install Backdoors Without Prompts |
South Korean authorities and four security firms have disclosed a state-sponsored campaign that compromised trusted domestic websites. The attackers used those sites to exploit locally installed financial-security |
||
|
30.7.26 |
SilverFox Targets Japanese Manufacturer with 3-Driver BYOVD Chain and ValleyRAT |
The Chinese cybercrime group known as Silver Fox has been observed using new drivers as part of bring your own vulnerable driver (BYOVD) |
||
|
30.7.26 |
Russian Hackers Exploit Microsoft OWA Flaw to Keep Mailbox Access After Credential Rotation |
The Russian threat actors recently linked to the exploitation of a now-patched vulnerability in Zimbra have been observed exploiting another vulnerability, this time in Microsoft Outlook Web Access (OWA), to target U.S. and European government entities, as well as the telecommunications, financial, hospitality, and aerospace sectors. |
||
|
30.7.26 |
Russian Hackers Exploit Microsoft OWA Flaw to Keep Mailbox Access After Credential Rotation |
The Russian threat actors recently linked to the exploitation of a now-patched vulnerability in Zimbra have been observed exploiting another vulnerability, this time in Microsoft Outlook Web Access (OWA), to target U.S. and European government entities, as well as the telecommunications, financial, hospitality, and aerospace sectors. |
||
|
30.7.26 |
Amazon Links Debug and Chalk npm Hijack to North Korea’s Sapphire Sleet |
Amazon has tied the September 2025 hijack of the npm packages debug and chalk to North Korea. For ten months, the incident sat in the public record as crypto theft: a maintainer phished through a lookalike npm domain and a wallet-draining script pushed into at least 18 packages carrying more than 2 billion weekly downloads between them. |
||
|
29.7.26 |
Nine-Year Fraud Campaign Clones Russian Company Sites to Steal Advance Payments |
Cybersecurity researchers have disclosed details of a large-scale fraud campaign that involves creating lookalike websites of major Russian |
||
|
28.7.26 |
Mirage Kitten targets Middle East and Africa region with new malware |
Kaspersky researchers reveal previously undocumented malware attributed to Mirage Kitten (UNC1549, Smoke Sandstorm, Nimbus Manticore): NightLedger backdoor, ArcBridge, and BridgeHead tunneling tools. |
||
|
28.7.26 |
Nimbus Manticore Deploys NightLedger and Turns Victim Systems Into Covert Relays |
The Iranian state-backed hacking group tracked as Nimbus Manticore (aka GalaxyGato, Mirage Kitten, Smoke Sandstorm, Subtle Snail, and UNC1549) |
||
|
27.7.26 |
Cruciferra Crypter Uses BYOVD and Process Ghosting to Hide Windows Malware |
The China-linked cybercrime group behind the use of income tax-related phishing lures targeting Indian taxpayers, tax professionals, and corporate |
||
|
26.7.26 |
Russian hackers exploit Zimbra zero-click flaw for email theft |
CISA is warning that the Russian state-sponsored hacking group Laundry Bear, also known as Void Blizzard, is targeting organizations using Zimbra Collaboration email servers by combining phishing attacks with the exploitation of a now-patched Zimbra vulnerability. |
||
|
24.7.26 |
Golden Chickens Resurfaces With Four New Malware Families and Modular Implants |
The threat actors behind the Golden Chickens malware-as-a-service (MaaS) ecosystem have resurfaced with four new malware families, indicating that the operators are showing no signs of stopping despite extensive public disclosures into their inner workings. |
||
|
24.7.26 |
Fake Notepad++ Plugin Delivers MATCHBOIL.V2 in UAC-0099 Attacks |
The Computer Emergency Response Team of Ukraine (CERT-UA) has warned of a new campaign that involves the use of a malicious program |
||
|
24.7.26 |
Russian Espionage Group Exploited Zimbra Zero-Day to Steal Mail and 2FA Codes |
A Russian state-supported espionage group spent months reading Western mailboxes through a then-unknown flaw in Zimbra's webmail |
||
|
23.7.26 |
Operation RoundPress Rolls on with More Half-Click Webmail Zero-Days from TA458 |
The Russia-aligned threat actor TA458, the group behind Operation RoundPress, continues to focus on webmail targeting using half-click exploits as a way to steal highly sensitive email data. |
||
|
23.7.26 |
Proofpoint uncovered that Russia-aligned threat actor TA488 (Void Blizzard, Laundry Bear) was exploiting a previously unknown vulnerability against Zimbra mailservers for at least five months during 2025, until the issue was patched with CVE-2025-66376. |
|||
|
23.7.26 |
China-Nexus JadeProx Uses New TriBack Loader in Government and Healthcare Attacks |
An exposed Alibaba Cloud server has revealed a China-nexus operation that Group-IB tracks as JadeProx . The cluster has targeted government, |
||
|
20.7.26 |
Russian-Speaking Hacker Uses Google Gemini CLI to Control Botnet of Eight Dental Clinic PCs |
A solo Russian-speaking threat actor known as " bandcampro " outsourced a chunk of their operations to Google's open-source Gemini |
||
|
20.7.26 |
UAC-0145 Uses ClickFix CAPTCHAs to Infect Ukrainian Devices wih Malware |
Russian state-sponsored threat actors have been observed leveraging the infamous ClickFix strategy to trick Ukrainian targets into infecting their |
||
|
14.7.26 |
Microsoft Maps Three Salesforce Attack Paths Tied to a Year of ShinyHunters Activity |
Attackers whose methods line up with the data-extortion group ShinyHunters have spent the past year walking into corporate Salesforce environments without exploiting a single flaw in the platform. The way in |
||
|
12.7.26 |
Hackers Weaponize Balochistan Police Portal in Multi-Group Espionage Campaigns |
Cybersecurity researchers have disclosed details of sustained cyber espionage activity against several Pakistani law enforcement |
||
|
8.7.26 |
China-Linked UAT-7810 Expands ORB Network With New LONGLEASH Malware |
A Chinese threat actor tracked as UAT-7810 is actively refining its bespoke malware to expand its Operational Relay Box (ORB) network by |
||
|
7.7.26 |
Iran-Linked Hackers Use New Cavern C2 Framework to Target Israeli Organizations |
An Iranian hacking group affiliated with Iran's Ministry of Intelligence and Security (MOIS) has been wielding a previously undocumented modular |
||
|
5.7.26 |
North Korean Hackers Publish 108 Malicious Packages and Extensions in PolinRider Campaign |
The North Korean threat actors linked to the Contagious Interview campaign have been observed publishing 108 unique packages and web |
||
|
4.7.26 |
North Korea-Linked npm Packages Mimic Rollup Polyfills to Steal Developer Secrets |
Threat actors with ties to North Korea have been linked to a fresh set of malicious npm packages that masquerade as Rollup polyfill tooling to |
||
|
2.7.26 |
ToddyCat-Linked Umbrij Malware Abuses OAuth to Access Gmail via Google API |
The threat actor known as ToddyCat has been attributed to a new malware called Umbrij that's designed to gain surreptitious access to a victim's email correspondence via the Google API. "In this campaign, the |
||
|
29.6.26 |
Mustang Panda Uses Zoho WorkDrive as Command Channel in Indian Government Attacks |
The China-aligned espionage group Mustang Panda is running two campaigns against the Indian government and hydropower targets, |
||
|
26.6.26 |
Chinese-Speaking APT Deploys New TinyRCT Backdoor in Southeast Asia Campaign |
A Chinese-speaking advanced persistent threat (APT) actor has been linked to a new custom backdoor called TinyRCT as part of cyber attacks aimed at government entities and critical infrastructure in Southeast Asia. |
||
|
24.6.26 |
FortiBleed Targeted FortiGate Firewalls in 110 Million-Credential Harvesting Operation |
A Russian-speaking initial access broker (IAB) driven by financial gain is assessed to be behind a large-scale credential-harvesting operation |
||
|
20.6.26 |
Chinese hackers breach REDCap servers, steal medical research |
A China-linked espionage campaign targeted exposed REDCap servers to deploy the InfiniteRed malware and steal sensitive data from a medical institution in North America. |
||
|
16.6.26 |
Google Threat Intelligence Group (GTIG) has identified a sophisticated campaign attributed to UNC6508, a People's Republic of China (PRC)-nexus threat actor, targeting institutions in the North American academic, medical, and military research community. |
|||
|
16.6.26 |
Chinese Hackers Abused Google Workspace Rules to Steal Research and Defense Emails |
A China-linked espionage group hid inside North American medical, academic, and military research networks for more than a year, quietly |
||
|
16.6.26 |
North Korean Hackers Are Turning Developer Tools Into Malware Delivery Channels |
Cybersecurity researchers have flagged two malicious cyber campaigns that exhibit similarities with a persistent North Korean threat cluster |
||
|
14.6.26 |
Chinese hackers hijack auth flow, spy on isolated network for a decade |
Chinese hackers took control of a target organization's authentication stack and maintained persistence for 10 years, with full visibility into the administrative activity. |
||
|
14.6.26 |
Oracle PeopleSoft servers hacked in ShinyHunters data theft attacks |
Oracle PeopleSoft servers are being targeted in ongoing data theft attacks by the ShinyHunters extortion gang, which claims to have stolen data from over 100 organizations. |
||
|
14.6.26 |
China-linked JDY botnet expands targeting of U.S. military networks |
The JDY botnet, a malware network previously associated with Chinese threat actors like Volt Typhoon, has significantly expanded its targeting scope and reconnaissance efforts. |
||
|
13.6.26 |
China-Linked Hackers Backdoored Linux Login Software to Hide for Nearly a Decade |
Instead of hiding on the laptops and servers defenders watch most closely, a China-nexus group spent close to a decade hidden inside the |
||
|
11.6.26 |
OceanLotus Hits Vietnam Investors With SPECTRALVIPER in FireAnt Attack |
The Vietnam-aligned threat actor known as OceanLotus has been attributed to two distinct campaigns that targeted domestic entities and |
||
|
8.6.26 |
VerdantBamboo Deploys BSD Variant of BRICKSTORM on Linux Appliances |
A China-nexus cyber espionage group has been observed deploying a BSD variant of a known backdoor called BRICKSTORM, as well as two |
||
|
8.6.26 |
UNC3753 Used Vishing and Physical Intrusions in U.S. Data Theft Extortion Campaign |
Cybersecurity researchers have disclosed details of a financially motivated data theft extortion campaign that has targeted dozens of |
||
|
7.6.26 |
Chinese APT deploys new malware to keep access to hacked networks |
A Chinese espionage group tracked as UNC5221 has been accessing Microsoft 365 environments using the Brickstorm backdoor and previously undocumented malware named Plenet and AgentPSD |
||
|
5.6.26 |
New Threat Cluster OP-512 Targets Microsoft IIS Servers with Custom Web Shell Framework |
Cybersecurity researchers have discovered a previously unreported threat cluster dubbed OP-512 (where "OP" stands for "opponent") that has been |
||
|
4.6.26 |
Espionage Campaign Targeted Stock Exchange Executive for Five Months |
Unknown attackers stole a senior executive's Outlook mailbox in incremental batches, exfiltrating through Dropbox and OneDrive Personal to keep the traffic indistinguishable from legitimate activity. |
||
|
4.6.26 |
China-Linked TA4922 Expands Phishing Attacks to UK, Germany, Italy, and South Africa |
A new China-linked cybercrime group known as TA4922 has expanded its targeting focus to target European organizations in the U.K., Germany, Italy, and South Africa. |
||
|
2.6.26 |
Pakistan-Linked SideCopy Targets Afghanistan Finance Ministry with Xeno RAT |
Cybersecurity researchers have disclosed details of a spear-phishing campaign likely undertaken by the Pakistan-aligned SideCopy group targeting Afghanistan's Ministry of Finance with an open-source remote |
||
|
2.6.26 |
Pakistan-Linked SideCopy Targets Afghanistan Finance Ministry with Xeno RAT |
Cybersecurity researchers have disclosed details of a spear-phishing campaign likely undertaken by the Pakistan-aligned SideCopy group targeting Afghanistan's Ministry of Finance with an open-source remote |
||
|
1.6.26 |
China-Aligned Groups Ramp Up Attacks: Dragon Weave Hits Czech Republic & Taiwan |
A new cyber espionage campaign codenamed Operation Dragon Weave has been observed targeting officials and citizens in the Czech Republic |
||
|
26.5.26 |
MuddyWater Uses DLL Side-Loading in Espionage Campaign Targeting 9 Countries |
The Iranian hacking group known as MuddyWater has been linked to a new campaign affecting at least nine organizations across nine countries |
||
|
26.5.26 |
Cloud Atlas activity in the second half of 2025 and early 2026: new tools and a new payload |
Cloud Atlas attacks the public sector and diplomatic structures of Russia and Belarus, using ReverseSocks, SSH, and Tor for persistence in infected systems and its new tool, PowerCloud. |
||
|
25.5.26 |
Lazarus Deploys RemotePE Memory-Only RAT Against Financial and Crypto Firms |
Cybersecurity researchers have shed light on a cross-platform malware called RemotePE that has been put to use by the North Korea-linked |
||
|
24.5.26 |
Chinese hackers target telcos with new Linux, Windows malware |
A Chinese cyber-espionage campaign has been targeting telecommunications providers with newly discovered Linux and Windows malware dubbed Showboat and JFMBackdoor, respectively. |
||
|
17.5.26 |
Iranian hackers targeted major South Korean electronics maker |
The Iran-linked hacking group MuddyWater (a.k.a. Seedworm, Static Kitten) launched a broad cyber-espionage campaign targeting at least nine high-profile organizations across multiple sectors and countries. |
||
|
16.5.26 |
Turla Turns Kazuar Backdoor Into Modular P2P Botnet for Persistent Access |
The Russian state-sponsored hacking group known as Turla has transformed its custom backdoor Kazuar into a modular peer-to-peer |
||
|
14.5.26 |
Ghostwriter Targets Ukrainian Government With Geofenced PDF Phishing, Cobalt Strike |
The Belarus-aligned threat group known as Ghostwriter has been attributed to a fresh set of attacks targeting governmental organizations in Ukraine. Active since at least 2016, Ghostwriter has been linked to both cyber espionage and influence operations targeting neighboring countries, particularly Ukraine. |
||
|
14.5.26 |
Instructure reaches 'agreement' with ShinyHunters to stop data leak |
Instructure, the edtech giant behind the widely popular Canvas learning management system (LMS), has reached an "agreement" with the ShinyHunters extortion group to prevent the data stolen in a recent breach from being leaked online. |
||
|
10.5.26 |
Americans sentenced for running 'laptop farms' for North Korea |
Two U.S. nationals were sentenced to 18 months in prison each for operating so-called laptop farms that helped North Korean IT workers fraudulently obtain remote employment at nearly 70 American companies. |
||
|
10.5.26 |
MuddyWater hackers use Chaos ransomware as a decoy in attacks |
The MuddyWater Iranian hackers disguised their operations as a Chaos ransomware attack, relying on Microsoft Teams social engineering to gain access and establish persistence. |
||
|
9.5.26 |
ScarCruft hackers push BirdCall Android malware via game platform |
The North Korean hacker group APT37 has been delivering an Android version of a backdoor called BirdCall in a supply-chain attack through a video game platform. |
||
|
6.5.26 |
China-Linked UAT-8302 Targets Governments Using Shared APT Malware Across Regions |
A sophisticated China-nexus advanced persistent threat (APT) group has been attributed to attacks targeting government entities in South America |
||
|
4.5.26 |
Silver Fox Deploys ABCDoor Malware via Tax-Themed Phishing in India and Russia |
The China-based cybercrime group known as Silver Fox has been linked to a new campaign targeting organizations in Russia and India with a new |
||
|
30.4.26 |
New Wave of DPRK Attacks Uses AI-Inserted npm Malware, Fake Firms, and RATs |
Cybersecurity researchers have discovered malicious code in an npm package after a malicious package as a dependency to the project by Anthropic's Claude Opus large language model (LLM). The package in question is " |
||
|
28.4.26 |
Chinese Silk Typhoon Hacker Extradited to U.S. Over COVID Research Cyberattacks |
A Chinese national accused of being a member of the Silk Typhoon hacking group has been extradited to the U.S. from Italy. Xu Zewei, 34, was arrested in |
||
|
26.4.26 |
New GopherWhisper APT group abuses Outlook, Slack, Discord for comms |
A previously undocumented state-backed threat actor named GopherWhisper is using a Go-based custom toolkit and legitimate services like Microsoft 365 Outlook, Slack, and Discord in attacks against government entities. |
||
|
25.4.26 |
State-sponsored North Korean hackers are likely behind the $290 million crypto-heist that impacted the KelpDAO DeFi project on Saturday. |
|||
|
23.4.26 |
China-Linked GopherWhisper Infects 12 Mongolian Government Systems with Go Backdoors |
Mongolian governmental institutions have emerged as the target of a previously undocumented China-aligned advanced persistent threat (APT) |
||
|
22.4.26 |
Mustang Panda’s New LOTUSLITE Variant Targets India Banks, South Korea Policy Circles |
Cybersecurity researchers have discovered a new variant of a known malware called LOTUSLITE that's distributed via a theme related to India's banking |
||
|
19.4.26 |
US nationals behind DPRK IT worker 'laptop farm' sent to prison |
Two U.S. nationals have been sent to prison for helping North Korean remote information technology (IT) workers to pose as U.S. residents and get hired by over 100 companies across the country, including many Fortune 500 firms. |
||
|
14.4.26 |
North Korea's APT37 Uses Facebook Social Engineering to Deliver RokRAT Malware |
The North Korean hacking group tracked as APT37 (aka ScarCruft) has been attributed to a fresh multi-stage, social engineering campaign in which threat |
||
|
12.4.26 |
Nearly 4,000 US industrial devices exposed to Iranian cyberattacks |
The attack surface targeted by Iranian-linked hackers in cyberattacks against U.S. critical infrastructure networks includes thousands of Internet-exposed programmable logic controllers (PLCs) manufactured by Rockwell Automation. |
||
|
10.4.26 |
UAT-10362 Targets Taiwanese NGOs with LucidRook Malware in Spear-Phishing Campaigns |
A previously undocumented threat cluster dubbed UAT-10362 has been attributed to spear-phishing campaigns targeting Taiwanese non-governmental |
||
|
10.4.26 |
Bitter-Linked Hack-for-Hire Campaign Targets Journalists Across MENA Region |
An apparent hack-for-hire campaign likely orchestrated by a threat actor with suspected ties to the Indian government targeted journalists, activists, and |
||
|
9.4.26 |
APT28 Deploys PRISMEX Malware in Campaign Targeting Ukraine and NATO Allies |
The Russian threat actor known as APT28 (aka Forest Blizzard and Pawn Storm) has been linked to a fresh spear-phishing campaign targeting Ukraine |
||
|
9.4.26 |
N. Korean Hackers Spread 1,700 Malicious Packages Across npm, PyPI, Go, Rust |
The North Korea-linked persistent campaign known as Contagious Interview has spread its tentacles by publishing malicious packages targeting the Go, |
||
|
8.4.26 |
Iran-Linked Hackers Disrupt U.S. Critical Infrastructure by Targeting Internet-Exposed PLCs |
Iran-affiliated cyber actors are targeting internet-facing operational technology (OT) devices across critical infrastructures in the U.S., including programmable |
||
|
8.4.26 |
Russian State-Linked APT28 Exploits SOHO Routers in Global DNS Hijacking Campaign |
The Russia-linked threat actor known as APT28 (aka Forest Blizzard) has been linked to a new campaign that has compromised insecure MikroTik and TP- |
||
|
8.4.26 |
China-Linked Storm-1175 Exploits Zero-Days to Rapidly Deploy Medusa Ransomware |
A China-based threat actor known for deploying Medusa ransomware has been linked to the weaponization of a combination of zero-day and N-day |
||
|
8.4.26 |
Iran-Linked Password-Spraying Campaign Targets 300+ Israeli Microsoft 365 Organizations |
An Iran-nexus threat actor is suspected to be behind a password-spraying campaign targeting Microsoft 365 environments in Israel and the U.A.E. |
||
|
8.4.26 |
DPRK-Linked Hackers Use GitHub as C2 in Multi-Stage Attacks Targeting South Korea |
Threat actors likely associated with the Democratic People's Republic of Korea (DPRK) have been observed using GitHub as command-and-control (C2) |
||
|
8.4.26 |
$285 Million Drift Hack Traced to Six-Month DPRK Social Engineering Operation |
Drift has revealed that the April 1, 2026, attack that led to the theft of $285 million was the culmination of a months-long targeted and meticulously |
||
|
6.4.26 |
Drift loses $280 million as North Korean hackers seize Security Council powers |
The Drift Protocol lost at least $280 million after a threat actor took control of its Security Council administrative powers in a planned, sophisticated operation. |
||
|
5.4.26 |
FBI warns against using Chinese mobile apps due to privacy risks |
The U.S. Federal Bureau of Investigation (FBI) warned Americans against using foreign-developed mobile applications, particularly those created by Chinese developers. |
||
|
4.4.26 |
China-Linked TA416 Targets European Governments with PlugX and OAuth-Based Phishing |
A China-aligned threat actor has set its sights on European government and diplomatic organizations since mid-2025, following a two-year period of |
||
|
3.4.26 |
UNC1069 Social Engineering of Axios Maintainer Led to npm Supply Chain Attack |
The maintainer of the Axios npm package has confirmed that the supply chain compromise was the result of a highly-targeted social engineering campaign |
||
|
3.4.26 |
Drift Loses $285 Million in Durable Nonce Social Engineering Attack Linked to DPRK |
Solana-based decentralized exchange Drift has confirmed that attackers drained about $285 million from the platform during a security incident that |
||
|
1.4.26 |
Google Attributes Axios npm Supply Chain Attack to North Korean Group UNC1069 |
Google has formally attributed the supply chain compromise of the popular Axios npm package to a financially motivated North Korean threat activity |
||
|
30.3.26 |
Russian CTRL Toolkit Delivered via Malicious LNK Files Hijacks RDP via FRP Tunnels |
Cybersecurity researchers have discovered a remote access toolkit of Russian-origin that's distributed via malicious Windows shortcut (LNK) files that are |
||
|
30.3.26 |
Three China-Linked Clusters Target Southeast Asian Government in 2025 Cyber Campaign |
Three threat activity clusters aligned with China have targeted a government organization in Southeast Asia as part of what has been described as a |
||
|
30.3.26 |
Iran-Linked Hackers Breach FBI Director’s Personal Email, Hit Stryker With Wiper Attack |
Threat actors with ties to Iran successfully broke into the personal email account of Kash Patel, the director of the U.S. Federal Bureau of Investigation |
||
|
28.3.26 |
TA446 Deploys DarkSword iOS Exploit Kit in Targeted Spear-Phishing Campaign |
Proofpoint has disclosed details of a targeted email campaign in which threat actors with ties to Russia are leveraging the recently disclosed DarkSword |
||
|
27.3.26 |
China-Linked Red Menshen Uses Stealthy BPFDoor Implants to Spy via Telecom Networks |
A long-term and ongoing campaign attributed to a China-nexus threat actor has embedded itself in telecom networks to conduct espionage against |
||
|
25.3.26 |
Russian Hacker Sentenced to 2 Years for TA551 Botnet-Driven Ransomware Attacks |
The U.S. Department of Justice (DoJ) said a Russian national has been sentenced to two years in prison for managing a botnet that was used to |
||
|
22.3.26 |
Crypto-powered gift card store Bitrefill says that the attack it suffered at the beginning of the month was likely perpetrated by North Korean hackers of the Bluenoroff group. |
|||
|
22.3.26 |
Russian hackers exploit Zimbra flaw in Ukrainian govt attacks |
Hackers part of APT28, a state-backed threat group linked to Russia's military intelligence service (GRU), are exploiting a Zimbra Collaboration Suite (ZCS) vulnerability in attacks targeting Ukrainian government entities. |
||
|
21.3.26 |
The European Union Council has announced sanctions against three entities and two individuals for their involvement in cyberattacks targeting critical infrastructure in the region. |
|||
|
18.3.26 |
OFAC Sanctions DPRK IT Worker Network Funding WMD Programs Through Fake Remote Jobs |
The U.S. Department of the Treasury's Office of Foreign Assets Control (OFAC) has sanctioned six individuals and two entities for their involvement in the |
||
|
14.3.26 |
New ‘BlackSanta’ EDR killer spotted targeting HR departments |
For more than a year, a Russian-speaking threat actor targeted human resource (HR) departments with malware that delivers a new EDR killer named BlackSanta. |
||
|
14.3.26 |
APT28 hackers deploy customized variant of Covenant open-source tool |
The Russian state-sponsored APT28 threat group is using a custom variant of the open-source Covenant post-exploitation framework for long-term espionage operations. |
||
|
14.3.26 |
Chinese Hackers Target Southeast Asian Militaries with AppleChris and MemFun Malware |
A suspected China-based cyber espionage operation has targeted Southeast Asian military organizations as part of a state-sponsored campaign that dates |
||
|
14.3.26 |
Storm-2561 Spreads Trojan VPN Clients via SEO Poisoning to Steal Credentials |
Microsoft has disclosed details of a credential theft campaign that employs fake virtual private network (VPN) clients distributed through search engine |
||
|
12.3.26 |
ShinyHunters claims ongoing Salesforce Aura data theft attacks |
Salesforce is warning customers that hackers are targeting websites with misconfigured Experience Cloud platforms that give guest users access to more data than intended. However, the ShinyHunters extortion gang claims to be actively exploiting a new bug to steal data from instances. |
||
|
11.3.26 |
UNC6426 Exploits nx npm Supply-Chain Attack to Gain AWS Admin Access in 72 Hours |
A threat actor known as UNC6426 leveraged keys stolen following the supply chain compromise of the nx npm package last year to completely breach a |
||
|
10.3.26 |
APT28 Uses BEARDSHELL and COVENANT Malware to Spy on Ukrainian Military |
The Russian state-sponsored hacking group tracked as APT28 has been observed using a pair of implants dubbed BEARDSHELL and COVENANT to |
||
|
7.3.26 |
Iran-Linked MuddyWater Hackers Target U.S. Networks With New Dindoor Backdoor |
New research from Broadcom's Symantec and Carbon Black Threat Hunter Team has discovered evidence of an Iranian hacking group embedding itself in |
||
|
6.3.26 |
China-Linked Hackers Use TernDoor, PeerTime, BruteEntry in South American Telecom Attacks |
A China-linked advanced persistent threat (APT) actor has been targeting critical telecommunications infrastructure in South America since 2024, |
||
|
6.3.26 |
APT28-Linked Campaign Deploys BadPaw Loader and MeowMeow Backdoor in Ukraine |
Cybersecurity researchers have disclosed details of a new Russian cyber campaign that has targeted Ukrainian entities with two previously |
||
|
4.3.26 |
APT41-Linked Silver Dragon Targets Governments Using Cobalt Strike and Google Drive C2 |
Cybersecurity researchers have disclosed details of an advanced persistent threat (APT) group dubbed Silver Dragon that has been linked to cyber attacks |
||
|
3.3.26 |
SloppyLemming Targets Pakistan and Bangladesh Governments Using Dual Malware Chains |
The threat activity cluster known as SloppyLemming has been attributed to a fresh set of attacks targeting government entities and critical infrastructure |
||
|
2.3.26 |
APT28 Tied to CVE-2026-21513 MSHTML 0-Day Exploited Before Feb 2026 Patch Tuesday |
A recently disclosed security flaw patched by Microsoft may have been exploited by the Russia-linked state-sponsored threat actor known as APT28 , |
||
|
2.3.26 |
North Korean Hackers Publish 26 npm Packages Hiding Pastebin C2 for Cross-Platform RAT |
Cybersecurity researchers have disclosed a new iteration of the ongoing Contagious Interview campaign, where the North Korean threat actors have |
||
|
1.3.26 |
North Korean hackers are deploying newly uncovered tools to move data between internet-connected and air-gapped systems, spread via removable drives, and conduct covert surveillance. |
|||
|
28.2.26 |
North Korean Lazarus group linked to Medusa ransomware attacks |
North Korean state-backed hackers associated with the Lazarus threat group are targeting U.S. healthcare organizations in extortion attacks using the Medusa ransomware. |
||
|
26.2.26 |
UAT-10027 Targets U.S. Education and Healthcare with Dohdoor Backdoor |
A previously undocumented threat activity cluster has been attributed to an ongoing malicious campaign targeting education and healthcare sectors in the |
||
|
24.2.26 |
UAC-0050 Targets European Financial Institution With Spoofed Domain and RMS Malware |
A Russia-aligned threat actor has been observed targeting a European financial institution as part of a social engineering attack to likely facilitate |
||
|
24.2.26 |
UnsolicitedBooker Targets Central Asian Telecoms With LuciDoor and MarsSnake Backdoors |
The threat activity cluster known as UnsolicitedBooker has been observed targeting telecommunications companies in Kyrgyzstan and Tajikistan, marking a shift from prior attacks aimed at Saudi Arabian entities. The attacks |
||
|
24.2.26 |
APT28 Targeted European Entities Using Webhook-Based Macro Malware |
The Russia-linked state-sponsored threat actor tracked as APT28 has been attributed to a new campaign targeting specific entities in Western and Central |
||
|
23.2.26 |
MuddyWater Targets MENA Organizations with GhostFetch, CHAR, and HTTP_VIP |
The Iranian hacking group known as MuddyWater (aka Earth Vetala, Mango Sandstorm, and MUDDYCOAST) has targeted several organizations and |
||
|
22.2.26 |
Texas sues TP-Link over Chinese hacking risks, user deception |
Texas sued networking giant TP-Link Systems, accusing the company of deceptively marketing its routers as secure while allowing Chinese state-backed hackers to exploit firmware vulnerabilities and access users' devices. |
||
|
21.2.26 |
Chinese hackers exploiting Dell zero-day flaw since mid-2024 |
A suspected Chinese state-backed hacking group has been quietly exploiting a critical Dell security flaw in zero-day attacks that started in mid-2024. |
||
|
18.2.26 |
From BRICKSTORM to GRIMBOLT: UNC6201 Exploiting a Dell RecoverPoint for Virtual Machines Zero-Day |
Mandiant and Google Threat Intelligence Group (GTIG) have identified the zero-day exploitation of a high-risk vulnerability in Dell RecoverPoint for Virtual Machines, tracked as CVE-2026-22769, with a CVSSv3.1 score of 10.0. |
||
|
15.2.26 |
Fake job recruiters hide malware in developer coding challenges |
A new variation of the fake recruiter campaign from North Korean threat actors is targeting JavaScript and Python developers with cryptocurrency-related tasks. |
||
|
13.2.26 |
Google Links China, Iran, Russia, North Korea to Coordinated Defense Sector Cyber Operations |
Several state-sponsored actors, hacktivist entities, and criminal groups from China, Iran, North Korea, and Russia have trained their sights on the defense |
||
|
13.2.26 |
Lazarus Campaign Plants Malicious Packages in npm and PyPI Ecosystems |
Cybersecurity researchers have discovered a fresh set of malicious packages across npm and the Python Package Index (PyPI) repository linked to a fake |
||
|
11.2.26 |
APT36 and SideCopy Launch Cross-Platform RAT Campaigns Against Indian Entities |
Indian defense sector and government-aligned organizations have been targeted by multiple campaigns that are designed to compromise Windows |
||
|
11.2.26 |
DPRK Operatives Impersonate Professionals on LinkedIn to Infiltrate Companies |
The information technology (IT) workers associated with the Democratic People's Republic of Korea (DPRK) are now applying to remote positions using |
||
|
10.2.26 |
China-Linked UNC3886 Targets Singapore Telecom Sector in Cyber Espionage Campaign |
The Cyber Security Agency (CSA) of Singapore on Monday revealed that the China-nexus cyber espionage group known as UNC3886 targeted its |
||
|
9.2.26 |
Bloody Wolf Targets Uzbekistan, Russia Using NetSupport RAT in Spear-Phishing Campaign |
The threat actor known as Bloody Wolf has been linked to a campaign targeting Uzbekistan and Russia to infect systems with a remote access trojan |
||
|
8.2.26 |
New Amaranth Dragon cyberespionage group exploits WinRAR flaw |
A new threat actor called Amaranth Dragon, linked to APT41 state-sponsored Chinese operations, exploited the CVE-2025-8088 vulnerability in WinRAR in espionage attacks on government and law enforcement agencies. |
||
|
7.2.26 |
Notepad++ update feature hijacked by Chinese state hackers for months |
Chinese state-sponsored threat actors were likely behind the hijacking of Notepad++ update traffic last year that lasted for almost half a year, the developer states in an official announcement today. |
||
|
7.2.26 |
Mandiant details how ShinyHunters abuse SSO to steal cloud data |
Mandiant says a wave of recent ShinyHunters SaaS data-theft attacks is being fueled by targeted voice phishing (vishing) attacks and company-branded phishing sites that steal single sign-on (SSO) credentials and multi-factor authentication (MFA) codes. |
||
|
6.2.26 |
China-Linked DKnife AitM Framework Targets Routers for Traffic Hijacking, Malware Delivery |
Cybersecurity researchers have taken the wraps off a gateway-monitoring and adversary-in-the-middle (AitM) framework dubbed DKnife that's operated by |
||
|
6.2.26 |
Asian State-Backed Group TGR-STA-1030 Breaches 70 Government, Infrastructure Entities |
A previously undocumented cyber espionage group operating from Asia broke into the networks of at least 70 government and critical infrastructure |
||
|
5.2.26 |
Get SafeBreach Labs’s latest update on the threat actor, including new details about their Telegram attack vector, a strike back attempt at SafeBreach researchers, the discovery of a new Tornado malware variant, and activity that indicates a definitive connection to the Iranian government. |
|||
|
5.2.26 |
Infy Hackers Resume Operations with New C2 Servers After Iran Internet Blackout Ends |
The elusive Iranian threat group known as Infy (aka Prince of Persia) has evolved its tactics as part of efforts to hide its tracks, even as it readied new |
||
|
4.2.26 |
China-Linked Amaranth-Dragon Exploits WinRAR Flaw in Espionage Campaigns |
Threat actors affiliated with China have been attributed to a fresh set of cyber espionage campaigns targeting government and law enforcement agencies |
||
|
3.2.26 |
APT28 Uses Microsoft Office CVE-2026-21509 in Espionage-Focused Malware Attacks |
The Russia-linked state-sponsored threat actor known as APT28 (aka UAC-0001) has been attributed to attacks exploiting a newly disclosed security flaw |
||
|
3.2.26 |
Notepad++ Hosting Breach Attributed to China-Linked Lotus Blossom Hacking Group |
A China-linked threat actor known as Lotus Blossom has been attributed with medium confidence to the recently discovered compromise of the |
||
|
31.1.26 |
Iran-Linked RedKitten Cyber Campaign Targets Human Rights NGOs and Activists |
A Farsi-speaking threat actor aligned with Iranian state interests is suspected to be behind a new campaign targeting non-governmental organizations and |
||
|
31.1.26 |
China-Linked UAT-8099 Targets IIS Servers in Asia with BadIIS SEO Malware |
Cybersecurity researchers have discovered a new campaign attributed to a China-linked threat actor known as UAT-8099 that took place between late |
||
|
28.1.26 |
APT Attacks Target Indian Government Using GOGITTER, GITSHELLPAD, and GOSHELL | Part 1 |
In September 2025, Zscaler ThreatLabz identified two campaigns, tracked as Gopher Strike and Sheet Attack, by a threat actor that operates in Pakistan and primarily targets entities in the Indian government. |
||
|
28.1.26 |
Experts Detect Pakistan-Linked Cyber Campaigns Aimed at Indian Government Entities |
Indian government entities have been targeted in two campaigns undertaken by a threat actor that operates in Pakistan using previously undocumented |
||
|
25.1.26 |
Sandworm hackers linked to failed wiper attack on Poland’s energy systems |
A cyberattack targeting Poland's power grid in late December 2025 has been linked to the Russian state-sponsored hacking group Sandworm, which attempted to deploy a new destructive data-wiping malware dubbed DynoWiper during the attack.. |
||
|
25.1.26 |
Konni hackers target blockchain engineers with AI-built malware |
The North Korean hacker group Konni (Opal Sleet, TA406) is using AI-generated PowerShell malware to target developers and engineers in the blockchain sector. |
||
|
25.1.26 |
UK govt. warns about ongoing Russian hacktivist group attacks |
The U.K. government is warning of continued malicious activity from Russian-aligned hacktivist groups targeting critical infrastructure and local government organizations in the country in disruptive denial-of-service (DDoS) attacks. |
||
|
22.1.26 |
North Korean PurpleBravo Campaign Targeted 3,136 IP Addresses via Fake Job Interviews |
As many as 3,136 individual IP addresses linked to likely targets of the Contagious Interview activity have been identified, with the campaign claiming |
||
|
22.1.26 |
North Korea-Linked Hackers Target Developers via Malicious VS Code Projects |
The North Korean threat actors associated with the long-running Contagious Interview campaign have been observed using malicious Microsoft Visual |
||
|
18.1.26 |
China-linked hackers exploited Sitecore zero-day for initial access |
An advanced threat actor tracked as UAT-8837 and believed to be linked to China has been focusing on critical infrastructure systems in North America, gaining access by exploiting both known and zero-day vulnerabilities. |
||
|
16.1.26 |
China-Linked APT Exploits Sitecore Zero-Day in Attacks on American Critical Infrastructure |
A threat actor likely aligned with China has been observed targeting critical infrastructure sectors in North America since at least last year. Cisco Talos, which is tracking the activity |
||
|
11.1.26 |
New China-linked hackers breach telcos using edge device exploits |
A sophisticated threat actor that uses Linux-based malware to target telecommunications providers has recently broadened its operations to include organizations in Southeastern Europe. |
||
|
10.1.26 |
FBI warns about Kimsuky hackers using QR codes to phish U.S. orgs |
The North Korean state-sponsored hacker group Kimsuki is using malicious QR codes in spearphishing campaigns that target U.S. organizations, the Federal Bureau of Investigation warns in a flash alert. |
||
|
10.1.26 |
China-Linked Hackers Exploit VMware ESXi Zero-Days to Escape Virtual Machines |
Chinese-speaking threat actors are suspected to have leveraged a compromised SonicWall VPN appliance as an initial access vector to deploy a VMware ESXi exploit that may have |
||
|
10.1.26 |
Russian APT28 Runs Credential-Stealing Campaign Targeting Energy and Policy Organizations |
Russian state-sponsored threat actors have been linked to a fresh set of credential harvesting attacks targeting individuals associated with a Turkish energy and nuclear |
||
|
8.1.26 |
China-Linked UAT-7290 Targets Telecoms with Linux Malware and ORB Nodes |
A China-nexus threat actor known as UAT-7290 has been attributed to espionage-focused intrusions against entities in South Asia and Southeastern Europe. The activity cluster, which |
||
|
6.1.26 |
Russia-Aligned Hackers Abuse Viber to Target Ukrainian Military and Government |
The Russia-aligned threat actor known as UAC-0184 has been observed targeting Ukrainian military and government entities by leveraging the Viber messaging platform to deliver |
||