APT Blog- 2026  2025  2024  2023  2021  2020  2019  2018

AI blog  APT blog  Attack blog  BigBrother blog  BotNet blog  CyberCrime blog  Cyber blog  Cryptocurrency blog  Exploit blog  Hacking blog  ICS blog  Incident blog  IoT blog  Malware blog  OS Blog  Phishing blog  Ransom blog  Safety blog  Security blog  Social blog  Spam blog  Vulnerebility blog 

DATE

NAME

Info

CATEG.

WEB

10.9.26

Attack Cases in Korea Involving the Installation of Radmin and UltraVNC The AhnLab SEcurity intelligence Center (ASEC) recently identified attack cases that exploited Radmin and UltraVNC. Although the Initial Intrusion method remains unknown, the attackers installed Radmin—a remote control tool—and then installed UltraVNC. APT blog Zscaler

8.9.26

Beyond Lazarus: How North Korea Organizes Its Cyber Operations Get the full overview of North Korea's cyber operations, from state institutions and APT clusters to IT workers units, and enablers. APT blog SEKOIA

5.9.26

Beyond Point-in-Time: Continuous Offensive Security with the Cobalt API For enterprise security programs, the challenge was never running offensive security testing against your applications and networks. It's whether the process and results were manageable at scale and could actually drive faster remediation across every business unit and engineering team in the organization. APT blog COBALT

5.9.26

DPRK APTs: Ted backdoor and curlRAT target South Korean media and automotive sectors A new Linux toolkit, identified by Rapid7 Labs, has been targeting organizations across South Korea’s automotive and media industries with minimal detection. The campaign made use of a HAProxy instance named “ted backdoor”, alongside trojanized versions of crond, agetty, atd, sshd, and polkitd. APT blog RAPID7

5.9.26

Chinese-Speaking Operator Uses AI Agents to Target Government and Education Systems Disclosure note: Hunt.io disclosed these findings under TLP:AMBER to the relevant national CERTs for the affected jurisdictions and, following responsible disclosure, held publication until September 3, 2026. APT blog HUNT.IO

5.9.26

Financially Motivated Threat Actor BREEZE COMET Targets Brazil Google Threat Intelligence Group (GTIG) is tracking three distinct suspected Russian cyber espionage threat clusters abusing legitimate authentication flows to target individuals working in academia, aerospace and defense, governments and think tanks across Europe, as well as academia and think tanks within the United States. APT blog GTI

2.9.26

Gaming the system: how a Chinese-speaking actor turned Brazilian government sites into an SEO weapon A Chinese-speaking actor is now targeting Brazil. Check Point Research has uncovered a sustained campaign against Brazilian organizations, primarily government and educational institutions since mid-2025. APT blog CHECKPOINT

31.8.26

Carry-On Compromise: TA4922 Packs PackClient Proofpoint researchers recently discovered a RAT framework we named PackClient. PackClient is being used by at least one threat actor, Chinese-speaking TA4922, and appears to be actively sold on Telegram. PackClient is a full featured, modular command and control (C2) framework that supports data theft, surveillance, and downloading of additional plugins and payloads. APT blog PROOFPOINT

29.8.26

Inside SHADOW-WATER-084: A Steganographic Loader-as-a-Service Delivering Remcos, LXBASE, and More

TrendAI™ Research tracked three campaigns that ship completely different decoy applications and unrelated payloads, all riding one shared toolkit. This analysis covers the full chain, from the pixel data that hides the first stage, through a flexible shared loader to deliver multiple payloads, revealing how adversaries are standardizing their delivery mechanisms.

APT blog

Trend Micro

29.8.26

Chinese Implants in the Supply Chain

The implant beacons hit the sinkhole as soon as we stood it up. Hundreds of routers, almost all in China, beaconing home to a forgotten domain. We found the domain obfuscated in the firmware of a router we bought on Amazon from a small company in New York. Now, we own the domain. We own the implants.

APT blog

VULNCHECK

29.8.26 July 2026 Threat Trend Report on APT Attacks (South Korea) Overview AhnLab monitored APT (Advanced Persistent Threat) attacks targeting entities in Korea using its own infrastructure. This report summarizes the classification, statistics, and functional characteristics for each type of domestic APT attacks identified during the month of July 2026. APT blog Zscaler
29.8.26 Insights into Suspected DPRK Workers: Red Flags to Look Out For North Korean (DPRK) remote IT workers (sometimes referred to as FAMOUS CHOMILLA) continue to pose a prolific threat to global organisations. DPRK-aligned operatives use fake or stolen identities to get hired at companies before sending their wages back to North Korea's regime, stealing data, or planting malware. APT blog Huntress
29.8.26 BlueDelta Targets Defense and Diplomacy with HOOKEDGE Insikt Group has identified a series of BlueDelta initial access campaigns conducted between late September 2025 and early April 2026, targeting government and diplomatic organizations in Romania, Spain, and Türkiye. APT blog Recorded Futures
29.8.26 Carry-On Compromise: TA4922 Packs PackClient Proofpoint researchers recently discovered a RAT framework we named PackClient. PackClient is being used by at least one threat actor, Chinese-speaking TA4922, and appears to be actively sold on Telegram. PackClient is a full featured, modular command and control (C2) framework that supports data theft, surveillance, and downloading of additional plugins and payloads. APT blog PROOFPOINT
29.8.26 TA488 Targets Zimbra Mailservers with Half-Click Exploits Proofpoint uncovered that Russia-aligned threat actor TA488 (Void Blizzard, Laundry Bear) was exploiting a previously unknown vulnerability against Zimbra mailservers for at least five months during 2025, until the issue was patched with CVE-2025-66376. APT blog PROOFPOINT
29.8.26 Operation RoundPress Rolls on with More Half-Click Webmail Zero-Days from TA458 The Russia-aligned threat actor TA458, the group behind Operation RoundPress, continues to focus on webmail targeting using half-click exploits as a way to steal highly sensitive email data. APT blog PROOFPOINT
27.8.26 Introducing CylindricalCanine: The GoldenEyeDog subgroup responsible for the April DigiCert incident Chinese cybercrime group, GoldenEyeDog, has been regularly updating their malware and tactics since 2015. We’ve observed them regularly leveraging code-signing certificates to bypass Windows’s SmartScreen since 2024. APT blog Expel
27.8.26 Inside China-nexus cyber espionage infrastructure Black Lotus Labs and the FBI uncovered China-nexus infrastructure used to hide cyber espionage, showing how early detection helps protect customers. APT blog LUMEN
27.8.26 Philippine Nuclear Agency and Naval Contractor Targeted by Suspected Chinese-Speaking Operator Using Known Vulnerabilities Disclosure note: Hunt.io disclosed these findings to CERT-PH under TLP:AMBER and, following responsible disclosure, held publication until August 25, 2026. CERT-PH coordinated notification to the affected organizations. APT blog HUNT.IO
27.8.26 Tortoiseshell: New Toolset and Operational Infrastructure Exposed Group-IB Threat Intelligence performed enrichment and APT hunting based on recent public data about the Tortoiseshell APT group, leading to the discovery of new samples sharing similarities with known Tortoiseshell malware and additional operational infrastructure. APT blog GROUP-IB
22.8.26 Bird Watching: Characterizing the Infrastructure and Behavior of Falcon-branded Extortion Operations Increased attention has been called to a sustained adversary-in-the-middle (AitM) phishing and vishing operation targeting financial services, professional services, energy and technology organizations since at least April 2026. This activity aligns with the threat cluster publicly designated UNC6671 by Google Threat Intelligence Group and O-UNC-045 / CORDIAL SPIDER by Okta Threat Intelligence, operating under extortion brands including Falcon, Helix, Pink and Redact (formerly BlackFile). APT blog GUIDESECURITY

22.8.26

July 2026 Threat Trend Report on APT Groups The July 2026 Threat Trend Report on APT Groups summarizes the trend in which state-sponsored threat actors and financially motivated attackers are employing a combination of supply chain attacks, account takeovers, cloud breaches, and social engineering techniques. Key targets include Microsoft 365, webmail accounts, cloud infrastructure, GitHub and development environments, VPN and remote access systems, mobile devices, and credentials stored in browsers. APT blog AHNLAB

22.8.26

North Korean IT Workers Scheme: Detection IOCs and Tactics for Government and Corporate SOCs The infiltration of North Korean IT workers into American and European organizations has evolved into a sophisticated operation that bypasses traditional security perimeters. By using forged identities and AI-assisted workflows, these operatives successfully transition from external applicants to trusted insiders. APT blog ANYRUN BLOG
22.8.26 PurpleDelta's Fraudulent Employment Operations Insikt Group has identified several clusters of activity linked to PurpleDelta, Recorded Future's designation for North Korean IT workers, comprising multiple operators likely based in China. Between late 2024 and early 2025, one cluster applied to jobs at over 1,100 companies, primarily in the software and technology, staffing and consulting, and healthcare and biotechnology sectors. APT blog Recorded Futures

22.8.26

Going with the Flow(s): Distinct Clusters Target Individuals of Interest to Russia Google Threat Intelligence Group (GTIG) is tracking three distinct suspected Russian cyber espionage threat clusters abusing legitimate authentication flows to target individuals working in academia, aerospace and defense, governments and think tanks across Europe, as well as academia and think tanks within the United States.  APT blog GTI

22.8.26

UAT-10147 deploys SPECTRE: A cross-platform implant with Linux rootkit and BYOVD capabilities The newly identified SPECTRE implant represents an evolution in commodity intrusion tooling, integrating cross-platform C2 operations, process injection, credential theft, anti-analysis protections, and kernel-level endpoint detection and response (EDR) bypass functionality. APT blog CISCO TALOS
22.8.26 UAT-10147: Chinese-speaking adversary integrates agentic AI into post-compromise operations Cisco Talos discovered a Chinese-speaking cybercrime group, tracked as UAT-10147, that targets a wide range of vulnerable web servers. This is an overview of the campaign, examining the countries affected, potential impact of BadIIS infections, the attack chain, and post-compromise tactics. APT blog CISCO TALOS

15.8.26

Jewelbug: APT Group Runs Espionage and Crypto Fraud Operations Side by Side China-based hackers-for-hire group is breaking into government ministries across the Middle East and Asia from the same control panel it uses to run an industrial-scale cryptocurrency fraud business. APT blog SECURITY.COM

15.8.26

Shattering the Dream – When a Job Offer Becomes a Zero-Day Attack Check Point Research is tracking a long‑running campaign called Operation Dream Job, targeting organizations worldwide, with a particular focus on the defense sector. The campaign is affiliated to DPRK-linked Lazarus group and its latest wave focuses on the defense sector in Europe and India. APT blog CHECKPOINT

1.8.26

June 2026 Threat Trend Report on APT Attacks (South Korea) AhnLab monitored domestic APT (Advanced Persistent Threat) attacks—which are conducted covertly and persistently—using its own infrastructure. This report summarizes the classification and statistics on domestic APT attacks identified in June 2026 and describes the capabilities of each type of APT attack. APT blog AHNLAB

1.8.26

Cleaning Out Inboxes: TA488 Comes for Outlook with Another Half-Click Exploit On 22 July 2026 (the day prior to Proofpoint’s joint release with the NSA), TA488 initiated a new wave of exploitation abusing a cross-site scripting (XSS) vulnerability, CVE-2026-42897, in Outlook Web Access (OWA). Proofpoint did not have sufficient time to analyze, action, and incorporate the new activity into existing reporting, so we are issuing a rapid follow-up to highlight this activity. APT blog PROOFPOINT

1.8.26

Batten Down Your Packages: Mitigation Guidance for Supply Chain Compromise For years, the cybersecurity industry's understanding of software supply chain compromise has been anchored by a few watershed events, including Russian cyber espionage actor ICE RELIC’s (formerly known as APT29) 2020 compromise of SolarWinds and North Korean cyber espionage actor UNC4736's 2023 compromise of 3CX. APT blog GTI

1.8.26

APTs Top the List of Most Active Threat Actors in H1 2026 These are the most active threat actors in H1 2026 as APT groups lead global cyber operations, followed by ransomware and hacktivist campaigns. APT blog Cyble

25.7.26

Updated Cyber Threat Actor Naming System Today, Google Threat Intelligence Group (GTIG) will begin rolling out a unified naming schema for tracking threat actors. This new naming taxonomy represents an effort to standardize tracking across platforms and public reporting. APT blog GTI

25.7.26

Russian Global Webmail Espionage Unit 42 has observed a persistent cyberespionage campaign we track as CL-STA-1114. This activity cluster overlaps with activity from a Russian threat actor tracked by other vendors as Void Blizzard and LAUNDRY BEAR. APT blog Palo Alto

18.7.26

Four years after Symantec first uncovered Daxin, the most advanced malware we had seen from a China-linked actor, it has been found running inside a Taiwan manufacturing firm, deployed with a novel new backdoor. APT blog SECURITY.COM
11.7.26 Cavern Manticore: Exposing Iran-Linked Modular C2 Framework Note: SysAid was not compromised, and no SysAid vulnerability was involved. The attacker had already gained access to the victim environment and abused a legitimate software-deployment feature to deploy malware onto another machine within it. APT blog CHECKPOINT
4.7.26 The Bear Necessities: A Look at the Drivers, Dynamics, and Applications of the Pro-Russia Influence Ecosystem Four years into Russia’s full-scale invasion of Ukraine, the pro-Russia influence ecosystem has evolved from a tool of war back into a global strategic asset. Since the mobilization of this ecosystem to support frontline objectives, we have witnessed the expedited development of new influence assets linked to multiple, expansive, covert information operations (IO) campaigns and a revitalization of pro-Russia hacktivism at an unprecedented scale. APT blog GTI
4.7.26 CL-STA-1062 Targets Southeast Asian Governments and Critical Infrastructure Throughout 2025, we observed a cluster of activity targeting government entities and critical infrastructure in Southeast Asia. Specifically, the activity targeted state-owned enterprises in the energy and government sectors. APT blog Palo Alto
27.6.26 CL-STA-1062 Targets Southeast Asian Governments and Critical Infrastructure Throughout 2025, we observed a cluster of activity targeting government entities and critical infrastructure in Southeast Asia. Specifically, the activity targeted state-owned enterprises in the energy and government sectors. APT blog Palo Alto
19.6.26 Public and Private Medical Community Targeted by China-Nexus Threat Actor Pursuing Artificial Intelligence, Cyber, Medical, and National Defense Research Google Threat Intelligence Group (GTIG) has identified a sophisticated campaign attributed to UNC6508, a People's Republic of China (PRC)-nexus threat actor, targeting institutions in the North American academic, medical, and military research community. APT blog GTI
13.6.26 OceanLotus: From external espionage to domestic targeting A shift in operational pattern of the infamous Vietnam-aligned APT group APT blog Eset
30.5.26 ESET APT Activity Report Q4 2025–Q1 2026 An overview of the activities of selected APT groups investigated and analyzed by ESET Research in Q4 2025 and Q1 2026 APT blog Eset
23.5.26 Fast16: Pre-Stuxnet Sabotage Tool Was Built to Subvert Nuclear Weapons Simulations New analysis confirms the targeted applications and reveals fast16 was tailored to corrupt uranium-compression simulations central to nuclear weapon design. APT blog SECURITY.COM
23.5.26 Exposing Fox Tempest: A malware-signing service operation  Fox Tempest is a financially motivated threat actor operating a malware‑signing‑as‑a‑service (MSaaS) used by other cybercriminals, including Vanilla Tempest and Storm groups, to more effectively distribute malicious code, including ransomware. APT blog Microsoft blog
23.5.26 From PDB strings to MaaS: Tracking a commodity BadIIS ecosystem used by Chinese-speaking threat Cisco Talos has uncovered a BadIIS variant — identifiable by its embedded "demo.pdb" strings — that functions as commodity malware, likely sold or shared among multiple Chinese-speaking cyber crime groups operating under a malware-as-a-service (MaaS) model for continuous monetization. APT blog CISCO TALOS
16.5.26 Iran-linked threat actor abused signed Fortemedia and SentinelOne binaries for DLL sideloading and exfiltrated data through a public file-transfer service. APT blog SECURITY.COM
16.5.26 FrostyNeighbor: Fresh mischief and digital shenanigans ESConflict is a boon for opportunistic fraudsters. Look out for their ploys.ET researchers uncovered new activities attributed to FrostyNeighbor, updating its compromise chain to support the group’s continual cyberespionage operations APT blog Eset
9.5.26 UAT-8302 and its box full of malware Cisco Talos is disclosing UAT-8302, a sophisticated, China-nexus advanced persistent threat (APT) group targeting government entities in South America since at least late 2024 and government agencies in southeastern Europe in 2025. APT blog CISCO TALOS
9.5.26 A rigged game: ScarCruft compromises gaming platform in a supply-chain attack ESET researchers have investigated an ongoing attack by the ScarCruft APT group that targets the Yanbian region via backdoor-laced Windows and Android games APT blog Eset
2.5.26 Inside Shadow-Earth-053: A China-Aligned Cyberespionage Campaign Against Government and Defense Sectors in Asia A China-aligned threat group is exploiting unpatched Microsoft Exchange vulnerabilities to conduct cyberespionage against government and critical infrastructure targets across Asia and beyond. APT blog Trend Micro
25.4.26 The Harvester APT group has developed a new, highly-evasive, Linux version of its GoGra backdoor. The malware uses the legitimate Microsoft Graph API and Outlook mailboxes as a covert command-and-control (C2) channel, allowing it to bypass traditional perimeter network defenses. APT blog SECURITY.COM
18.4.26 State-sponsored threats: Different objectives, similar access paths A look at 2025 state-sponsored threats, exploring how actors linked to China, Russia, North Korea, and Iran use vulnerabilities, identity, and trusted access paths to achieve their goals. APT blog CISCO TALOS
4.4.26 North Korea-Nexus Threat Actor Compromises Widely Used Axios NPM Package in Supply Chain Attack Google Threat Intelligence Group (GTIG) is tracking an active software supply chain attack targeting the popular Node Package Manager (NPM) package "axios." Between March 31, 2026, 00:21 and 03:20 UTC, an attacker introduced a malicious dependency named "plain-crypto-js" into axios NPM releases versions 1.14.1 and 0.30.4. Axios is the most popular JavaScript library used to simplify HTTP requests, and these packages typically have over 100 million and 83 million weekly downloads, respectively. APT blog GTI
4.4.26 Professional Networks Under Attack: Vietnam-Linked Actors Deploy PXA Stealer in Global Infostealer Campaign Cyble dissects a LinkedIn job‑lure campaign, exposing its multi‑stage PXA Stealer tactic that hijacks accounts and steals sensitive data. APT blog Cyble
28.3.26 China’s APT41 and the Expanding Enterprise Attack Surface: What Security Teams Must Prepare For APT41’s hybrid model exposes gaps in enterprise security, targeting cloud, supply chains, and OT with advanced tactics and persistent access. APT blog Cyble
21.3.26 Inside Russia’s Shift to Credential-Based Intrusions: What CISOs Need to Know in 2026 Russia’s credential-based intrusions are rising, leading to more account takeover attacks and new risks for critical infrastructure in 2026. APT blog Cyble
14.3.26 Initial access techniques used by Iran-based threat actors Analysis of attacks originating from Iran-linked threat groups reveals a preference for certain techniques APT blog SOPHOS
14.3.26 Deno Runtime Exploited: The Emerging Threat You Can’t Ignore Recently, the SonicWall Capture Labs threat research team observed threat actors have started abusing Deno, a modern JavaScript runtime, to run malicious JavaScript outside the browser, bypassing the need for Node.js. APT blog SonicWall
14.3.26 Suspected China-Based Espionage Operation Against Military Targets in Southeast Asia We identified a cluster of malicious activity targeting Southeast Asian military organizations, suspected with moderate confidence to be operating out of China. We designate this cluster as CL-STA-1087, with STA representing our assessment that the activity is conducted by state-sponsored actors. We traced this activity back to at least 2020. APT blog Palo Alto
14.3.26 Iranian MOIS Actors & the Cyber Crime Connection Iran-linked actors are increasingly engaging with the cyber crime ecosystem. Their activity suggests a growing reliance on criminal tools, services, and operational models in support of state objectives. APT blog CHECKPOINT
14.3.26 “Handala Hack” – Unveiling Group’s Modus Operandi Handala Hack is an online persona operated by Void Manticore (aka Red Sandstorm, Banished Kitten), an actor affiliated with Iranian Ministry of Intelligence and Security (MOIS) APT blog CHECKPOINT
14.3.26 Sednit reloaded: Back in the trenches The resurgence of one of Russia’s most notorious APT groups APT blog Eset
7.3.26 Middle East on the Brink: Iran-US-Israel Hostilities Trigger Cyber-Kinetic Conflict Middle East faces unprecedented hybrid warfare as Iran, US, and Israel clash through cyberattacks, missile strikes, and hacktivist campaigns. APT blog Cyble
7.3.26 This activity began in early February and has continued in recent days. What organizations should expect next from Iran-aligned groups and the steps they should take to guard against cyberattacks. APT blog SECURITY.COM
7.3.26 An Investigation Into Years of Undetected Operations Targeting High-Value Sectors Since at least 2020, we have observed a cluster of activity targeting high-value organizations across South, Southeast and East Asia. The attacks focus on critical sectors such as aviation, energy, government, law enforcement, pharmaceutical, technology and telecommunications. APT blog Palo Alto
7.3.26 Threat Brief: March 2026 Escalation of Cyber Risk Related to Iran On Feb. 28, 2026, the United States and Israel launched a significant joint offensive code named Operation Epic Fury (U.S.) and Operation Roaring Lion (Israel). In the hours following the initial strikes, Iran began a multi-vector retaliatory campaign, which has evolved into a significant trans-regional conflict. APT blog Palo Alto
7.3.26 Interplay between Iranian Targeting of IP Cameras and Physical Warfare in the Middle East During the ongoing conflict, we identified intensified targeting of IP cameras from two manufacturers starting on February 28, originating from infrastructure we attribute to Iranian threat actors. APT blog CHECKPOINT
7.3.26 Silver Dragon Targets Organizations in Southeast Asia and Europe Check Point Research (CPR) is tracking Silver Dragon, an advanced persistent threat (APT) group which has been actively targeting organizations across Europe and Southeast Asia since at least mid-2024. The actor is likely operating within the umbrella of Chinese-nexus APT41. APT blog CHECKPOINT
7.3.26 Talos on the developing situation in the Middle East Cisco Talos continues to monitor the ongoing conflict in the Middle East. As always, we will be watching closely for any cyber-related incidents that are tied to the conflict. APT blog CISCO TALOS
7.3.26 UAT-9244 targets South American telecommunication providers with three new malware implants Cisco Talos is disclosing UAT-9244, who we assess with high confidence is a China-nexus advanced persistent threat (APT) actor closely associated with Famous Sparrow. APT blog CISCO TALOS
7.3.26 The Iranian Cyber Capability 2026 This report examines Iranian-linked threat activity from 2024 onward. APT blog Trelix
28.2.26 North Korean attackers continuing to mount extortion attacks against the U.S. healthcare sector despite indictment. APT blog SECURITY.COM
14.2.26 A Peek Into Muddled Libra’s Operational Playbook During a September 2025 incident response investigation, Unit 42 discovered a rogue virtual machine (VM) which we believe with high confidence to be used by the cybercrime group Muddled Libra (aka Scattered Spider, UNC3944). The contents of this rogue VM and activity from the attack provide valuable insight into the operational playbook of this threat actor. APT blog Palo Alto
13.2.26 Lotus Blossom (G0030) and the Notepad++ Supply-Chain Espionage Campaign In late 2025 and early 2026, a series of independent disclosures by software maintainers, security researchers, and national cyber authorities converged on an unsettling conclusion: for months, the update mechanism of one of the world’s most widely used open-source text editors had been quietly subverted. APT blog DomainTools Investigation
7.2.2026 The Shadow Campaigns: Uncovering Global Espionage This investigation unveils a new cyberespionage group that Unit 42 tracks as TGR-STA-1030. We refer to the group’s activity as the Shadow Campaigns. We assess with high confidence that TGR-STA-1030 is a state-aligned group that operates out of Asia. Over the past year, this group has compromised government and critical infrastructure organizations across 37 countries. APT blog Palo Alto
7.2.2026 Amaranth-Dragon: Weaponizing CVE-2025-8088 for Targeted Espionage in the Southeast Asia Check Point Research (CPR) has been tracking Amaranth-Dragon, a nexus of APT-41, previously aligned with Chinese interests. The group launched highly targeted cyber-espionage campaigns throughout 2025 against government and law enforcement agencies in Southeast Asia. APT blog CHECKPOINT
7.2.2026 APT28’s Stealthy Multi-Stage Campaign Leveraging CVE‑2026‑21509 and Cloud C2 Infrastructure Russian state-sponsored threat group APT28 (aka Fancy Bear or UAC-0001) has launched a sophisticated espionage campaign targeting European military and government entities, specifically targeting maritime and transport organizations across Poland, Slovenia, Turkey, Greece, the UAE, and Ukraine. APT blog Trelix
1.2.26 Dissecting UAT-8099: New persistence mechanisms and regional focus Cisco Talos has identified a new, regionally targeted campaign by UAT-8099 that leverages advanced persistence techniques and custom BadIIS malware variants to compromise IIS servers, particularly in Thailand and Vietnam. APT blog CISCO TALOS
24.1.26 The Invisible Insider: Why AML and KYC Compliance Fail Against Digital Deception North Korean operatives and professional money launderers have been drawing six-figure salaries from Fortune Global 500 companies by exploiting a fundamental flaw in identity verification. APT blog Silent Push
24.1.26 From the Shadows to the Headlines: A Decade of State-Sponsored Cyber Leaks Analysis of a decade of major state-sponsored cyber leaks (Shadow Brokers, Vault 7, i-Soon, KittenBusters): patterns, impact, and the centrality of human vulnerability. APT blog Trelix
17.1.26 Unmasking the DPRK Remote Worker Problem The DPRK remote worker program functions as a high-volume revenue engine for the North Korean regime. These state-sponsored operatives use stolen identities to secure remote roles within Western enterprises. They establish long-term persistence inside corporate infrastructure before their first meeting. These actors bypass standard IAM and EDR by mimicking the behavior, location, and hardware signatures of a domestic employee. APT blog Silent Push
17.1.26 APT PROFILE – KIMSUKI Kimsuki, an advanced persistent threat (APT) group active since at least 2012, is suspected to be operating out of North Korea in direct support of the regime’s strategic objectives. The… APT blog

Cyfirma

17.1.26 Inside RedVDS: How a single virtual desktop provider fueled worldwide cybercriminal operations Microsoft’s investigation into RedVDS services and infrastructure uncovered a global network of disparate cybercriminals purchasing and using to target multiple sectors. APT blog Microsoft blog
17.1.26 UAT-8837 targets critical infrastructure sectors in North America Cisco Talos is closely tracking UAT-8837, a threat actor we assess with medium confidence is a China-nexus advanced persistent threat (APT) actor. APT blog CISCO TALOS
10.1.26 Initial Access Sales Accelerated Across Australia and New Zealand in 2025 Cyble’s 2025 report analyzes Initial Access sales, ransomware operations, and data breaches shaping the cyber threat landscape in Australia and New Zealand. APT blog

Cyble

10.1.26 Resurgence of Scattered Lapsus$ hunters Executive Summary: Recent monitoring of underground forums and Telegram communities has identified the resurgence of the Scattered Lapsus$ collective. The actors appear to be APT blog Cyfirma
10.1.26 UAT-7290 targets high value telecommunications infrastructure in South Asia Talos assesses with high confidence that UAT-7290 is a sophisticated threat actor falling under the China-nexus of advanced persistent threat actors (APTs). UAT-7290 primarily targets telecommunications providers in South Asia. APT blog

CISCO TALOS

10.1.26 Resolutions, shmesolutions (and what’s actually worked for me) Talos' editor ditches the pressure of traditional New Year’s resolutions in favor of practical, in-the-moment changes, and finds more success by letting go of perfection. Plus, we break down the latest on UAT-7290, a newly disclosed threat actor targeting critical infrastructure. APT blog

CISCO TALOS