Curated Cyber Threat Intelligence

Threat Feed

Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.

scheduleUpdated 2026-09-04 · 02:17 UTC
articleTotal: 1172 reports

Filtered Reports

30 / 258 results
Active filter:tag: #campaign✕ clear
SMOKE#SCREEN Campaign Deploys ScreenConnect via Fake Software Updateshighperson_alertThreat Actor
person_alertThreat Actor

SMOKE#SCREEN Campaign Deploys ScreenConnect via Fake Software Updates

SMOKE#SCREEN is an unattributed multi-wave campaign active as of August 2026 that leverages social engineering to deploy ConnectWise ScreenConnect RMM software for persistent remote access.

Adobe4 Aug · 11:11 UTC
DOUBLECUP LaaS Uses ClickFix and Steganography to Deploy CountLoaderhighperson_alertThreat Actor
person_alertThreat Actor

DOUBLECUP LaaS Uses ClickFix and Steganography to Deploy CountLoader

DOUBLECUP is a Russian loader-as-a-service (LaaS) operation active since early June 2026. The service provides operators with licenses and a Go-based Windows GUI client to orchestrate campaigns that deliver malware via ClickFix social engineering lur…

The Hacker News4 Aug · 07:03 UTC
Midnight Blizzard targets hospitality Wi-Fi in CaptiveCrunch campaignhighperson_alertThreat Actor
person_alertThreat Actor

Midnight Blizzard targets hospitality Wi-Fi in CaptiveCrunch campaign

Midnight Blizzard (APT29, also tracked as Storm-2945, IRON RITUAL, IRON HEMLOCK, NobleBaron, Dark Halo) is a Russian-attributed advanced persistent threat group linked to intelligence collection operations.

Microsoft3 Aug · 22:17 UTC
DOUBLECUP loader-as-a-service delivers malware via ClickFix attackshighperson_alertThreat Actor
person_alertThreat Actor

DOUBLECUP loader-as-a-service delivers malware via ClickFix attacks

DOUBLECUP is a Russian loader-as-a-service platform that has operated since early June 2026. The service provides customers with licenses and a Go-based Windows tool for creating malicious ClickFix campaigns.

Microsoft3 Aug · 18:01 UTC
Fake Xeno Executor installers infect Roblox players with RAT malwarehighbug_reportVulnerability
bug_reportVulnerability

Fake Xeno Executor installers infect Roblox players with RAT malware

Roblox players downloading fake Xeno Executor script launcher installers from gaming forums, Discord communities, and compromised accounts. Campaign active since January 2026 with sharp increase in March.

BleepingComputer3 Aug · 17:25 UTC
BTMOB Android RAT ecosystem fragments into resellers and source-code saleshighbug_reportVulnerability
bug_reportVulnerability

BTMOB Android RAT ecosystem fragments into resellers and source-code sales

Organizations and individuals targeted by BTMOB Android RAT malware-as-a-service (MaaS). BTMOB is an Android remote access trojan distributed through multiple channels including official operators, resellers, and source-code buyers.

BleepingComputer3 Aug · 12:45 UTC
Chinese-Speaking Actor Deploys GHOSTBLADE via Leaked DarkSword iOS Kithighperson_alertThreat Actor
person_alertThreat Actor

Chinese-Speaking Actor Deploys GHOSTBLADE via Leaked DarkSword iOS Kit

An unidentified Chinese-speaking threat actor conducting mobile exploitation campaigns against iOS devices. The actor operates extensive infrastructure spanning over 100 web properties concentrated in Hong Kong with reach into Japan, the United State…

Apple3 Aug · 08:49 UTC
Storm-2945 Hijacks Hotel Wi-Fi to Deploy CornFlake Surveillance RAThighperson_alertThreat Actor
person_alertThreat Actor

Storm-2945 Hijacks Hotel Wi-Fi to Deploy CornFlake Surveillance RAT

Storm-2945 is assessed by Microsoft to be an operational sub-cluster of Midnight Blizzard (APT29, Cozy Bear), which the U.S. and U.K. governments attribute to Russia's Foreign Intelligence Service (SVR). The U.K.

Microsoft1 Aug · 04:29 UTC
Storm-2945 Exploits Captive Portals in CaptiveCrunch Espionage Campaignhighperson_alertThreat Actor
person_alertThreat Actor

Storm-2945 Exploits Captive Portals in CaptiveCrunch Espionage Campaign

Storm-2945 is an operational sub-cluster of Midnight Blizzard (APT29), a Russia-based threat actor attributed by US and UK governments to the Foreign Intelligence Service of the Russian Federation (SVR).

Microsoft Security31 Jul · 19:01 UTC
Chinese-speaking actor uses DeepSeek AI with Hermes Agent for automationhighperson_alertThreat Actor
person_alertThreat Actor

Chinese-speaking actor uses DeepSeek AI with Hermes Agent for automation

A Chinese-speaking threat actor leveraging artificial intelligence models to conduct cyberattacks. The actor employs the DeepSeek AI model in combination with the open-source Hermes Agent framework to enable autonomous offensive operations against in…

BleepingComputer31 Jul · 15:35 UTC
CISA warns of rising attacks on internet-exposed PLCs in water systemshighbug_reportVulnerability
bug_reportVulnerability

CISA warns of rising attacks on internet-exposed PLCs in water systems

Internet-exposed programmable logic controllers (PLCs) in U.S. water and wastewater systems. Specific vendors and models not disclosed in available information.

BleepingComputer31 Jul · 14:49 UTC
HollowFrame Loader and Matryoshka Backdoor Target Law Firmshighperson_alertThreat Actor
person_alertThreat Actor

HollowFrame Loader and Matryoshka Backdoor Target Law Firms

The threat actor behind this campaign remains unattributed. The operation demonstrates sophisticated tradecraft, deploying a previously undocumented Go-based loader framework (HollowFrame) and a Rust-based backdoor (Matryoshka) in targeted spear-phis…

The Hacker News31 Jul · 14:39 UTC
Fuyao Campaign: Android TV Boxes Weaponized for Ad Fraud and Proxy Abusehighperson_alertThreat Actor
person_alertThreat Actor

Fuyao Campaign: Android TV Boxes Weaponized for Ad Fraud and Proxy Abuse

Zhejiang Fengwo IoT Technology Co., Ltd. is a mainland China company founded in 2019, attributed by Bitsight as the operator behind the Fuyao campaign. The attribution is based on shared TLS certificate data, exposed wiki files, reused email addresse…

Samsung31 Jul · 12:45 UTC
knaithe/KnYuan Uses DeepSeek AI for Autonomous Exploitation Campaignhighperson_alertThreat Actor
person_alertThreat Actor

knaithe/KnYuan Uses DeepSeek AI for Autonomous Exploitation Campaign

knaithe (also tracked as KnYuan) is a Chinese-speaking threat actor assessed by Unit 42 to be based in Zhuhai, China. Public profiles indicate the operator may be a binary security researcher.

Palo Alto Networks31 Jul · 09:21 UTC
Lazarus Deploys Crypto-Stealing Malware via macOS Malvertising Campaignhighperson_alertThreat Actor
person_alertThreat Actor

Lazarus Deploys Crypto-Stealing Malware via macOS Malvertising Campaign

Lazarus is a North Korea-linked APT group with a sustained focus on financial gain, particularly targeting cryptocurrency assets. Operating under DPRK state sponsorship, the group has evolved its tactics to include sophisticated social engineering ca…

Apple30 Jul · 16:18 UTC
State-Sponsored Campaign Exploits AnySign4PC to Deploy SIGNBT & COPPERHEDGEhighperson_alertThreat Actor
person_alertThreat Actor

State-Sponsored Campaign Exploits AnySign4PC to Deploy SIGNBT & COPPERHEDGE

South Korean authorities (KISA, National Intelligence Service, National Police Agency, Financial Security Institute) disclosed a state-sponsored campaign targeting South Korean entities.

AnySign4PC30 Jul · 08:33 UTC
Silver Fox Deploys 3-Driver BYOVD Chain to Deliver ValleyRAThighperson_alertThreat Actor
person_alertThreat Actor

Silver Fox Deploys 3-Driver BYOVD Chain to Deliver ValleyRAT

Silver Fox is a Chinese cybercrime group known for sophisticated intrusion campaigns targeting organizations in Asia. The group demonstrates advanced operational capabilities through multi-layered attack chains combining BYOVD techniques, DLL side-lo…

The Hacker News30 Jul · 08:32 UTC
Chinese-Speaking Actor Uses AI for Autonomous Vulnerability Exploitationhighperson_alertThreat Actor
person_alertThreat Actor

Chinese-Speaking Actor Uses AI for Autonomous Vulnerability Exploitation

A Chinese-speaking threat actor operating under the aliases knaithe and KnYuan has demonstrated an end-to-end autonomous offensive capability by leveraging AI models for vulnerability scanning and exploitation.

Unit 42 (Palo Alto)30 Jul · 08:00 UTC
ShinyHunters escalates vishing-driven data theft against healthcare sectorhighperson_alertThreat Actor
person_alertThreat Actor

ShinyHunters escalates vishing-driven data theft against healthcare sector

ShinyHunters is a financially motivated extortion gang specializing in data theft attacks against cloud SaaS and storage platforms. The group has gained notoriety over the past two years for conducting supply chain attacks on third-party integration…

BleepingComputer29 Jul · 15:54 UTC
Coordinated OT attack disrupts 30+ Minnesota water systemshighbug_reportVulnerability
bug_reportVulnerability

Coordinated OT attack disrupts 30+ Minnesota water systems

Over 30 community water systems in Minnesota. Operational technology (OT) systems at local water utilities targeted, including programmable logic controllers and computerized operating systems. Attacks occurred July 26-27, 2026. Threat actor unknown.

BleepingComputer29 Jul · 12:55 UTC
Coordinated attack hits 30+ Minnesota water systems, causes plant outageshighbug_reportVulnerability
bug_reportVulnerability

Coordinated attack hits 30+ Minnesota water systems, causes plant outages

Over 30 Minnesota community water systems targeted July 26-27, 2026. Operational technology (OT) infrastructure affected, including programmable logic controllers (PLCs) and human-machine interfaces (HMIs) at water treatment and wastewater facilities…

The Hacker News29 Jul · 11:48 UTC
Nine-year fraud campaign clones Russian firms to steal B2B paymentshighbug_reportVulnerability
bug_reportVulnerability

Nine-year fraud campaign clones Russian firms to steal B2B payments

International businesses conducting B2B trade with Russian fertilizer manufacturers, petrochemical companies, metallurgical plants, logistics operators, and banks. Primary targets: CIS countries and international importers.

Russian companies (fertilizer manufacturers, petrochemical companies)29 Jul · 11:42 UTC
Tengu botnet abuses Linux watchdog to force reboots after process killhighbug_reportVulnerability
bug_reportVulnerability

Tengu botnet abuses Linux watchdog to force reboots after process kill

Linux-based IoT devices and embedded systems across multiple architectures (i386, amd64, MIPS, ARM, PowerPC, m68k). No specific vendor or device model identified. Devices with exposed Telnet services and weak credentials are primary targets.

Linux28 Jul · 13:01 UTC
Dysphoria botnet infects 200K devices for DDoS and proxy relay attackshighbug_reportVulnerability
bug_reportVulnerability

Dysphoria botnet infects 200K devices for DDoS and proxy relay attacks

Approximately 200,000 routers, cameras, and IoT devices worldwide. Targets include devices with weak Telnet/SSH credentials and known vulnerabilities: CVE-2025-55182 (React2Shell), CVE-2025-34152, CVE-2025-28137 (Totolink), CVE-2025-9528 (Linksys), C…

BleepingComputer27 Jul · 19:08 UTC
JackSkid Adopts Blockchain C2 and Relay Mesh After March Takedownhighperson_alertThreat Actor
person_alertThreat Actor

JackSkid Adopts Blockchain C2 and Relay Mesh After March Takedown

JackSkid is an IoT botnet operator linked to the Dysphoria botnet family, targeted in coordinated U.S., German, and Canadian law enforcement actions on March 19, 2026.

The Hacker News27 Jul · 15:16 UTC
Operation BlueDash: Phishing Campaign Delivers RMM Tools via Fake Teamshighperson_alertThreat Actor
person_alertThreat Actor

Operation BlueDash: Phishing Campaign Delivers RMM Tools via Fake Teams

Operation BlueDash is a phishing campaign attributed with moderate-to-high confidence to a threat actor group operating from Nigeria. The attribution is based on analysis of infrastructure, code history, and a GitHub environment used to operate the c…

Microsoft27 Jul · 10:37 UTC
China-Linked Group Uses Cruciferra Crypter in Tax-Themed Phishing Campaignshighperson_alertThreat Actor
person_alertThreat Actor

China-Linked Group Uses Cruciferra Crypter in Tax-Themed Phishing Campaigns

A China-linked cybercrime group, tracked as TA4922 by Proofpoint, has been conducting opportunistic phishing campaigns targeting Indian taxpayers, tax professionals, and corporate finance teams.

The Hacker News27 Jul · 08:51 UTC
East Asia-Linked Actor Deploys TELESHIM, MIXEDKEY, BINDCLOAK Against ME Govhighperson_alertThreat Actor
person_alertThreat Actor

East Asia-Linked Actor Deploys TELESHIM, MIXEDKEY, BINDCLOAK Against ME Gov

An unattributed threat actor assessed with moderate-to-high confidence to originate from East Asia, based on operational hours (4 a.m.–12 p.m. UTC, peaking 7–11 a.m.

The Hacker News27 Jul · 06:48 UTC
ClickFix Abuses Steam Forums to Deliver XMRig Cryptominerhighperson_alertThreat Actor
person_alertThreat Actor

ClickFix Abuses Steam Forums to Deliver XMRig Cryptominer

ClickFix is a threat actor conducting social engineering campaigns that leverage fake technical support content to distribute malware. The actor exploits user trust in community-driven platforms, specifically targeting gaming communities through Stea…

Steam25 Jul · 20:37 UTC
SourTrade Campaign Delivers Malware via Browser-Assembled Executableshighperson_alertThreat Actor
person_alertThreat Actor

SourTrade Campaign Delivers Malware via Browser-Assembled Executables

SourTrade is a malvertising campaign (not a named threat actor group) operating since late 2024. The campaign impersonates legitimate trading platforms—TradingView, Solana, and Luno—to distribute malware to retail traders and cryptocurrency investors…

Bun25 Jul · 16:48 UTC