Threat Feed
Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.
Filtered Reports
30 / 258 results
highperson_alertThreat ActorSMOKE#SCREEN Campaign Deploys ScreenConnect via Fake Software Updates
SMOKE#SCREEN is an unattributed multi-wave campaign active as of August 2026 that leverages social engineering to deploy ConnectWise ScreenConnect RMM software for persistent remote access.
highperson_alertThreat ActorDOUBLECUP LaaS Uses ClickFix and Steganography to Deploy CountLoader
DOUBLECUP is a Russian loader-as-a-service (LaaS) operation active since early June 2026. The service provides operators with licenses and a Go-based Windows GUI client to orchestrate campaigns that deliver malware via ClickFix social engineering lur…
highperson_alertThreat ActorMidnight Blizzard targets hospitality Wi-Fi in CaptiveCrunch campaign
Midnight Blizzard (APT29, also tracked as Storm-2945, IRON RITUAL, IRON HEMLOCK, NobleBaron, Dark Halo) is a Russian-attributed advanced persistent threat group linked to intelligence collection operations.
highperson_alertThreat ActorDOUBLECUP loader-as-a-service delivers malware via ClickFix attacks
DOUBLECUP is a Russian loader-as-a-service platform that has operated since early June 2026. The service provides customers with licenses and a Go-based Windows tool for creating malicious ClickFix campaigns.
highbug_reportVulnerabilityFake Xeno Executor installers infect Roblox players with RAT malware
Roblox players downloading fake Xeno Executor script launcher installers from gaming forums, Discord communities, and compromised accounts. Campaign active since January 2026 with sharp increase in March.
highbug_reportVulnerabilityBTMOB Android RAT ecosystem fragments into resellers and source-code sales
Organizations and individuals targeted by BTMOB Android RAT malware-as-a-service (MaaS). BTMOB is an Android remote access trojan distributed through multiple channels including official operators, resellers, and source-code buyers.
highperson_alertThreat ActorChinese-Speaking Actor Deploys GHOSTBLADE via Leaked DarkSword iOS Kit
An unidentified Chinese-speaking threat actor conducting mobile exploitation campaigns against iOS devices. The actor operates extensive infrastructure spanning over 100 web properties concentrated in Hong Kong with reach into Japan, the United State…
highperson_alertThreat ActorStorm-2945 Hijacks Hotel Wi-Fi to Deploy CornFlake Surveillance RAT
Storm-2945 is assessed by Microsoft to be an operational sub-cluster of Midnight Blizzard (APT29, Cozy Bear), which the U.S. and U.K. governments attribute to Russia's Foreign Intelligence Service (SVR). The U.K.
highperson_alertThreat ActorStorm-2945 Exploits Captive Portals in CaptiveCrunch Espionage Campaign
Storm-2945 is an operational sub-cluster of Midnight Blizzard (APT29), a Russia-based threat actor attributed by US and UK governments to the Foreign Intelligence Service of the Russian Federation (SVR).
highperson_alertThreat ActorChinese-speaking actor uses DeepSeek AI with Hermes Agent for automation
A Chinese-speaking threat actor leveraging artificial intelligence models to conduct cyberattacks. The actor employs the DeepSeek AI model in combination with the open-source Hermes Agent framework to enable autonomous offensive operations against in…
highbug_reportVulnerabilityCISA warns of rising attacks on internet-exposed PLCs in water systems
Internet-exposed programmable logic controllers (PLCs) in U.S. water and wastewater systems. Specific vendors and models not disclosed in available information.
highperson_alertThreat ActorHollowFrame Loader and Matryoshka Backdoor Target Law Firms
The threat actor behind this campaign remains unattributed. The operation demonstrates sophisticated tradecraft, deploying a previously undocumented Go-based loader framework (HollowFrame) and a Rust-based backdoor (Matryoshka) in targeted spear-phis…
highperson_alertThreat ActorFuyao Campaign: Android TV Boxes Weaponized for Ad Fraud and Proxy Abuse
Zhejiang Fengwo IoT Technology Co., Ltd. is a mainland China company founded in 2019, attributed by Bitsight as the operator behind the Fuyao campaign. The attribution is based on shared TLS certificate data, exposed wiki files, reused email addresse…
highperson_alertThreat Actorknaithe/KnYuan Uses DeepSeek AI for Autonomous Exploitation Campaign
knaithe (also tracked as KnYuan) is a Chinese-speaking threat actor assessed by Unit 42 to be based in Zhuhai, China. Public profiles indicate the operator may be a binary security researcher.
highperson_alertThreat ActorLazarus Deploys Crypto-Stealing Malware via macOS Malvertising Campaign
Lazarus is a North Korea-linked APT group with a sustained focus on financial gain, particularly targeting cryptocurrency assets. Operating under DPRK state sponsorship, the group has evolved its tactics to include sophisticated social engineering ca…
highperson_alertThreat ActorState-Sponsored Campaign Exploits AnySign4PC to Deploy SIGNBT & COPPERHEDGE
South Korean authorities (KISA, National Intelligence Service, National Police Agency, Financial Security Institute) disclosed a state-sponsored campaign targeting South Korean entities.
highperson_alertThreat ActorSilver Fox Deploys 3-Driver BYOVD Chain to Deliver ValleyRAT
Silver Fox is a Chinese cybercrime group known for sophisticated intrusion campaigns targeting organizations in Asia. The group demonstrates advanced operational capabilities through multi-layered attack chains combining BYOVD techniques, DLL side-lo…
highperson_alertThreat ActorChinese-Speaking Actor Uses AI for Autonomous Vulnerability Exploitation
A Chinese-speaking threat actor operating under the aliases knaithe and KnYuan has demonstrated an end-to-end autonomous offensive capability by leveraging AI models for vulnerability scanning and exploitation.
highperson_alertThreat ActorShinyHunters escalates vishing-driven data theft against healthcare sector
ShinyHunters is a financially motivated extortion gang specializing in data theft attacks against cloud SaaS and storage platforms. The group has gained notoriety over the past two years for conducting supply chain attacks on third-party integration…
highbug_reportVulnerabilityCoordinated OT attack disrupts 30+ Minnesota water systems
Over 30 community water systems in Minnesota. Operational technology (OT) systems at local water utilities targeted, including programmable logic controllers and computerized operating systems. Attacks occurred July 26-27, 2026. Threat actor unknown.
highbug_reportVulnerabilityCoordinated attack hits 30+ Minnesota water systems, causes plant outages
Over 30 Minnesota community water systems targeted July 26-27, 2026. Operational technology (OT) infrastructure affected, including programmable logic controllers (PLCs) and human-machine interfaces (HMIs) at water treatment and wastewater facilities…
highbug_reportVulnerabilityNine-year fraud campaign clones Russian firms to steal B2B payments
International businesses conducting B2B trade with Russian fertilizer manufacturers, petrochemical companies, metallurgical plants, logistics operators, and banks. Primary targets: CIS countries and international importers.
highbug_reportVulnerabilityTengu botnet abuses Linux watchdog to force reboots after process kill
Linux-based IoT devices and embedded systems across multiple architectures (i386, amd64, MIPS, ARM, PowerPC, m68k). No specific vendor or device model identified. Devices with exposed Telnet services and weak credentials are primary targets.
highbug_reportVulnerabilityDysphoria botnet infects 200K devices for DDoS and proxy relay attacks
Approximately 200,000 routers, cameras, and IoT devices worldwide. Targets include devices with weak Telnet/SSH credentials and known vulnerabilities: CVE-2025-55182 (React2Shell), CVE-2025-34152, CVE-2025-28137 (Totolink), CVE-2025-9528 (Linksys), C…
highperson_alertThreat ActorJackSkid Adopts Blockchain C2 and Relay Mesh After March Takedown
JackSkid is an IoT botnet operator linked to the Dysphoria botnet family, targeted in coordinated U.S., German, and Canadian law enforcement actions on March 19, 2026.
highperson_alertThreat ActorOperation BlueDash: Phishing Campaign Delivers RMM Tools via Fake Teams
Operation BlueDash is a phishing campaign attributed with moderate-to-high confidence to a threat actor group operating from Nigeria. The attribution is based on analysis of infrastructure, code history, and a GitHub environment used to operate the c…
highperson_alertThreat ActorChina-Linked Group Uses Cruciferra Crypter in Tax-Themed Phishing Campaigns
A China-linked cybercrime group, tracked as TA4922 by Proofpoint, has been conducting opportunistic phishing campaigns targeting Indian taxpayers, tax professionals, and corporate finance teams.
highperson_alertThreat ActorEast Asia-Linked Actor Deploys TELESHIM, MIXEDKEY, BINDCLOAK Against ME Gov
An unattributed threat actor assessed with moderate-to-high confidence to originate from East Asia, based on operational hours (4 a.m.–12 p.m. UTC, peaking 7–11 a.m.
highperson_alertThreat ActorClickFix Abuses Steam Forums to Deliver XMRig Cryptominer
ClickFix is a threat actor conducting social engineering campaigns that leverage fake technical support content to distribute malware. The actor exploits user trust in community-driven platforms, specifically targeting gaming communities through Stea…
highperson_alertThreat ActorSourTrade Campaign Delivers Malware via Browser-Assembled Executables
SourTrade is a malvertising campaign (not a named threat actor group) operating since late 2024. The campaign impersonates legitimate trading platforms—TradingView, Solana, and Luno—to distribute malware to retail traders and cryptocurrency investors…