Curated Cyber Threat Intelligence

Threat Feed

Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.

scheduleUpdated 2026-09-04 · 02:17 UTC
articleTotal: 1172 reports

Filtered Reports

30 / 291 results
Active filter:✕ clear
Silver Fox Deploys 3-Driver BYOVD Chain to Deliver ValleyRAThighperson_alertThreat Actor
person_alertThreat Actor

Silver Fox Deploys 3-Driver BYOVD Chain to Deliver ValleyRAT

Silver Fox is a Chinese cybercrime group known for sophisticated intrusion campaigns targeting organizations in Asia. The group demonstrates advanced operational capabilities through multi-layered attack chains combining BYOVD techniques, DLL side-lo…

The Hacker News30 Jul · 08:32 UTC
Chinese-Speaking Actor Uses AI for Autonomous Vulnerability Exploitationhighperson_alertThreat Actor
person_alertThreat Actor

Chinese-Speaking Actor Uses AI for Autonomous Vulnerability Exploitation

A Chinese-speaking threat actor operating under the aliases knaithe and KnYuan has demonstrated an end-to-end autonomous offensive capability by leveraging AI models for vulnerability scanning and exploitation.

Unit 42 (Palo Alto)30 Jul · 08:00 UTC
Laundry Bear exploits Exchange OWA zero-day to deploy OWAReaper backdoorcriticalperson_alertThreat Actor
person_alertThreat Actor

Laundry Bear exploits Exchange OWA zero-day to deploy OWAReaper backdoor

Laundry Bear (also tracked as Void Blizzard, TA488 by Proofpoint) is a Russian state-sponsored threat actor focused on long-term email intelligence collection.

Microsoft29 Jul · 21:44 UTC
ShinyHunters escalates vishing-driven data theft against healthcare sectorhighperson_alertThreat Actor
person_alertThreat Actor

ShinyHunters escalates vishing-driven data theft against healthcare sector

ShinyHunters is a financially motivated extortion gang specializing in data theft attacks against cloud SaaS and storage platforms. The group has gained notoriety over the past two years for conducting supply chain attacks on third-party integration…

BleepingComputer29 Jul · 15:54 UTC
Nimbus Manticore Deploys NightLedger Backdoor in Middle East Campaignhighperson_alertThreat Actor
person_alertThreat Actor

Nimbus Manticore Deploys NightLedger Backdoor in Middle East Campaign

Nimbus Manticore (also tracked as GalaxyGato, Mirage Kitten, Smoke Sandstorm, Subtle Snail, and UNC1549) is an Iranian state-backed advanced persistent threat group conducting cyber espionage operations.

The Hacker News28 Jul · 09:55 UTC
Fraudulent Sparrow Wallet App on Apple App Store Steals $1.8M in Bitcoinhighperson_alertThreat Actor
person_alertThreat Actor

Fraudulent Sparrow Wallet App on Apple App Store Steals $1.8M in Bitcoin

The threat actor behind this campaign remains unidentified. The operation involved publishing fraudulent cryptocurrency wallet applications on Apple's App Store that impersonated the legitimate Sparrow Wallet.

Apple27 Jul · 15:29 UTC
JackSkid Adopts Blockchain C2 and Relay Mesh After March Takedownhighperson_alertThreat Actor
person_alertThreat Actor

JackSkid Adopts Blockchain C2 and Relay Mesh After March Takedown

JackSkid is an IoT botnet operator linked to the Dysphoria botnet family, targeted in coordinated U.S., German, and Canadian law enforcement actions on March 19, 2026.

The Hacker News27 Jul · 15:16 UTC
Anubis Ransomware Attacks Coca-Cola's Fairlife Subsidiaryhighperson_alertThreat Actor
person_alertThreat Actor

Anubis Ransomware Attacks Coca-Cola's Fairlife Subsidiary

Anubis is a ransomware operation that employs double extortion tactics, combining data encryption with exfiltration and threatened public release of stolen information.

Coca-Cola Company27 Jul · 13:39 UTC
ShinyHunters Claims Ernst & Young Breach via Supply-Chain Attackhighperson_alertThreat Actor
person_alertThreat Actor

ShinyHunters Claims Ernst & Young Breach via Supply-Chain Attack

ShinyHunters is a financially motivated cybercrime extortion gang known for conducting data breaches and operating a data leak site to pressure victims into paying ransoms.

Ernst & Young27 Jul · 13:12 UTC
Operation BlueDash: Phishing Campaign Delivers RMM Tools via Fake Teamshighperson_alertThreat Actor
person_alertThreat Actor

Operation BlueDash: Phishing Campaign Delivers RMM Tools via Fake Teams

Operation BlueDash is a phishing campaign attributed with moderate-to-high confidence to a threat actor group operating from Nigeria. The attribution is based on analysis of infrastructure, code history, and a GitHub environment used to operate the c…

Microsoft27 Jul · 10:37 UTC
China-Linked Group Uses Cruciferra Crypter in Tax-Themed Phishing Campaignshighperson_alertThreat Actor
person_alertThreat Actor

China-Linked Group Uses Cruciferra Crypter in Tax-Themed Phishing Campaigns

A China-linked cybercrime group, tracked as TA4922 by Proofpoint, has been conducting opportunistic phishing campaigns targeting Indian taxpayers, tax professionals, and corporate finance teams.

The Hacker News27 Jul · 08:51 UTC
East Asia-Linked Actor Deploys TELESHIM, MIXEDKEY, BINDCLOAK Against ME Govhighperson_alertThreat Actor
person_alertThreat Actor

East Asia-Linked Actor Deploys TELESHIM, MIXEDKEY, BINDCLOAK Against ME Gov

An unattributed threat actor assessed with moderate-to-high confidence to originate from East Asia, based on operational hours (4 a.m.–12 p.m. UTC, peaking 7–11 a.m.

The Hacker News27 Jul · 06:48 UTC
ClickFix Abuses Steam Forums to Deliver XMRig Cryptominerhighperson_alertThreat Actor
person_alertThreat Actor

ClickFix Abuses Steam Forums to Deliver XMRig Cryptominer

ClickFix is a threat actor conducting social engineering campaigns that leverage fake technical support content to distribute malware. The actor exploits user trust in community-driven platforms, specifically targeting gaming communities through Stea…

Steam25 Jul · 20:37 UTC
SourTrade Campaign Delivers Malware via Browser-Assembled Executableshighperson_alertThreat Actor
person_alertThreat Actor

SourTrade Campaign Delivers Malware via Browser-Assembled Executables

SourTrade is a malvertising campaign (not a named threat actor group) operating since late 2024. The campaign impersonates legitimate trading platforms—TradingView, Solana, and Luno—to distribute malware to retail traders and cryptocurrency investors…

Bun25 Jul · 16:48 UTC
ShinyHunters-themed sextortion campaign exploits leaked breach datahighperson_alertThreat Actor
person_alertThreat Actor

ShinyHunters-themed sextortion campaign exploits leaked breach data

ShinyHunters is a known extortion group that has leaked data from multiple high-profile breaches including Amtrak, Hallmark, Substack, Betterment, CarGurus, ADT, Panera Bread, and McGraw Hill.

BleepingComputer25 Jul · 12:16 UTC
Cl0p Affiliates Exploit PTC Windchill RCE for Manufacturing Data Extortioncriticalperson_alertThreat Actor
person_alertThreat Actor

Cl0p Affiliates Exploit PTC Windchill RCE for Manufacturing Data Extortion

Cl0p (also tracked as Chubby Scorpius, FIN11, Graceful Spider, and Lace Tempest) is a financially-motivated ransomware operation known for systematically exploiting zero-day and N-day vulnerabilities in enterprise file transfer and business-critical…

PTC25 Jul · 08:14 UTC
DevMan RaaS Centralizes Affiliate Operations via Dedicated Portalhighperson_alertThreat Actor
person_alertThreat Actor

DevMan RaaS Centralizes Affiliate Operations via Dedicated Portal

DevMan (tracked as Funky Mantis by PRODAFT) is a ransomware-as-a-service operation that emerged in April 2025, initially as an affiliate for Qilin, DragonForce, Apos, and RansomHub before transitioning to independent RaaS operations.

The Hacker News25 Jul · 07:53 UTC
BlueNoroff Phishing Kit Profiles Crypto Wallets Before Malware Deliveryhighperson_alertThreat Actor
person_alertThreat Actor

BlueNoroff Phishing Kit Profiles Crypto Wallets Before Malware Delivery

BlueNoroff (also tracked as APT38, NICKEL GLADSTONE, BeagleBoyz, Stardust Chollima) is a North Korean state-sponsored threat actor attributed to financially motivated operations targeting the cryptocurrency and technology sectors.

Zoom24 Jul · 13:12 UTC
Hermes AI Agent Used for Post-Exploitation at Thai Finance Ministryhighperson_alertThreat Actor
person_alertThreat Actor

Hermes AI Agent Used for Post-Exploitation at Thai Finance Ministry

The threat actor behind this intrusion remains unattributed. Hunt.io assesses with low-to-medium confidence that the operator is Chinese-speaking or fluent in Chinese, based on linguistic artifacts (password containing "Leishen," meaning thunder god)…

Hermes AI24 Jul · 08:15 UTC
Golden Chickens MaaS Resurfaces With Four New Malware Familieshighperson_alertThreat Actor
person_alertThreat Actor

Golden Chickens MaaS Resurfaces With Four New Malware Families

Golden Chickens (also known as Venom Spider, tracked by Recorded Future as TAG-195) is a financially motivated malware-as-a-service (MaaS) developer that provides tooling to multiple cybercrime groups.

The Hacker News24 Jul · 08:09 UTC
Clop Ransomware Gang Exploits PTC Windchill and FlexPLM Vulnerabilitieshighperson_alertThreat Actor
person_alertThreat Actor

Clop Ransomware Gang Exploits PTC Windchill and FlexPLM Vulnerabilities

Clop (also tracked as Cl0p) is a financially motivated ransomware and data extortion gang with a well-established pattern of targeting enterprise software platforms to steal sensitive data and extort victims.

PTC24 Jul · 05:36 UTC
UAC-0099 Deploys MATCHBOIL.V2 via Fake Notepad++ Pluginhighperson_alertThreat Actor
person_alertThreat Actor

UAC-0099 Deploys MATCHBOIL.V2 via Fake Notepad++ Plugin

UAC-0099 is a Russia-aligned threat group active since at least mid-2022. The actor conducts cyber espionage operations primarily targeting Ukrainian entities.

Notepad++24 Jul · 04:50 UTC
Russian Espionage Group Exploited Zimbra Zero-Day for Email Theftcriticalperson_alertThreat Actor
person_alertThreat Actor

Russian Espionage Group Exploited Zimbra Zero-Day for Email Theft

A Russian state-sponsored espionage group conducted a sustained campaign exploiting a zero-day vulnerability in Zimbra's webmail client. The actor, tracked as TA488 by Proofpoint and CL-STA-1114 by Unit 42, operated undetected for at least five month…

Zimbra23 Jul · 16:36 UTC
Laundry Bear exploits Zimbra XSS zero-day for email thefthighperson_alertThreat Actor
person_alertThreat Actor

Laundry Bear exploits Zimbra XSS zero-day for email theft

Laundry Bear (also tracked as Void Blizzard by Microsoft) is a Russian state-sponsored APT group first publicly attributed by Dutch intelligence agencies in May 2025 following their 2024 compromise of the Dutch National Police.

Zimbra23 Jul · 14:49 UTC
Russian cyberespionage campaign targets Zimbra via JavaScript injectionhighperson_alertThreat Actor
person_alertThreat Actor

Russian cyberespionage campaign targets Zimbra via JavaScript injection

This campaign is attributed by Unit 42 to Russian cyberespionage interests. The actor's motivation centers on intelligence gathering through compromise of email infrastructure.

Zimbra23 Jul · 12:10 UTC
Chaos Ransomware Group Deploys msaRAT Rust Implant via Headless Browsershighperson_alertThreat Actor
person_alertThreat Actor

Chaos Ransomware Group Deploys msaRAT Rust Implant via Headless Browsers

Chaos is a ransomware group that operates through spam floods, vishing campaigns, Quick Assist abuse, and RMM tools for initial access and persistence. The group deploys custom tooling including the msaRAT Rust-based implant as a pre-ransomware stage…

Microsoft23 Jul · 11:11 UTC
JadeProx Deploys TriBack Loader Against Asian, Latin American Targetshighperson_alertThreat Actor
person_alertThreat Actor

JadeProx Deploys TriBack Loader Against Asian, Latin American Targets

JadeProx is a China-nexus threat actor tracked by Group-IB, discovered through an exposed Alibaba Cloud server in Singapore in mid-April 2026. The actor targets government, healthcare, and education organizations across Asia and Latin America.

Alibaba Cloud23 Jul · 10:20 UTC
Laundry Bear: Russian APT deploys zero-click phishing via Zimbra exploithighperson_alertThreat Actor
person_alertThreat Actor

Laundry Bear: Russian APT deploys zero-click phishing via Zimbra exploit

Laundry Bear is an advanced persistent threat (APT) group attributed to Russian state support, specializing in covert email data acquisition. The group conducts espionage operations targeting Western organizations and NATO members.

NCSC UK23 Jul · 10:00 UTC
GitHub Actions Abused to Scan and Exploit cPanel/WHM Servershighperson_alertThreat Actor
person_alertThreat Actor

GitHub Actions Abused to Scan and Exploit cPanel/WHM Servers

The threat actor behind this campaign remains unattributed. The operation demonstrates sophisticated understanding of GitHub Actions infrastructure and supply chain attack vectors.

GitHub23 Jul · 09:28 UTC
Chaos ransomware gang deploys msaRAT backdoor via browser hijackinghighperson_alertThreat Actor
person_alertThreat Actor

Chaos ransomware gang deploys msaRAT backdoor via browser hijacking

Chaos is a ransomware gang that emerged in early 2025, distinct from the earlier same-named ransomware family active since 2021. The group has been linked to Iranian state-backed threat actor MuddyWater, who reportedly leveraged Chaos ransomware to d…

Google23 Jul · 07:59 UTC