Threat Feed
Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.
Filtered Reports
30 / 291 results
highperson_alertThreat ActorEvil Corp SocGholish botnet dismantled: 15,000 sites, 100+ servers
Evil Corp (also tracked as Indrik Spider, Manatee Tempest, DEV-0243, UNC2165) is a financially motivated cybercrime group linked to Russia. The group has operated since at least 2014 and is known for deploying banking trojans and ransomware variants…
highperson_alertThreat ActorJunior Hacker targets French automotive sector with credential theft
Junior Hacker is a French-speaking threat actor targeting small businesses in the French automotive sector. The actor demonstrates financially motivated objectives, focusing on credential theft for banking and email access.
highperson_alertThreat ActorShinyHunters Claims Responsibility for Kodak Data Breach
ShinyHunters is a financially motivated cybercrime group known for conducting data theft and extortion operations against organizations across multiple sectors.
highperson_alertThreat ActorGhostTree Abuses NTFS Junctions to Evade Microsoft Defender Scans
GhostTree is a threat actor that has developed an evasion technique exploiting recursive NTFS junctions to bypass antivirus scanning. The actor targets the information technology sector and leverages inherent Windows file system features to create in…
highperson_alertThreat ActorDragonForce Ransomware Gang Deploys Backdoor.Turn via Teams Infrastructure
DragonForce is a ransomware gang that has developed custom tooling to support their extortion operations. The group demonstrates advanced capabilities in developing bespoke malware and leveraging legitimate cloud infrastructure for command-and-contro…
highperson_alertThreat ActorChina-Linked Actor Deploys Windows Variants of SprySOCKS Backdoor
A China-linked threat actor has expanded the SprySOCKS malware family beyond its original Linux platform. The actor demonstrates advanced development capabilities through the creation of two distinct Windows variants (WIN_DRV and WIN_PLUS) featuring…
highperson_alertThreat ActorScarCruft Deploys NarwhalRAT via Microsoft Account Phishing Lures
ScarCruft (also tracked as APT37, InkySquid, Reaper, and Group123) is a North Korean state-sponsored advanced persistent threat group. The actor is attributed to North Korea's intelligence apparatus and conducts espionage operations aligned with Pyon…
criticalperson_alertThreat ActorChina-linked espionage group targets North American research networks
A China-linked espionage group conducted a sustained intrusion campaign lasting over one year against North American institutions. The actor's motivation appears to be intelligence collection focused on medical research, academic intellectual propert…
highperson_alertThreat ActorContagious Interview targets developers via recruitment-themed phishing
Contagious Interview (also tracked as DeceptiveDevelopment, Gwisin Gang, Tenacious Pungsan, and DEV#POPPER) is a North Korean-aligned threat actor cluster that specializes in social engineering attacks against software developers and technology secto…
highperson_alertThreat ActorShinyHunters Claims Council of Europe Data Breach
ShinyHunters is a financially motivated cybercrime group known for large-scale data theft and extortion operations. The group has been active since at least 2020, targeting organizations across multiple sectors to steal sensitive databases and person…
highperson_alertThreat ActorChina-Linked Espionage Group Deploys InfiniteRed via REDCap Servers
This activity is attributed to a China-linked espionage group targeting healthcare and medical research sectors. The actor's motivation appears to be intelligence collection focused on sensitive medical research data, consistent with strategic intere…
highperson_alertThreat ActorShinyHunters Breaches 137K+ School Staff via Salesforce Attack
ShinyHunters is a financially motivated cybercrime actor specializing in large-scale data theft and extortion operations. The group has established a reputation for targeting cloud-based platforms and third-party service providers to compromise downs…
highperson_alertThreat ActorFBI disrupts Outsider Enterprise Chinese phishing-as-a-service platform
Outsider Enterprise is a Chinese phishing-as-a-service (PhaaS) operation disrupted by the FBI in coordination with Google and Black Lotus Labs. The actor operated thousands of phishing websites designed to harvest credit card data and passwords from…
criticalperson_alertThreat ActorChinese state-sponsored hackers maintain 10-year persistent access
Chinese state-sponsored hackers, likely an advanced persistent threat (APT) group operating on behalf of the People's Republic of China. The actor demonstrated exceptional operational security and patience, maintaining covert access to a target organ…
highperson_alertThreat ActorChinese Cybercrime Network Weaponizes Google Gemini AI for SMS Phishing
A Chinese cybercrime network operating a phishing-as-a-service (PhaaS) platform called Outsider. The group weaponizes Google's Gemini AI to craft and conduct SMS-based phishing attacks (smishing) targeting American victims.
criticalperson_alertThreat ActorVelvet Ant: China-linked APT backdoors Linux auth for decade-long access
Velvet Ant (G1047) is a China-linked advanced persistent threat actor characterized by exceptional operational security and long-term persistence capabilities.
highperson_alertThreat ActorConti Operator Pleads Guilty After Extradition to United States
Conti is a prolific ransomware-as-a-service (RaaS) operation that emerged in 2020 and became one of the most active and financially successful cybercrime groups before its infrastructure was leaked and operations fragmented in 2022.
highperson_alertThreat ActorUNC1151/Ghostwriter Targets Polish Gmail Accounts in Phishing Campaign
UNC1151, also known as Ghostwriter, is a threat actor group attributed by FireEye/Mandiant that has conducted sustained information operations and cyber espionage activities.
highperson_alertThreat ActorINTERPOL arrests Guedz, admin of Sniper Dz phishing-as-a-service platform
Guedz is identified as the primary administrator of Sniper Dz, a phishing-as-a-service (PhaaS) platform that operated for approximately a decade across the Middle East and North Africa (MENA) region.
highperson_alertThreat ActorEuropol Disrupts AudiA6 Cryptocurrency Laundering Service
AudiA6 was a cryptocurrency laundering service utilized by ransomware gangs and cybercriminal networks to obfuscate and legitimize illicit proceeds. The service facilitated the conversion and movement of cryptocurrency obtained through ransomware ope…
highperson_alertThreat ActorThe Gentlemen ransomware group claims 478 victims via multi-RaaS model
The Gentlemen is a financially motivated ransomware threat group that has claimed 478 victims through a hybrid operational model. Initially operating as an affiliate leveraging multiple ransomware-as-a-service (RaaS) platforms—including LockBit, Qili…
highperson_alertThreat ActorLaw Enforcement Dismantles AudiA6 Cryptocurrency Laundering Service
AudiA6 was a cryptocurrency laundering service that facilitated money laundering operations for ransomware actors and other cybercriminals. The service allegedly processed over $380 million in illicit proceeds before being dismantled by law enforceme…
highperson_alertThreat ActorOceanLotus Targets Vietnamese Infrastructure with SPECTRALVIPER Backdoor
OceanLotus (also tracked as APT32, SeaLotus, APT-C-00, and Canvas Cyclone) is a Vietnam-aligned advanced persistent threat group attributed by multiple vendors to conducting cyber espionage operations.
highperson_alertThreat ActorShinyHunters Targets Oracle PeopleSoft Servers in Mass Data Theft
ShinyHunters is a financially motivated cybercrime group known for large-scale data theft and extortion operations. The group has gained notoriety for breaching numerous organizations and exfiltrating sensitive data, which is then used for extortion…
highperson_alertThreat ActorChina-Nexus Actors Expand JDY Botnet to 1,500+ IoT/SOHO Devices
China-nexus state-sponsored threat actors operating the JDY botnet infrastructure. The actors leverage compromised small office/home office (SOHO) routers and IoT devices to build a distributed scanning platform for cyber reconnaissance operations.
highperson_alertThreat ActorVolt Typhoon Expands JDY Botnet Operations Against U.S. Military
Volt Typhoon (also tracked as BRONZE SILHOUETTE, Vanguard Panda, DEV-0391, and UNC3236) is a Chinese state-sponsored APT group attributed to conducting cyber espionage operations targeting critical infrastructure.
highperson_alertThreat ActorThe Gentlemen Ransomware: Aggressive Affiliate Model Drives Rapid Growth
The Gentlemen is a ransomware-as-a-service (RaaS) operation that has rapidly ascended to become the second most active ransomware group by victim count.
highperson_alertThreat ActorNSO Group linked to WhatsApp spear-phishing campaigns
NSO Group is an Israeli cyber intelligence firm that develops and sells commercial surveillance technology, primarily the Pegasus spyware platform. The company markets its tools to government clients for lawful interception and intelligence gathering…
highperson_alertThreat ActorMeta blocks NSO Group spear-phishing targeting WhatsApp users
NSO Group is an Israeli commercial surveillance vendor that develops and sells offensive cyber capabilities, primarily the Pegasus spyware platform, to government clients.
highperson_alertThreat ActorVerdantBamboo deploys BSD BRICKSTORM variant with Linux malware
VerdantBamboo is a China-nexus cyber espionage group attributed by Volexity, with operational overlap with the threat cluster known as Clay Typhoon. The actor focuses on intelligence collection operations and has demonstrated cross-platform capabilit…