Curated Cyber Threat Intelligence

Threat Feed

Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.

scheduleUpdated 2026-09-04 · 02:17 UTC
articleTotal: 1172 reports

Filtered Reports

30 / 67 results
Active filter:tag: #apt✕ clear
UAC-0099 Deploys GuardBreaker to Sabotage AI-Assisted Malware Analysishighperson_alertThreat Actor
person_alertThreat Actor

UAC-0099 Deploys GuardBreaker to Sabotage AI-Assisted Malware Analysis

UAC-0099 is a Russia-aligned threat actor with a documented history of targeting Ukraine's transportation and energy sectors. The group demonstrates tactical innovation by adapting emerging anti-analysis techniques, specifically targeting AI-assisted…

The Hacker News1 Sep · 06:26 UTC
Fire Ant compromises Cisco routers for network surveillancehighperson_alertThreat Actor
person_alertThreat Actor

Fire Ant compromises Cisco routers for network surveillance

Fire Ant is a Chinese espionage-focused threat actor attributed by Sygnia, with operational overlap to UNC3886 (previously documented by Google). The group targets critical infrastructure and high-value networks through a "target behind the target" s…

Cisco31 Aug · 12:52 UTC
Fire Ant Expands Espionage to Cisco Routers and TACACS Servershighperson_alertThreat Actor
person_alertThreat Actor

Fire Ant Expands Espionage to Cisco Routers and TACACS Servers

Fire Ant is a China-linked cyber espionage actor that has conducted long-running campaigns targeting network infrastructure and virtualization platforms.

Cisco31 Aug · 07:04 UTC
Chinese QTFY Group Targeted U.S. Federal Agencies via IoT Botnethighperson_alertThreat Actor
person_alertThreat Actor

Chinese QTFY Group Targeted U.S. Federal Agencies via IoT Botnet

QTFY (also known as QT AND QTCYBER) is a Chinese state-sponsored threat actor active since 2018, operating on behalf of Nanjing Xinjiuwei Network Technology Co.

NASA31 Aug · 05:56 UTC
DoJ Disrupts QTFY Chinese State-Sponsored Infrastructure Targeting U.S.highperson_alertThreat Actor
person_alertThreat Actor

DoJ Disrupts QTFY Chinese State-Sponsored Infrastructure Targeting U.S.

QTFY is a Chinese state-sponsored threat actor employed by Nanjing Xinjiuwei Network Technology Company (南京鑫玖维网络科技有限公司), active since May 2018. The group functions as a digital quartermaster serving China's Ministry of State Security (MSS) and People…

U.S. critical infrastructure operators26 Aug · 14:42 UTC
Nimbus Manticore Expands Toolset With TWOSTROKE-Like Backdoorhighperson_alertThreat Actor
person_alertThreat Actor

Nimbus Manticore Expands Toolset With TWOSTROKE-Like Backdoor

Nimbus Manticore is an Iranian state-sponsored APT group affiliated with the Islamic Revolutionary Guard Corps (IRGC). Also tracked as GalaxyGato, Mirage Kitten, Screening Serpens, Smoke Sandstorm, Subtle Snail, and UNC1549, the group is assessed to…

The Hacker News26 Aug · 13:35 UTC
FBI disrupts QTFY quartermaster infrastructure for Chinese espionagehighperson_alertThreat Actor
person_alertThreat Actor

FBI disrupts QTFY quartermaster infrastructure for Chinese espionage

QTFY (also tracked as QT, QTCYBER) is a China-based threat actor operating as a technical "quartermaster" providing reconnaissance, proxy management, and operational routing capabilities for Chinese cyber espionage operations.

BleepingComputer26 Aug · 12:17 UTC
Operation QUICSILVER: China-nexus campaign targets Myanmar with QUICAgenthighperson_alertThreat Actor
person_alertThreat Actor

Operation QUICSILVER: China-nexus campaign targets Myanmar with QUICAgent

Operation QUICSILVER is attributed with moderate confidence to a China-nexus threat actor conducting cyber espionage operations against Myanmar. The actor demonstrates sophisticated tradecraft, leveraging social engineering lures themed around govern…

The Hacker News24 Aug · 09:51 UTC
UNC6293, UNC7005, UNC5976 Abuse OAuth and WhatsApp Linking for Espionagehighperson_alertThreat Actor
person_alertThreat Actor

UNC6293, UNC7005, UNC5976 Abuse OAuth and WhatsApp Linking for Espionage

UNC6293, UNC7005, and UNC5976 are three distinct suspected Russian cyber espionage threat clusters conducting persistent account compromise operations. UNC6293 is assessed to be a sub-cluster of Ice Relic (formerly APT29, also tracked as Cozy Bear an…

Google20 Aug · 17:59 UTC
AI-Generated Exploits Target Siemens S7 PLCs in U.S. Critical Infrastructurehighperson_alertThreat Actor
person_alertThreat Actor

AI-Generated Exploits Target Siemens S7 PLCs in U.S. Critical Infrastructure

This campaign involves unattributed threat actors leveraging artificial intelligence to generate exploitation scripts targeting industrial control systems.

Siemens20 Aug · 14:59 UTC
AI-Generated Scripts Target Siemens S7 PLCs in U.S. Critical Infrastructurehighperson_alertThreat Actor
person_alertThreat Actor

AI-Generated Scripts Target Siemens S7 PLCs in U.S. Critical Infrastructure

No specific threat actor or group has been attributed to this campaign. The advisory describes ongoing activity by unidentified threat actors targeting Siemens S7 Series programmable logic controllers in U.S. critical infrastructure.

Siemens19 Aug · 15:50 UTC
U.S. charges 17 Mabna Institute members for $3.4B IP theft campaignhighperson_alertThreat Actor
person_alertThreat Actor

U.S. charges 17 Mabna Institute members for $3.4B IP theft campaign

Mabna Institute is an Iranian hacking-for-hire organization linked to cyber operations conducted on behalf of Iran's Islamic Revolutionary Guard Corps (IRGC), other Iranian government bodies, universities, and private paying customers.

BleepingComputer19 Aug · 13:56 UTC
SilkParasite Targets Central Asian Governments with Five New RATshighperson_alertThreat Actor
person_alertThreat Actor

SilkParasite Targets Central Asian Governments with Five New RATs

SilkParasite is a previously unreported cyber espionage operation first discovered in late 2025, assessed with medium confidence to be a China-nexus threat cluster.

The Hacker News19 Aug · 11:12 UTC
TWINLOOT Implant Abuses Microsoft 365 Services for C2 and Lateral Movementhighperson_alertThreat Actor
person_alertThreat Actor

TWINLOOT Implant Abuses Microsoft 365 Services for C2 and Lateral Movement

No specific threat actor has been attributed to TWINLOOT operations. The malware was discovered by Ontinue's Cyber Defense Center during investigation of an ongoing campaign in July 2026.

Microsoft18 Aug · 10:38 UTC
Iranian Cavern C2 Framework Evolves with DNS and Google Apps Script Relayhighperson_alertThreat Actor
person_alertThreat Actor

Iranian Cavern C2 Framework Evolves with DNS and Google Apps Script Relay

Cavern (aka Cav3rn) is a command-and-control framework attributed to Iranian nation-state threat actors, specifically linked to Cavern Manticore, a hacking group affiliated with Iran's Ministry of Intelligence and Security (MOIS).

The Hacker News17 Aug · 15:41 UTC
China-Nexus APT Exploits VMware vCenter Flaws, Deploys Babuk Ransomwarecriticalperson_alertThreat Actor
person_alertThreat Actor

China-Nexus APT Exploits VMware vCenter Flaws, Deploys Babuk Ransomware

A suspected China-nexus advanced persistent threat actor, assessed with moderate confidence by QUIRSO to be Chinese-speaking and operating in the UTC+08:00 time zone.

CVE-2026-5931017 Aug · 05:36 UTC
Lazarus Exploits Windows Zero-Day in Operation Dream Job Campaigncriticalperson_alertThreat Actor
person_alertThreat Actor

Lazarus Exploits Windows Zero-Day in Operation Dream Job Campaign

Lazarus Group is a North Korean state-sponsored advanced persistent threat (APT) actor attributed to Pyongyang-backed cyber operations. The group conducts cyber espionage and financially motivated campaigns targeting organizations worldwide.

Microsoft12 Aug · 15:39 UTC
Lazarus Exploits Windows Zero-Day in Operation Dream Job Campaigncriticalperson_alertThreat Actor
person_alertThreat Actor

Lazarus Exploits Windows Zero-Day in Operation Dream Job Campaign

Lazarus is a North Korean state-sponsored advanced persistent threat (APT) group linked to the Reconnaissance General Bureau. The group is financially and strategically motivated, conducting espionage operations targeting defense and critical infrast…

CVE-2026-6882012 Aug · 13:38 UTC
North Korea IT Worker Infiltration Targets Crypto and Tech Firmshighperson_alertThreat Actor
person_alertThreat Actor

North Korea IT Worker Infiltration Targets Crypto and Tech Firms

North Korean IT worker operations, attributed by researchers to Famous Chollima (a CrowdStrike designation under the Lazarus umbrella), involve operatives seeking employment at Western technology and cryptocurrency companies under fraudulent identiti…

The Hacker News11 Aug · 09:35 UTC
Kimsuky Deploys Offline AI Stack for Enhanced Phishing and Malware Automationhighperson_alertThreat Actor
person_alertThreat Actor

Kimsuky Deploys Offline AI Stack for Enhanced Phishing and Malware Automation

Kimsuky (also tracked as Black Banshee, Velvet Chollima, Emerald Sleet, THALLIUM) is a North Korean state-sponsored APT group operating under the Reconnaissance General Bureau. Sanctioned by the U.S.

The Hacker News10 Aug · 11:19 UTC
December 2025 Poland Energy Sector Campaign via Private APNhighperson_alertThreat Actor
person_alertThreat Actor

December 2025 Poland Energy Sector Campaign via Private APN

No specific threat actor has been publicly attributed to this campaign. The December 2025 attacks targeted Poland's energy infrastructure with purely destructive intent, representing a coordinated operation against multiple facilities including wind…

CERT.PL (Poland)8 Aug · 15:00 UTC
Chinese-Speaking Actor Deploys OctLurk & SilkLurk in Central Asiahighperson_alertThreat Actor
person_alertThreat Actor

Chinese-Speaking Actor Deploys OctLurk & SilkLurk in Central Asia

A Chinese-speaking threat actor, not yet attributed to any known APT group, has been conducting targeted cyber espionage operations against government and strategic organizations in Central Asia and Syria since January 2025.

The Hacker News31 Jul · 16:52 UTC
Laundry Bear exploits Exchange OWA zero-day to deploy OWAReaper backdoorcriticalperson_alertThreat Actor
person_alertThreat Actor

Laundry Bear exploits Exchange OWA zero-day to deploy OWAReaper backdoor

Laundry Bear (also tracked as Void Blizzard, TA488 by Proofpoint) is a Russian state-sponsored threat actor focused on long-term email intelligence collection.

Microsoft29 Jul · 21:44 UTC
Nimbus Manticore Deploys NightLedger Backdoor in Middle East Campaignhighperson_alertThreat Actor
person_alertThreat Actor

Nimbus Manticore Deploys NightLedger Backdoor in Middle East Campaign

Nimbus Manticore (also tracked as GalaxyGato, Mirage Kitten, Smoke Sandstorm, Subtle Snail, and UNC1549) is an Iranian state-backed advanced persistent threat group conducting cyber espionage operations.

The Hacker News28 Jul · 09:55 UTC
Hermes AI Agent Used for Post-Exploitation at Thai Finance Ministryhighperson_alertThreat Actor
person_alertThreat Actor

Hermes AI Agent Used for Post-Exploitation at Thai Finance Ministry

The threat actor behind this intrusion remains unattributed. Hunt.io assesses with low-to-medium confidence that the operator is Chinese-speaking or fluent in Chinese, based on linguistic artifacts (password containing "Leishen," meaning thunder god)…

Hermes AI24 Jul · 08:15 UTC
Russian Espionage Group Exploited Zimbra Zero-Day for Email Theftcriticalperson_alertThreat Actor
person_alertThreat Actor

Russian Espionage Group Exploited Zimbra Zero-Day for Email Theft

A Russian state-sponsored espionage group conducted a sustained campaign exploiting a zero-day vulnerability in Zimbra's webmail client. The actor, tracked as TA488 by Proofpoint and CL-STA-1114 by Unit 42, operated undetected for at least five month…

Zimbra23 Jul · 16:36 UTC
Laundry Bear exploits Zimbra XSS zero-day for email thefthighperson_alertThreat Actor
person_alertThreat Actor

Laundry Bear exploits Zimbra XSS zero-day for email theft

Laundry Bear (also tracked as Void Blizzard by Microsoft) is a Russian state-sponsored APT group first publicly attributed by Dutch intelligence agencies in May 2025 following their 2024 compromise of the Dutch National Police.

Zimbra23 Jul · 14:49 UTC
JadeProx Deploys TriBack Loader Against Asian, Latin American Targetshighperson_alertThreat Actor
person_alertThreat Actor

JadeProx Deploys TriBack Loader Against Asian, Latin American Targets

JadeProx is a China-nexus threat actor tracked by Group-IB, discovered through an exposed Alibaba Cloud server in Singapore in mid-April 2026. The actor targets government, healthcare, and education organizations across Asia and Latin America.

Alibaba Cloud23 Jul · 10:20 UTC
Laundry Bear: Russian APT deploys zero-click phishing via Zimbra exploithighperson_alertThreat Actor
person_alertThreat Actor

Laundry Bear: Russian APT deploys zero-click phishing via Zimbra exploit

Laundry Bear is an advanced persistent threat (APT) group attributed to Russian state support, specializing in covert email data acquisition. The group conducts espionage operations targeting Western organizations and NATO members.

NCSC UK23 Jul · 10:00 UTC
Russian Intelligence Services Exploit Security Cameras for Military Surveillancehighperson_alertThreat Actor
person_alertThreat Actor

Russian Intelligence Services Exploit Security Cameras for Military Surveillance

Russian intelligence services are conducting a systematic cyber-espionage campaign targeting internet-connected security cameras across Europe and Ukraine.

The Hacker News20 Jul · 10:13 UTC