Curated Cyber Threat Intelligence

Threat Feed

Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.

scheduleUpdated 2026-07-20 · 02:03 UTC
articleTotal: 593 reports

Filtered Reports

30 / 36 results
Active filter:tag: #apt✕ clear
GoSerpent Malware Targets Southeast Asian Government and Diplomacyhighperson_alertThreat Actor
person_alertThreat Actor

GoSerpent Malware Targets Southeast Asian Government and Diplomacy

GoSerpent is a previously undocumented malware family discovered by Kaspersky researchers in late 2025. The malware is designed for long-term persistent access and intelligence gathering operations.

Kaspersky06:46 UTC
China-Linked Cluster Exploits Roundcube at Universitieshighperson_alertThreat Actor
person_alertThreat Actor

China-Linked Cluster Exploits Roundcube at Universities

This China-linked threat cluster targets academic institutions in North America, focusing on credential theft and persistent access through exploitation of vulnerable Roundcube webmail servers.

Roundcube16:56 UTC
UAT-7810 Expands ORB Network with LONGLEASH Malware on Edge Deviceshighperson_alertThreat Actor
person_alertThreat Actor

UAT-7810 Expands ORB Network with LONGLEASH Malware on Edge Devices

UAT-7810 is a China-linked advanced persistent threat (APT) actor focused on compromising internet-facing networking and infrastructure devices to build and maintain an Operational Relay Box (ORB) network designated LapDogs.

The Hacker News07:04 UTC
UAT-7810 Deploys LONGLEASH Malware Against Network Infrastructurehighperson_alertThreat Actor
person_alertThreat Actor

UAT-7810 Deploys LONGLEASH Malware Against Network Infrastructure

UAT-7810 is a Chinese-linked threat actor focused on compromising internet-facing networking devices to expand their Operational Relay Box (ORB) network infrastructure.

Ruckus16:52 UTC
China-Aligned Cluster Exploits Roundcube Flaws at Universitieshighperson_alertThreat Actor
person_alertThreat Actor

China-Aligned Cluster Exploits Roundcube Flaws at Universities

This activity cluster is attributed to China-aligned threat actors targeting academic institutions in North America. The group demonstrates a clear strategic interest in research and development sectors, specifically physics and engineering departmen…

CVE-2024-4200907:10 UTC
Iran-linked MOIS group deploys Cavern C2 framework against Israelhighperson_alertThreat Actor
person_alertThreat Actor

Iran-linked MOIS group deploys Cavern C2 framework against Israel

An Iranian threat actor affiliated with Iran's Ministry of Intelligence and Security (MOIS), tracked by Check Point Research. The group operates in support of Iranian state intelligence objectives, focusing on espionage operations against adversary n…

The Hacker News16:34 UTC
NSO Group's Pegasus Targets EU Parliament Member Investigating Spywarehighperson_alertThreat Actor
person_alertThreat Actor

NSO Group's Pegasus Targets EU Parliament Member Investigating Spyware

NSO Group is an Israeli-based commercial surveillance vendor that develops and sells the Pegasus spyware to government clients. The company markets its tools as lawful intercept solutions for counterterrorism and law enforcement, but has faced repeat…

The Hacker News09:05 UTC
ToddyCat Deploys Umbrij Malware to Hijack Gmail via OAuth Abusehighperson_alertThreat Actor
person_alertThreat Actor

ToddyCat Deploys Umbrij Malware to Hijack Gmail via OAuth Abuse

ToddyCat (G1022) is an advanced persistent threat group that has demonstrated sophisticated capabilities in targeting corporate and enterprise environments.

Google11:04 UTC
Scattered Spider Member Extradited to U.S. from Estoniahighperson_alertThreat Actor
person_alertThreat Actor

Scattered Spider Member Extradited to U.S. from Estonia

Scattered Spider (G1015), also tracked as Roasted 0ktapus, Octo Tempest, Storm-0875, and UNC3944, is a financially motivated threat actor collective known for sophisticated social engineering and identity-based attacks.

BleepingComputer06:58 UTC
Scattered Spider Member Extradited to U.S. on Federal Hacking Chargeshighperson_alertThreat Actor
person_alertThreat Actor

Scattered Spider Member Extradited to U.S. on Federal Hacking Charges

Scattered Spider (also tracked as Roasted 0ktapus, Octo Tempest, Storm-0875, and UNC3944) is a financially motivated threat actor group known for sophisticated social engineering and identity-based attacks.

The Hacker News17:28 UTC
Mustang Panda Targets Indian Government and Hydropower Infrastructurehighperson_alertThreat Actor
person_alertThreat Actor

Mustang Panda Targets Indian Government and Hydropower Infrastructure

Mustang Panda (also tracked as TA416, RedDelta, BRONZE PRESIDENT, and STATELY TAURUS) is a China-aligned advanced persistent threat group focused on espionage operations.

Zoho13:03 UTC
Gamaredon APT Expands Ukraine Operations with 35 Spear-Phishing Campaignshighperson_alertThreat Actor
person_alertThreat Actor

Gamaredon APT Expands Ukraine Operations with 35 Spear-Phishing Campaigns

Gamaredon (also tracked as Armageddon, Shuckworm, Primitive Bear, and UAC-0010) is a Russian state-sponsored APT group attributed by multiple vendors to Russia's Federal Security Service (FSB).

ESET09:40 UTC
Russian Intelligence Escalates Signal Phishing for Backup Recovery Keyshighperson_alertThreat Actor
person_alertThreat Actor

Russian Intelligence Escalates Signal Phishing for Backup Recovery Keys

Russian intelligence actors, as identified by FBI and CISA joint reporting, are conducting targeted phishing operations against Signal messaging platform users.

Signal17:38 UTC
CL-STA-1062 deploys TinyRCT backdoor against Southeast Asian governmenthighperson_alertThreat Actor
person_alertThreat Actor

CL-STA-1062 deploys TinyRCT backdoor against Southeast Asian government

CL-STA-1062 is a Chinese-speaking APT actor conducting targeted cyber espionage operations against government entities and critical infrastructure in Southeast Asia.

Palo Alto Networks14:21 UTC
CL-STA-1062 targets Southeast Asian government with TinyRCT backdoorhighperson_alertThreat Actor
person_alertThreat Actor

CL-STA-1062 targets Southeast Asian government with TinyRCT backdoor

CL-STA-1062 is a threat actor conducting cyber espionage operations against government entities and critical infrastructure in Southeast Asia. The actor employs a hybrid toolkit centered around a custom backdoor known as TinyRCT.

Unit 42 (Palo Alto)20:00 UTC
China-Linked Actor Deploys Windows Variants of SprySOCKS Backdoorhighperson_alertThreat Actor
person_alertThreat Actor

China-Linked Actor Deploys Windows Variants of SprySOCKS Backdoor

A China-linked threat actor has expanded the SprySOCKS malware family beyond its original Linux platform. The actor demonstrates advanced development capabilities through the creation of two distinct Windows variants (WIN_DRV and WIN_PLUS) featuring…

Windows07:44 UTC
ScarCruft Deploys NarwhalRAT via Microsoft Account Phishing Lureshighperson_alertThreat Actor
person_alertThreat Actor

ScarCruft Deploys NarwhalRAT via Microsoft Account Phishing Lures

ScarCruft (also tracked as APT37, InkySquid, Reaper, and Group123) is a North Korean state-sponsored advanced persistent threat group. The actor is attributed to North Korea's intelligence apparatus and conducts espionage operations aligned with Pyon…

Microsoft06:14 UTC
China-linked espionage group targets North American research networkscriticalperson_alertThreat Actor
person_alertThreat Actor

China-linked espionage group targets North American research networks

A China-linked espionage group conducted a sustained intrusion campaign lasting over one year against North American institutions. The actor's motivation appears to be intelligence collection focused on medical research, academic intellectual propert…

Google Workspace17:44 UTC
Chinese state-sponsored hackers maintain 10-year persistent accesscriticalperson_alertThreat Actor
person_alertThreat Actor

Chinese state-sponsored hackers maintain 10-year persistent access

Chinese state-sponsored hackers, likely an advanced persistent threat (APT) group operating on behalf of the People's Republic of China. The actor demonstrated exceptional operational security and patience, maintaining covert access to a target organ…

BleepingComputer12:06 UTC
Velvet Ant: China-linked APT backdoors Linux auth for decade-long accesscriticalperson_alertThreat Actor
person_alertThreat Actor

Velvet Ant: China-linked APT backdoors Linux auth for decade-long access

Velvet Ant (G1047) is a China-linked advanced persistent threat actor characterized by exceptional operational security and long-term persistence capabilities.

Linux16:17 UTC
OceanLotus Targets Vietnamese Infrastructure with SPECTRALVIPER Backdoorhighperson_alertThreat Actor
person_alertThreat Actor

OceanLotus Targets Vietnamese Infrastructure with SPECTRALVIPER Backdoor

OceanLotus (also tracked as APT32, SeaLotus, APT-C-00, and Canvas Cyclone) is a Vietnam-aligned advanced persistent threat group attributed by multiple vendors to conducting cyber espionage operations.

The Hacker News07:45 UTC
China-Nexus Actors Expand JDY Botnet to 1,500+ IoT/SOHO Deviceshighperson_alertThreat Actor
person_alertThreat Actor

China-Nexus Actors Expand JDY Botnet to 1,500+ IoT/SOHO Devices

China-nexus state-sponsored threat actors operating the JDY botnet infrastructure. The actors leverage compromised small office/home office (SOHO) routers and IoT devices to build a distributed scanning platform for cyber reconnaissance operations.

The Hacker News14:08 UTC
Volt Typhoon Expands JDY Botnet Operations Against U.S. Militaryhighperson_alertThreat Actor
person_alertThreat Actor

Volt Typhoon Expands JDY Botnet Operations Against U.S. Military

Volt Typhoon (also tracked as BRONZE SILHOUETTE, Vanguard Panda, DEV-0391, and UNC3236) is a Chinese state-sponsored APT group attributed to conducting cyber espionage operations targeting critical infrastructure.

BleepingComputer13:00 UTC
Meta blocks NSO Group spear-phishing targeting WhatsApp usershighperson_alertThreat Actor
person_alertThreat Actor

Meta blocks NSO Group spear-phishing targeting WhatsApp users

NSO Group is an Israeli commercial surveillance vendor that develops and sells offensive cyber capabilities, primarily the Pegasus spyware platform, to government clients.

Meta15:08 UTC
VerdantBamboo deploys BSD BRICKSTORM variant with Linux malwarehighperson_alertThreat Actor
person_alertThreat Actor

VerdantBamboo deploys BSD BRICKSTORM variant with Linux malware

VerdantBamboo is a China-nexus cyber espionage group attributed by Volexity, with operational overlap with the threat cluster known as Clay Typhoon. The actor focuses on intelligence collection operations and has demonstrated cross-platform capabilit…

The Hacker News08:27 UTC
UNC5221 Deploys Brickstorm, Plenet, AgentPSD in M365 Espionage Campaignhighperson_alertThreat Actor
person_alertThreat Actor

UNC5221 Deploys Brickstorm, Plenet, AgentPSD in M365 Espionage Campaign

UNC5221 is a Chinese APT group attributed to conducting cyber espionage operations. The group demonstrates advanced capabilities in targeting cloud environments, specifically Microsoft 365 infrastructure.

Microsoft16:09 UTC
OP-512 Targets IIS Servers with Custom Web Shell Frameworkhighperson_alertThreat Actor
person_alertThreat Actor

OP-512 Targets IIS Servers with Custom Web Shell Framework

OP-512 is a previously unreported threat cluster assessed by ReliaQuest with moderate to high confidence to be linked to China. The actor demonstrates espionage-focused objectives, leveraging custom web shell frameworks to compromise Microsoft Intern…

Microsoft10:33 UTC
GREYVIBE: Russian-linked APT targeting Ukraine since August 2025highperson_alertThreat Actor
person_alertThreat Actor

GREYVIBE: Russian-linked APT targeting Ukraine since August 2025

GREYVIBE is a previously undocumented threat actor attributed by WithSecure as Russian-linked, assessed to operate in support of Kremlin state interests. The group is characterized as Russian-speaking and operates within Russian time zones.

The Hacker News09:31 UTC
Kimsuky Targets South Korean Military and Corporate Sectorshighperson_alertThreat Actor
person_alertThreat Actor

Kimsuky Targets South Korean Military and Corporate Sectors

Kimsuky (also tracked as Velvet Chollima, Black Banshee, Emerald Sleet, and THALLIUM) is a North Korean state-sponsored advanced persistent threat group.

The Hacker News03:57 UTC
MuddyWater Q1 2026 espionage campaign hits nine countries via DLL side-loadinghighperson_alertThreat Actor
person_alertThreat Actor

MuddyWater Q1 2026 espionage campaign hits nine countries via DLL side-loading

MuddyWater (also tracked as Earth Vetala, MERCURY, Static Kitten, and Seedworm) is an Iranian state-sponsored APT group attributed to Iran's Ministry of Intelligence and Security (MOIS).

The Hacker News13:48 UTC