Threat Feed
Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.
Filtered Reports
30 / 36 results
highperson_alertThreat ActorGoSerpent Malware Targets Southeast Asian Government and Diplomacy
GoSerpent is a previously undocumented malware family discovered by Kaspersky researchers in late 2025. The malware is designed for long-term persistent access and intelligence gathering operations.
highperson_alertThreat ActorChina-Linked Cluster Exploits Roundcube at Universities
This China-linked threat cluster targets academic institutions in North America, focusing on credential theft and persistent access through exploitation of vulnerable Roundcube webmail servers.
highperson_alertThreat ActorUAT-7810 Expands ORB Network with LONGLEASH Malware on Edge Devices
UAT-7810 is a China-linked advanced persistent threat (APT) actor focused on compromising internet-facing networking and infrastructure devices to build and maintain an Operational Relay Box (ORB) network designated LapDogs.
highperson_alertThreat ActorUAT-7810 Deploys LONGLEASH Malware Against Network Infrastructure
UAT-7810 is a Chinese-linked threat actor focused on compromising internet-facing networking devices to expand their Operational Relay Box (ORB) network infrastructure.
highperson_alertThreat ActorChina-Aligned Cluster Exploits Roundcube Flaws at Universities
This activity cluster is attributed to China-aligned threat actors targeting academic institutions in North America. The group demonstrates a clear strategic interest in research and development sectors, specifically physics and engineering departmen…
highperson_alertThreat ActorIran-linked MOIS group deploys Cavern C2 framework against Israel
An Iranian threat actor affiliated with Iran's Ministry of Intelligence and Security (MOIS), tracked by Check Point Research. The group operates in support of Iranian state intelligence objectives, focusing on espionage operations against adversary n…
highperson_alertThreat ActorNSO Group's Pegasus Targets EU Parliament Member Investigating Spyware
NSO Group is an Israeli-based commercial surveillance vendor that develops and sells the Pegasus spyware to government clients. The company markets its tools as lawful intercept solutions for counterterrorism and law enforcement, but has faced repeat…
highperson_alertThreat ActorToddyCat Deploys Umbrij Malware to Hijack Gmail via OAuth Abuse
ToddyCat (G1022) is an advanced persistent threat group that has demonstrated sophisticated capabilities in targeting corporate and enterprise environments.
highperson_alertThreat ActorScattered Spider Member Extradited to U.S. from Estonia
Scattered Spider (G1015), also tracked as Roasted 0ktapus, Octo Tempest, Storm-0875, and UNC3944, is a financially motivated threat actor collective known for sophisticated social engineering and identity-based attacks.
highperson_alertThreat ActorScattered Spider Member Extradited to U.S. on Federal Hacking Charges
Scattered Spider (also tracked as Roasted 0ktapus, Octo Tempest, Storm-0875, and UNC3944) is a financially motivated threat actor group known for sophisticated social engineering and identity-based attacks.
highperson_alertThreat ActorMustang Panda Targets Indian Government and Hydropower Infrastructure
Mustang Panda (also tracked as TA416, RedDelta, BRONZE PRESIDENT, and STATELY TAURUS) is a China-aligned advanced persistent threat group focused on espionage operations.
highperson_alertThreat ActorGamaredon APT Expands Ukraine Operations with 35 Spear-Phishing Campaigns
Gamaredon (also tracked as Armageddon, Shuckworm, Primitive Bear, and UAC-0010) is a Russian state-sponsored APT group attributed by multiple vendors to Russia's Federal Security Service (FSB).
highperson_alertThreat ActorRussian Intelligence Escalates Signal Phishing for Backup Recovery Keys
Russian intelligence actors, as identified by FBI and CISA joint reporting, are conducting targeted phishing operations against Signal messaging platform users.
highperson_alertThreat ActorCL-STA-1062 deploys TinyRCT backdoor against Southeast Asian government
CL-STA-1062 is a Chinese-speaking APT actor conducting targeted cyber espionage operations against government entities and critical infrastructure in Southeast Asia.
highperson_alertThreat ActorCL-STA-1062 targets Southeast Asian government with TinyRCT backdoor
CL-STA-1062 is a threat actor conducting cyber espionage operations against government entities and critical infrastructure in Southeast Asia. The actor employs a hybrid toolkit centered around a custom backdoor known as TinyRCT.
highperson_alertThreat ActorChina-Linked Actor Deploys Windows Variants of SprySOCKS Backdoor
A China-linked threat actor has expanded the SprySOCKS malware family beyond its original Linux platform. The actor demonstrates advanced development capabilities through the creation of two distinct Windows variants (WIN_DRV and WIN_PLUS) featuring…
highperson_alertThreat ActorScarCruft Deploys NarwhalRAT via Microsoft Account Phishing Lures
ScarCruft (also tracked as APT37, InkySquid, Reaper, and Group123) is a North Korean state-sponsored advanced persistent threat group. The actor is attributed to North Korea's intelligence apparatus and conducts espionage operations aligned with Pyon…
criticalperson_alertThreat ActorChina-linked espionage group targets North American research networks
A China-linked espionage group conducted a sustained intrusion campaign lasting over one year against North American institutions. The actor's motivation appears to be intelligence collection focused on medical research, academic intellectual propert…
criticalperson_alertThreat ActorChinese state-sponsored hackers maintain 10-year persistent access
Chinese state-sponsored hackers, likely an advanced persistent threat (APT) group operating on behalf of the People's Republic of China. The actor demonstrated exceptional operational security and patience, maintaining covert access to a target organ…
criticalperson_alertThreat ActorVelvet Ant: China-linked APT backdoors Linux auth for decade-long access
Velvet Ant (G1047) is a China-linked advanced persistent threat actor characterized by exceptional operational security and long-term persistence capabilities.
highperson_alertThreat ActorOceanLotus Targets Vietnamese Infrastructure with SPECTRALVIPER Backdoor
OceanLotus (also tracked as APT32, SeaLotus, APT-C-00, and Canvas Cyclone) is a Vietnam-aligned advanced persistent threat group attributed by multiple vendors to conducting cyber espionage operations.
highperson_alertThreat ActorChina-Nexus Actors Expand JDY Botnet to 1,500+ IoT/SOHO Devices
China-nexus state-sponsored threat actors operating the JDY botnet infrastructure. The actors leverage compromised small office/home office (SOHO) routers and IoT devices to build a distributed scanning platform for cyber reconnaissance operations.
highperson_alertThreat ActorVolt Typhoon Expands JDY Botnet Operations Against U.S. Military
Volt Typhoon (also tracked as BRONZE SILHOUETTE, Vanguard Panda, DEV-0391, and UNC3236) is a Chinese state-sponsored APT group attributed to conducting cyber espionage operations targeting critical infrastructure.
highperson_alertThreat ActorMeta blocks NSO Group spear-phishing targeting WhatsApp users
NSO Group is an Israeli commercial surveillance vendor that develops and sells offensive cyber capabilities, primarily the Pegasus spyware platform, to government clients.
highperson_alertThreat ActorVerdantBamboo deploys BSD BRICKSTORM variant with Linux malware
VerdantBamboo is a China-nexus cyber espionage group attributed by Volexity, with operational overlap with the threat cluster known as Clay Typhoon. The actor focuses on intelligence collection operations and has demonstrated cross-platform capabilit…
highperson_alertThreat ActorUNC5221 Deploys Brickstorm, Plenet, AgentPSD in M365 Espionage Campaign
UNC5221 is a Chinese APT group attributed to conducting cyber espionage operations. The group demonstrates advanced capabilities in targeting cloud environments, specifically Microsoft 365 infrastructure.
highperson_alertThreat ActorOP-512 Targets IIS Servers with Custom Web Shell Framework
OP-512 is a previously unreported threat cluster assessed by ReliaQuest with moderate to high confidence to be linked to China. The actor demonstrates espionage-focused objectives, leveraging custom web shell frameworks to compromise Microsoft Intern…
highperson_alertThreat ActorGREYVIBE: Russian-linked APT targeting Ukraine since August 2025
GREYVIBE is a previously undocumented threat actor attributed by WithSecure as Russian-linked, assessed to operate in support of Kremlin state interests. The group is characterized as Russian-speaking and operates within Russian time zones.
highperson_alertThreat ActorKimsuky Targets South Korean Military and Corporate Sectors
Kimsuky (also tracked as Velvet Chollima, Black Banshee, Emerald Sleet, and THALLIUM) is a North Korean state-sponsored advanced persistent threat group.
highperson_alertThreat ActorMuddyWater Q1 2026 espionage campaign hits nine countries via DLL side-loading
MuddyWater (also tracked as Earth Vetala, MERCURY, Static Kitten, and Seedworm) is an Iranian state-sponsored APT group attributed to Iran's Ministry of Intelligence and Security (MOIS).