Threat Feed
Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.
Filtered Reports
30 / 67 results
highperson_alertThreat ActorUAC-0099 Deploys GuardBreaker to Sabotage AI-Assisted Malware Analysis
UAC-0099 is a Russia-aligned threat actor with a documented history of targeting Ukraine's transportation and energy sectors. The group demonstrates tactical innovation by adapting emerging anti-analysis techniques, specifically targeting AI-assisted…
highperson_alertThreat ActorFire Ant compromises Cisco routers for network surveillance
Fire Ant is a Chinese espionage-focused threat actor attributed by Sygnia, with operational overlap to UNC3886 (previously documented by Google). The group targets critical infrastructure and high-value networks through a "target behind the target" s…
highperson_alertThreat ActorFire Ant Expands Espionage to Cisco Routers and TACACS Servers
Fire Ant is a China-linked cyber espionage actor that has conducted long-running campaigns targeting network infrastructure and virtualization platforms.
highperson_alertThreat ActorChinese QTFY Group Targeted U.S. Federal Agencies via IoT Botnet
QTFY (also known as QT AND QTCYBER) is a Chinese state-sponsored threat actor active since 2018, operating on behalf of Nanjing Xinjiuwei Network Technology Co.
highperson_alertThreat ActorDoJ Disrupts QTFY Chinese State-Sponsored Infrastructure Targeting U.S.
QTFY is a Chinese state-sponsored threat actor employed by Nanjing Xinjiuwei Network Technology Company (南京鑫玖维网络科技有限公司), active since May 2018. The group functions as a digital quartermaster serving China's Ministry of State Security (MSS) and People…
highperson_alertThreat ActorNimbus Manticore Expands Toolset With TWOSTROKE-Like Backdoor
Nimbus Manticore is an Iranian state-sponsored APT group affiliated with the Islamic Revolutionary Guard Corps (IRGC). Also tracked as GalaxyGato, Mirage Kitten, Screening Serpens, Smoke Sandstorm, Subtle Snail, and UNC1549, the group is assessed to…
highperson_alertThreat ActorFBI disrupts QTFY quartermaster infrastructure for Chinese espionage
QTFY (also tracked as QT, QTCYBER) is a China-based threat actor operating as a technical "quartermaster" providing reconnaissance, proxy management, and operational routing capabilities for Chinese cyber espionage operations.
highperson_alertThreat ActorOperation QUICSILVER: China-nexus campaign targets Myanmar with QUICAgent
Operation QUICSILVER is attributed with moderate confidence to a China-nexus threat actor conducting cyber espionage operations against Myanmar. The actor demonstrates sophisticated tradecraft, leveraging social engineering lures themed around govern…
highperson_alertThreat ActorUNC6293, UNC7005, UNC5976 Abuse OAuth and WhatsApp Linking for Espionage
UNC6293, UNC7005, and UNC5976 are three distinct suspected Russian cyber espionage threat clusters conducting persistent account compromise operations. UNC6293 is assessed to be a sub-cluster of Ice Relic (formerly APT29, also tracked as Cozy Bear an…
highperson_alertThreat ActorAI-Generated Exploits Target Siemens S7 PLCs in U.S. Critical Infrastructure
This campaign involves unattributed threat actors leveraging artificial intelligence to generate exploitation scripts targeting industrial control systems.
highperson_alertThreat ActorAI-Generated Scripts Target Siemens S7 PLCs in U.S. Critical Infrastructure
No specific threat actor or group has been attributed to this campaign. The advisory describes ongoing activity by unidentified threat actors targeting Siemens S7 Series programmable logic controllers in U.S. critical infrastructure.
highperson_alertThreat ActorU.S. charges 17 Mabna Institute members for $3.4B IP theft campaign
Mabna Institute is an Iranian hacking-for-hire organization linked to cyber operations conducted on behalf of Iran's Islamic Revolutionary Guard Corps (IRGC), other Iranian government bodies, universities, and private paying customers.
highperson_alertThreat ActorSilkParasite Targets Central Asian Governments with Five New RATs
SilkParasite is a previously unreported cyber espionage operation first discovered in late 2025, assessed with medium confidence to be a China-nexus threat cluster.
highperson_alertThreat ActorTWINLOOT Implant Abuses Microsoft 365 Services for C2 and Lateral Movement
No specific threat actor has been attributed to TWINLOOT operations. The malware was discovered by Ontinue's Cyber Defense Center during investigation of an ongoing campaign in July 2026.
highperson_alertThreat ActorIranian Cavern C2 Framework Evolves with DNS and Google Apps Script Relay
Cavern (aka Cav3rn) is a command-and-control framework attributed to Iranian nation-state threat actors, specifically linked to Cavern Manticore, a hacking group affiliated with Iran's Ministry of Intelligence and Security (MOIS).
criticalperson_alertThreat ActorChina-Nexus APT Exploits VMware vCenter Flaws, Deploys Babuk Ransomware
A suspected China-nexus advanced persistent threat actor, assessed with moderate confidence by QUIRSO to be Chinese-speaking and operating in the UTC+08:00 time zone.
criticalperson_alertThreat ActorLazarus Exploits Windows Zero-Day in Operation Dream Job Campaign
Lazarus Group is a North Korean state-sponsored advanced persistent threat (APT) actor attributed to Pyongyang-backed cyber operations. The group conducts cyber espionage and financially motivated campaigns targeting organizations worldwide.
criticalperson_alertThreat ActorLazarus Exploits Windows Zero-Day in Operation Dream Job Campaign
Lazarus is a North Korean state-sponsored advanced persistent threat (APT) group linked to the Reconnaissance General Bureau. The group is financially and strategically motivated, conducting espionage operations targeting defense and critical infrast…
highperson_alertThreat ActorNorth Korea IT Worker Infiltration Targets Crypto and Tech Firms
North Korean IT worker operations, attributed by researchers to Famous Chollima (a CrowdStrike designation under the Lazarus umbrella), involve operatives seeking employment at Western technology and cryptocurrency companies under fraudulent identiti…
highperson_alertThreat ActorKimsuky Deploys Offline AI Stack for Enhanced Phishing and Malware Automation
Kimsuky (also tracked as Black Banshee, Velvet Chollima, Emerald Sleet, THALLIUM) is a North Korean state-sponsored APT group operating under the Reconnaissance General Bureau. Sanctioned by the U.S.
highperson_alertThreat ActorDecember 2025 Poland Energy Sector Campaign via Private APN
No specific threat actor has been publicly attributed to this campaign. The December 2025 attacks targeted Poland's energy infrastructure with purely destructive intent, representing a coordinated operation against multiple facilities including wind…
highperson_alertThreat ActorChinese-Speaking Actor Deploys OctLurk & SilkLurk in Central Asia
A Chinese-speaking threat actor, not yet attributed to any known APT group, has been conducting targeted cyber espionage operations against government and strategic organizations in Central Asia and Syria since January 2025.
criticalperson_alertThreat ActorLaundry Bear exploits Exchange OWA zero-day to deploy OWAReaper backdoor
Laundry Bear (also tracked as Void Blizzard, TA488 by Proofpoint) is a Russian state-sponsored threat actor focused on long-term email intelligence collection.
highperson_alertThreat ActorNimbus Manticore Deploys NightLedger Backdoor in Middle East Campaign
Nimbus Manticore (also tracked as GalaxyGato, Mirage Kitten, Smoke Sandstorm, Subtle Snail, and UNC1549) is an Iranian state-backed advanced persistent threat group conducting cyber espionage operations.
highperson_alertThreat ActorHermes AI Agent Used for Post-Exploitation at Thai Finance Ministry
The threat actor behind this intrusion remains unattributed. Hunt.io assesses with low-to-medium confidence that the operator is Chinese-speaking or fluent in Chinese, based on linguistic artifacts (password containing "Leishen," meaning thunder god)…
criticalperson_alertThreat ActorRussian Espionage Group Exploited Zimbra Zero-Day for Email Theft
A Russian state-sponsored espionage group conducted a sustained campaign exploiting a zero-day vulnerability in Zimbra's webmail client. The actor, tracked as TA488 by Proofpoint and CL-STA-1114 by Unit 42, operated undetected for at least five month…
highperson_alertThreat ActorLaundry Bear exploits Zimbra XSS zero-day for email theft
Laundry Bear (also tracked as Void Blizzard by Microsoft) is a Russian state-sponsored APT group first publicly attributed by Dutch intelligence agencies in May 2025 following their 2024 compromise of the Dutch National Police.
highperson_alertThreat ActorJadeProx Deploys TriBack Loader Against Asian, Latin American Targets
JadeProx is a China-nexus threat actor tracked by Group-IB, discovered through an exposed Alibaba Cloud server in Singapore in mid-April 2026. The actor targets government, healthcare, and education organizations across Asia and Latin America.
highperson_alertThreat ActorLaundry Bear: Russian APT deploys zero-click phishing via Zimbra exploit
Laundry Bear is an advanced persistent threat (APT) group attributed to Russian state support, specializing in covert email data acquisition. The group conducts espionage operations targeting Western organizations and NATO members.
highperson_alertThreat ActorRussian Intelligence Services Exploit Security Cameras for Military Surveillance
Russian intelligence services are conducting a systematic cyber-espionage campaign targeting internet-connected security cameras across Europe and Ukraine.