Nation-State briefings
State-sponsored espionage and sabotage: APT campaigns, attributed intrusion sets, and the geopolitical context behind them.
- Russian spies steal email with poisoned calendar invites 2026-08-07
- Korean firms hit by backdoor tied to North Korean hackers 2026-08-06
- New backdoor links Middle East spying to Central Asia hacks 2026-08-03
- Kaspersky finds 2005 cyberweapon aimed at nuclear models 2026-08-03
- Colombia links a Remcos spyware case to Blind Eagle hackers 2026-08-03
- Russian hackers hijack hotel Wi-Fi to bug travelers 2026-08-01
- Spies hit Central Asian ministries with backdoors built per victim 2026-07-30
- Hacked Korean websites pushed spy backdoors and Gunra ransomware 2026-07-30
- Spies hit aviation and telecom firms across the Middle East and Africa 2026-07-29
- China-nexus hackers exposed after leaving their attack server open 2026-07-25
- Russian hackers steal Western emails with a zero-click Zimbra exploit 2026-07-25
- Kaspersky links Israel calendar spyware to Iran's OilRig hackers 2026-07-21
- Stealthy spies hit Middle East governments by hiding in Telegram traffic 2026-07-20
- New spy malware hides its commands inside Microsoft 365 calendars 2026-07-20
- North Korean hackers hide malware in SVG flags to trap developers 2026-07-17
- New Go backdoor quietly steals government secrets across Southeast Asia 2026-07-17
- Hackers hijack ViPNet updates to backdoor Russian government networks 2026-07-16
- State-backed hackers hide attacks inside AI tools and trusted cloud apps 2026-07-14
- APT-C-60 hides its Japan spying inside GitHub and GitLab 2026-07-13
- Russia's FSB is hijacking weakly secured routers, 12 nations warn 2026-07-13
- GigaWiper fuses three destructive malware families into one backdoor 2026-07-10
- China-linked hackers grow a covert router relay with new backdoors 2026-07-07
- Iran-linked group targets Israeli firms with a stealthy new spy toolkit 2026-07-06
- New APT Armored Likho hits governments with AI-built malware loaders 2026-07-03
- Iran ramps up dissident surveillance with fake VPN and media apps 2026-07-01
- ToddyCat hackers steal corporate Gmail access with a stealthy new tool 2026-06-30
- Google warns Russia's influence network is pivoting from Ukraine back to the West 2026-06-29
- North Korean hackers flood South Korea with booby-trapped shortcut files 2026-06-29
- US Agencies Warn Russian Spies Still Phishing Messaging Apps 2026-06-27
- Russia's Gamaredon hides Ukraine spying behind everyday web services 2026-06-26
- Chinese hackers hit Southeast Asian energy grids with a new backdoor 2026-06-26
- Russia's FSB-linked Turla hits Ukraine with a stealthy new backdoor 2026-06-25
- New SharkLoader malware hits diplomats and governments with Cobalt Strike 2026-06-24
- Patchwork hackers deploy a stealthy new in-memory RAT in China-themed attacks 2026-06-17
- Suspected China Group Uses Microsoft-Signed Driver to Disable Security Software in Japan 2026-06-17
- Chinese cyberspies hit governments with a stealthier Windows backdoor 2026-06-17
- China-linked spies spent over a year inside North American research networks 2026-06-16
- China-linked spies lurked in a critical network for nearly a decade 2026-06-11
- Russia's APT28 hackers move to disposable malware and AI-driven tools 2026-06-11
- China-linked groups drive most state-backed attacks on tech firms 2026-06-10
- Hackers are phishing employees through Microsoft Teams, not email 2026-06-10
- Russia-aligned hackers keep hitting Ukraine through an old WinRAR bug 2026-06-09
- Iran's Hackers Are Shifting From Spying to Sabotaging US Infrastructure 2026-06-09
- Russian FSB Hackers Hit Ukraine With a Self-Reinstalling Malware Chain 2026-06-06
- Hackers Hijack Palo Alto Firewalls With Unpatched Root Flaw 2026-06-06
- Russian and Belarusian Government Networks Hit by Cloud Atlas Spy Campaign 2026-06-06
- Iranian Hackers Hit Defense Firms With Six New Spying Trojans 2026-06-06
- From Hacktivist to State Proxy: How Handala Became Iran's Most Prominent Cyber Persona 2026-03-03
- Operation Olalampo: MuddyWater Deploys Rust CHAR Backdoor, GhostFetch/GhostBackDoor, and Telegram Bot C2 Against MENA Organizations 2026-02-20
- Operation Bibi Gate: Handala Breaches Telegram Accounts of Senior Israeli Officials 2026-02-16
- ScoringMathTea: Inside Lazarus Group's Modular RAT with Reflective Plugin Loading and PEB-Walking API Evasion 2026-02-16
- Lazarus Group Targets Aerospace and Defense with New Comebacker Variant: ChaCha20 Encryption and AES-Encrypted C2 Mark Evolving Tradecraft 2026-02-16
- Operation DreamJob Targets European UAV and Defense Manufacturers: Lazarus Deploys ScoringMathTea via Trojanized Open-Source Tools 2026-02-16
- SOE-phisticated Persistence: How Flax Typhoon Turned ArcGIS Into a Year-Long Backdoor 2026-02-16
- DHCSpy Android Spyware: MuddyWater's VPN-Masquerading Surveillance Tool Active Since August 2022 Targets WhatsApp, Contacts, and Media 2026-02-16
- DOJ Charges Two APT27 Hackers as Unit 42 Confirms Group Still Active Across 45 Countries in 2025 2026-02-16
- Kimsuky Abuses GitHub as C2 Infrastructure: Hardcoded Private Tokens Enable Malware Delivery and Exfiltration via Nine Private Repositories 2026-02-16
- Kimsuky Deploys HttpTroy Backdoor via VPN Invoice Lure: Three-Stage Chain Using MemLoad and COM-Based Persistence 2026-02-16
- Amazon Disrupts APT29 Watering Hole Campaign Abusing Microsoft Device Code Authentication 2026-02-16
- MuddyWater Targets CFOs Globally with Firebase CAPTCHA Phishing, NetBird Abuse, and Hidden Admin Account Persistence 2026-02-16
- Hive0154 (Mustang Panda) Deploys Toneshell9 with Proxy-Blended C2 and SnakeDisk USB Worm Targeting Thailand Amid Cambodia Border Crisis 2026-02-16
- Secret Blizzard (Turla/FSB Center 16) ISP-Level AiTM Against Moscow Embassies: ApolloShadow Malware Installs Kaspersky-Masquerading Root Certificates and UpdatusUser Hidden Admin 2026-02-16
- TraderTraitor (Lazarus/UNC4899): JumpCloud Supply Chain Compromise, Bybit $1.5B Safe{Wallet} AWS Session Token Theft, and DMM Bitcoin $308M RN Stealer Campaign 2026-02-16
- APT41 Expands into Africa: Kaspersky Uncovers Wicked Panda's Sophisticated Campaign Against Government IT Services 2026-02-16
- APT37 Deploys Rust-Based Backdoor and Python Loader in Targeted Campaign Against South Korean Dissidents 2026-02-16
- Salt Typhoon Targets European Telecom: CVE-2025-5777 Citrix NetScaler Exploit, SNAPPYBEE/Deed RAT via Antivirus DLL Sideloading, and Dual HTTP/TCP C2 via LightNode VPS 2026-02-16
- Kimsuky's LNK-to-PowerShell Espionage Chain: Credential Theft, Keylogging, and Exfiltration Targeting South Korean Government 2026-02-16
- Lazarus Contagious Interview Deploys Tsunami Framework: Modular Malware Uses TOR and Pastebin for C2 in Cryptocurrency Theft Campaign 2026-02-16
- Sandworm (APT44) Deploys Trojanized KMS Activators Against Ukrainian Users: BACKORDER Go Loader, DcRAT Espionage, and Kalambur TOR-Based RDP Backdoor 2026-02-16
- Lazarus Group's LinkedIn Recruiting Scam Deploys Cross-Platform Stealer Chain Leading to Tsunami Framework and Tor C2 2026-02-16
- IRGC-Affiliated CyberAv3ngers Target Unitronics PLCs in Water, Energy, and Healthcare Sectors Across Multiple Countries 2026-02-16
- Andariel Acted as Play Ransomware Precursor in Five-Month Network Siege, Unit 42 Reveals 2026-02-16
- Microsoft Reveals Andariel's New Dora RAT and Decade-Long Malware Arsenal Targeting Aerospace and Defence 2026-02-16
- U.S. and Allied Agencies Warn of North Korean Andariel Espionage Campaign Targeting Defense and Nuclear Sectors 2026-02-16
- Mandiant Designates Andariel as APT45: North Korea's Nuclear Blueprint-Stealing Unit Fully Exposed 2026-02-16
- Microsoft Exposes Onyx Sleet's Expanding Malware Arsenal Targeting Aerospace and Defense Organizations 2026-02-16
- MuddyWater Replaces Atera RMM with Custom MuddyRot C Implant: PDF-to-Egnyte Delivery, COM-Based Scheduled Task Persistence, and Raw TCP C2 2026-02-16
- MuddyWater Deploys BugSleep Backdoor Against Israeli Municipalities, Airlines, and Media: Active Development with EDR Evasion via ProcessSignaturePolicy 2026-02-16
- PackXOR Unpacked: Inside FIN7's Private Packer Used to Conceal AvNeutralizer and Other Payloads 2026-02-16
- Mustang Panda Targets Vietnamese Organizations with forfiles.exe Abuse, DLL Sideloading, and RC4 MAC Address Exfiltration in Dual-Campaign Espionage Operation 2026-02-16
- Sandworm (UAC-0133) Plans Coordinated Cyber Sabotage Against 20 Ukrainian Critical Infrastructure Facilities: BIASBOAT Linux QUEUESEED Variant, LOADGRIP ptrace Injector, and Supply Chain Compromise 2026-02-16
- Volt Typhoon CISA Malware Analysis: FRPC Reverse Proxy, FRP NAT Traversal, and ScanLine Port Scanner Recovered from Compromised US Critical Infrastructure 2026-02-16
- Operation Triangulation: Four Zero-Days Including Undocumented GPU CoreSight MMIO Hardware Feature Used to Bypass Apple PPL in Most Sophisticated iOS Attack Chain Ever Analyzed 2026-02-16
- Mustang Panda Deploys Nim-Written DLL Loader with Custom RC4 to Target Taiwanese Government and Diplomats Using 2024 Presidential Election Lure 2026-02-16
- Operation Dream Magic: Lazarus Group Exploits MagicLine Vulnerability in Watering Hole Campaign Targeting 40 South Korean Organizations 2026-02-16
- Stately Taurus (Mustang Panda) Conducts Two-Year Southeast Asian Government Espionage Operation: Three-DLL ToneShell Variant, ShadowPad, and Continuous File Exfiltration via Dropbox 2026-02-16
- OilRig Outer Space and Juicy Mix Campaigns: Solar and Mango C#/.NET Backdoors Target Israeli Organizations with XOR Encryption, Compromised Israeli Websites as C2 2026-02-16
- Kimsuky Adds Chrome Remote Desktop to Remote Control Arsenal Alongside AppleSeed, RDP Patcher, and Ngrok 2026-02-16
- Mustang Panda Targets Australian Trade Minister in AUKUS-Motivated Campaign: SolidPDFCreator DLL Sideloading and PlugX Stager with Microsoft Host Header Masquerade 2026-02-16
- KillNet: Russia's Cyber Militia Expands from DDoS to Data Theft Across NATO, Government, and Healthcare Targets 2026-02-16
- Abraham's Ax Linked to Moses Staff: COBALT SAPLING Operates Dual Hacktivist Personas Targeting Israel and Saudi Arabia 2026-02-16
- APT42: Iran's IRGC-Linked Espionage Group Deploys Multi-Persona Phishing and Android Spyware Against Dissidents 2026-02-16
- APT35 Infrastructure Analysis Exposes Phishing Campaign Targeting Egyptian Shipping and Israeli Pipeline Interests 2026-02-16
- Lazarus Group (APT38): North Korea's Most Prolific Cyber Threat Actor Targets Banks, Crypto, and Critical Infrastructure 2026-02-16
- Deep Panda Exploits Log4Shell in VMware Horizon to Deploy Milestone Backdoor and Novel Kernel Rootkit 2026-02-16
- Singapore CSA Analyzes Anonymous Collective's Hacktivism Surge During Russia-Ukraine Conflict 2026-02-16
- Gamaredon Group: Russia's Most Prolific APT Against Ukraine, Powered by Custom Malware and SFX Persistence 2026-02-16
- MuddyWater Targets Turkish and Pakistani Organizations with Canary Token Anti-Analysis, PDF Lures, and PowerShell Downloaders 2026-02-16
- German Intelligence Warns APT27 Targeting Businesses with HYPERBRO Malware via Exchange and Zoho Exploits 2026-02-16
- BlackTech Escalates Attacks on Japanese Organizations: Spear-Phishing, Exchange Exploitation, and a Custom Malware Factory 2026-02-16
- APT33: Iran's IRGC-Linked Espionage Group Targets Aviation, Energy, and Defense Across Three Continents 2026-02-16
- MosesStaff Technical Analysis: PyDCrypt Loader and DCSrv Wiper Use DiskCryptor for Ideologically Motivated Destruction Without Ransom 2026-02-16
- Walking on APT31 Infrastructure Footprints: Inside China's SOHO Router Spy Network 2026-02-16
- FBI and CISA Expose APT40: China's MSS-Linked Hainan Hackers Indicted for Global Espionage Campaign 2026-02-16
- Carbanak and FIN7: Inside the TTPs of Financially Motivated Threat Groups Targeting Banks, Retail, and Hospitality 2026-02-16
- HAFNIUM's ProxyLogon Chain Triggers 44,000 Exploitation Attempts from 1,600+ IPs Within Weeks of Disclosure 2026-02-16
- The Story of Jian: How APT31 Stole and Repurposed an NSA Zero-Day Two Years Before the Shadow Brokers Leak 2026-02-16
- APT32's Multi-Stage macOS Trojan Innovates on Crimeware Scripting Techniques 2026-02-16
- The Enigmatic Energetic Bear: Russia's Most Successful Critical Infrastructure Intruder You've Never Heard Of 2026-02-16
- OilRig's RDAT Backdoor Deploys Novel Steganographic Email C2 via Exchange Web Services: BMP-Hidden Commands Against Middle Eastern Telecom 2026-02-16
- Winnti Group Targets Hong Kong Universities with ShadowPad: HP Digital Imaging DLL Sideloading, Parent Process Patching, and 17-Module Backdoor with University Campaign IDs 2026-02-16
- APT39: Iran's Personal Data Harvesting Machine Targets Telecom and Travel Industries for Surveillance Operations 2026-02-16
- menuPass (APT10) Deploys Cobalt Strike via Encrypted Executables and DKMC Bitmap Shellcode in Dual-Wave Attacks on Japanese Organizations 2026-02-16
- Dragonfly 2.0: Sophisticated Energy Sector Threat Group Returns with Sabotage-Ready Access to Operational Systems 2026-02-16
- Leviathan: Chinese Espionage Actor Targets Maritime, Naval Defense, and Military Research with Orz, NanHaiShu, and Cobalt Strike 2026-02-16
- The Shadow Brokers NSA Equation Group Leak: EternalBlue, EternalRomance, DoublePulsar, and the Fuzzbunch Framework Released April 2017 2026-02-16
- APT10's Operation Cloud Hopper: How China's MSS Weaponized IT Service Providers for Global Espionage 2026-02-16
- Magic Hound Campaign Targets Saudi Energy, Government, and Technology Sectors with Five Custom Tools and Ties to Rocket Kitten 2026-02-16
- FireEye Exposes APT3's Operation Clandestine Wolf Exploiting Adobe Flash Zero-Day CVE-2015-3113 2026-02-16
- Mandiant Unmasks APT1 as China's PLA Unit 61398 in Landmark Cyber Espionage Exposé 2026-02-16
- DHS Warns Anonymous Developing New Attack Tools Including #RefRef and Apache Killer 2026-02-16
- GhostNet: The 1,295-Computer Espionage Network That Redefined State-Level Cyber Intelligence 2026-02-16
- APT28 Weaponizes CVE-2026-21509 Zero-Day in Operation Neusploit Targeting Eastern Europe 2026-02-02
- CERT-UA Issues Danger Bulletin as APT28 Exploits CVE-2026-21509 Against Ukraine and EU Governments 2026-02-01