At a glance Actor TA488 (Void Blizzard / Laundry Bear), Russia-aligned Activity Half-click XSS exploit of Outlook...
Cybercriminals
At a glance Actor or group TAG-195, also tracked as Golden Chickens and Venom Spider; deployment observed...
At a Glance Actor or group JadeProx, a China-nexus cluster named by Group-IB; no known group named...
At a glance Threat actor Famous Chollima, also called Wagemole; North Korea-aligned Activity type Social engineering via...
At a glance Actor or group Unnamed Russian-speaking crew tracked as Operation STANDOFF; self-branded “GG Influence” and...
At a glance Actor or group Kimsuky, a North Korea-linked group also tracked as Springtail, Thallium and...
At a glance Threat actor Unnamed group with links to East Asia (moderate-to-high confidence) Activity type Targeted...
At a glance Actor or group APT42 (Iran-linked; also tracked as TA453) Activity type AI-assisted spear-phishing, credential...
At a glance Actor / group DPRK-aligned group behind the Contagious Interview campaign (Elastic tracks it as...
At a glance Actor Jinbin Ren, 38, a Chinese national who lived in Lynnfield, Massachusetts; co-conspirators unnamed...
At a Glance Actor or group A vendor using the alias “Kontraktnik”; no real identity published Activity...
At a glance Actor / group Suspected Chinese-speaking APT group (low confidence) Activity type Cyberespionage using malicious...
At a glance Actor / group DoNot (APT-C-35); assessed by multiple vendors as India-aligned Activity type Targeted...
At a Glance Actor or group Unattributed threat actor; no group name published Activity type GitHub Actions...
At a glance Actor / group UAT-11795 (suspected Russian-speaking, financially motivated) Activity type Credential and cryptocurrency theft...
Initial Attack Details The renowned open-source private cloud software, Nextcloud, suffered a cyberattack yesterday morning. This incident...
At a Glance Actor Russian-speaking solo actor using the handle “bandcampro” Activity type AI-assisted C&C botnet, password...
During June 2026, Arctic Wolf Labs traced several ransomware intrusions to one entry point. Attackers exploited a...
At a glance Actor / group Piracy site operators. Four alleged members of “Los Ciberinfiltrados” arrested in...
At a Glance Field Detail Actors UNK_pyreq2323 and UNK_OutFlareAZ (two independent, unattributed clusters) Activity Account enumeration and...
Operation ShadowRecruit targets Indian job seekers with SheetAgent RAT, abusing ControlR and Google Sheets for C2. Seqrite...
At a glance Actor / group UTA0533 (Volexity tracking cluster); no nation or identity confirmed Activity type...