§Topic · APT & Threat Actors
APT & Threat Actors
Nation-state threat actors, APT groups, and targeted campaigns by advanced persistent adversaries.
All dispatches
Loading
§Topic · APT & Threat Actors
Nation-state threat actors, APT groups, and targeted campaigns by advanced persistent adversaries.
All dispatchesTerminalFix ClickFix variant tricks Windows Terminal/PowerShell users into running commands, deploying reverse-tunnel backdoor access.
Lazarus exploits AFD.sys zero-day (CVE-2026-68820) to deploy FudModule rootkit for stealthy kernel persistence.
Jewelbug APT operators run both state espionage and cryptocurrency theft from the same web control panel.
Microsoft issued massive Patch Tuesday fixes including multiple zero-days, with some exploited in nation-state campaigns.
Threat actors exploited unpatched TrueConf servers to replace client installers with trojanized backdoors for remote access.
CSS bomb technique manipulates webmail UI to spy on user activity and capture passwords and tokens without JavaScript.
Open-source AiTM phishing kits proxy live Microsoft 365 auth sessions, capturing tokens and bypassing MFA protections.
Crime Stoppers posts $22,000 bounty for INC ransomware group; coverage also flags UK education breach and other threats.
Wiz documents CaptiveCrunch AiTM campaign by Storm-2945/Midnight Blizzard targeting hospitality captive portals to harvest credentials.
Threat actors abused ViPNet update mechanism to push malicious updates targeting Russian government organizations.
UAC-0145 (Sandworm sub-cluster) uses ClickFix CAPTCHAs to trick Ukrainian targets into installing data-stealing malware.
Get these articles delivered to your inbox.
Subscribe free