2026-02-20 10:09 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
MuddyWater APT has launched a new cyber offensive operation, dubbed Operation Olalampo, deploying new malware variants and leveraging Telegram bots for command-and-control. Analysis of the campaign provides a glimpse into the group’s post-exploitation tactics, which largely align with their historical operations.
P0
2025-12-18 10:00 UTC
Other
ESET · indexed 2026-09-07 17:30 UTC
ESET researchers discovered a China-aligned APT group, LongNosedGoblin, which uses Group Policy to deploy cyberespionage tools across networks of governmental institutions
P0
2025-10-22 07:01 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Group-IB Threat Intelligence has uncovered a sophisticated phishing campaign, attributed with high confidence to the Advanced Persistent Threat (APT) MuddyWater. The attack used a compromised mailbox to distribute Phoenix backdoor malware to international organizations and across the whole Middle East and North Africa region, targeting more than 100 government entities.
P0
2025-09-15 05:44 UTC
Other
Red Hunt Labs · Bhavarth Karmarkar · indexed 2026-09-07 17:30 UTC
In July 2025, the Tea app 🔗, a mental health and social community platform, experienced a devastating breach that spilled 72,000 images (including 13,000 driver’s license and verification selfies) and over 1.1 million private direct messages onto the internet. The leaks first surfaced on 4chan and quickly spread across forums, torrents, and underground channels. This was not “just another API key leak.” Instead, it was a story about Firebase misconfigurations, poor data retention practices, an…
P25
2025-03-03 15:55 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Huntress discovered RedCurl activity across several organizations in Canada going back to 2023. Learn more about how this APT operates and how they aim to remain undetected while exfiltrating sensitive data.
P0
2024-11-13 05:55 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
P0
2024-09-04 06:52 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Explore the growing threats posed by the Lazarus Group's financially-driven campaign against developers. We will examine their recent Python scripts, including the CivetQ and BeaverTail malware variants, along with their updated versions in Windows and Python releases. Additionally, we will analyze their tactics, techniques, and indicators of compromise.
P0
2024-08-28 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Huntress identified an intrusion against a non-profit supporting Vietnamese human rights that’s likely spanned years. Jump in as we provide a thorough analysis of this malicious threat actor.
P0
2023-06-02 14:29 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
What we know about APT campaign to date and how to detect it
P0
2023-05-31 07:58 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
APT Dark Pink is back with 5 victims in new countries.
P0
2023-05-17 07:57 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Bridewell and Group-IB expose the APT’s unknown infrastructure
P0
2023-02-13 06:57 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
How a nation-state APT attempted to attack Group-IB
P0
2023-01-11 07:17 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
New APT hitting Asia-Pacific, Europe that goes deeper and darker
P0
2022-11-03 11:26 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
The French-speaking gang managed to carry out over 30 successful attacks on banks, financial services and telecommunications companies, mainly located in Africa.
P0
2022-08-18 08:48 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
4 malicious campaigns, 13 confirmed victims, and a new wave of Cobalt Strike infections
P0
2022-06-01 13:56 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
APT SideWinder’s new tool that narrows their reach to Pakistan
P0
2022-03-01 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
We discovered malicious, targeted advanced persistent threat (APT) activity on a partner's system. Here, we dive into the BABYSHARK malware strain.
P0
2021-08-03 07:33 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Chinese APTs attack Russia
P0
2021-06-10 09:26 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
APT41 likely behind a third-party attack on Air India
P0
2017-05-30 12:51 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Group-IB reveals the unknown details of attacks from one of the most notorious APT groups: sophisticated espionage and APT techniques of the North Korean state-sponsored hackers
P0