Hamas-affiliated Threat Actor WIRTE Continues its Middle East Operations and Moves to Disruptive Activity

  Category Details Threat Actors WIRTE, affiliated with Hamas and likely part of the Gaza…

Cyberattack causes credit card readers to malfunction in Israel

Category Details Threat Actors Iran-linked hacker group, Hezbollah, and Politically-motivated hacktivists. Campaign Overview DDoS attack…

Dark Web Profile: Tropic Trooper (APT23)

FieldDetailsThreat ActorsTropic Trooper (APT23), also known as Pirate Panda, Iron, KeyBoy, Bronze Hobart, Earth CentaurCampaign…

North Korea allegedly targeting crypto businesses with Mac-focused malware

CategoryDetailsThreat ActorsBlueNoroff, a subgroup of Lazarus, attributed to North Korea's Reconnaissance General Bureau (RGB).Campaign Overview"Hidden…

HrServ – Previously unknown web shell used in APT attack

CategoryDetailsThreat ActorsUnknown threat actor; possibly a non-native English speaker; potential connection to Traditional Chinese language…

EastWind campaign: new CloudSorcerer attacks on government organizations in Russia

Category Details Threat Actors APT31, APT27 Campaign Overview Targeted Russian government organizations and IT companies…

China-linked hackers tasked with Japanese targets pursue them through Europe

Category Details Threat Actors MirrorFace, a China-linked hacking group. Campaign Overview Expansion of operations to…

Security Brief: Actor Uses Compromised Accounts, Customized Social Engineering to Target Transport and Logistics Firms with Malware

Category Details Threat Actors Not currently attributed to a specific threat actor. Infrastructure overlaps with…

Advanced Persistent Threat Targeting Vietnamese Human Rights Defenders | Huntress

FieldDetailsThreat ActorsAPT32 Campaign OverviewAdvanced persistent threat targeting oil and energy sectors, stealing intellectual property, and…

Lazarus and the FudModule Rootkit: Beyond BYOVD with an Admin-to-Kernel Zero-Day

CategoryDetailsThreat ActorsLazarus GroupCampaign OverviewExploitation of a zero-day vulnerability in the appid.sys AppLocker driver to gain…