ElizaRAT
Cloudy With a Chance of RATs: Unveiling APT36 and the Evolution of ElizaRAT

CategoryDetailsThreat ActorsAPT36 (Transparent Tribe)Campaign OverviewTargeting Indian government organizations, diplomatic personnel, and military facilities. Focus on…

Threat Actor Abuses Cloudflare Tunnels to Deliver RATs

CategoryDetailsThreat ActorsUnattributed cybercriminal group using Cloudflare Tunnel abuse to deliver malware, primarily targeting organizations for…

Grandoreiro, the global trojan with grandiose goals

CategoryDetailsThreat ActorsBrazilian cybercriminal group operating Grandoreiro, part of the Tetrade umbrella.Campaign OverviewBanking trojan targeting financial…

Threat Actor Abuses Gophish to Deliver New PowerRAT and DCRAT

CategoryDetailsThreat ActorsUnknown Threat actor using Open-Source Gophish ToolkitCampaign OverviewPhishing campaign using modular infection chains (Maldoc…

Beyond the Surface: the evolution and expansion of the SideWinder APT group

CategoryDetailsThreat ActorsSideWinder (also T-APT-04, RattleSnake)Campaign OverviewProlific APT group active since 2012, targeting military & government…

The Crypto Game of Lazarus APT: Investors vs. Zero-days

CategoryDetailsThreat ActorsLazarus APT, BlueNoroff subgroupCampaign OverviewAttackers used a fake decentralized finance (DeFi) NFT-based tank game…

BlindEagle flying high in Latin America

CategoryDetailsThreat ActorsBlindEagle (APT-C-36)Campaign OverviewTargeting entities in Latin America (primarily Colombia) with espionage and financial attacks.Target…

Diplomats Beware: Cloaked Ursa Phishing With a Twist

CategoryDetailsThreat ActorsCloaked Ursa (aka APT29, UAC-0004, Midnight Blizzard/Nobelium, Cozy Bear), linked to Russia's Foreign Intelligence…

Top Tools for Email OSINT: Discover, Validate, and Investigate

Tool NameSnov.io Email FinderTool DescriptionA web-based tool to find email addresses associated with domains or…

Fortinet VPN zero-day exploited by Chinese threat actor

CategoryDetailsThreat ActorsBrazenBamboo (China-linked threat actor).Campaign OverviewExploiting a zero-day vulnerability in Fortinet’s FortiClient VPN for Windows…