Cloudy With a Chance of RATs: Unveiling APT36 and the Evolution of ElizaRAT
CategoryDetailsThreat ActorsAPT36 (Transparent Tribe)Campaign OverviewTargeting Indian government organizations, diplomatic personnel, and military facilities. Focus on…
Threat Actor Abuses Cloudflare Tunnels to Deliver RATs
CategoryDetailsThreat ActorsUnattributed cybercriminal group using Cloudflare Tunnel abuse to deliver malware, primarily targeting organizations for…
Grandoreiro, the global trojan with grandiose goals
CategoryDetailsThreat ActorsBrazilian cybercriminal group operating Grandoreiro, part of the Tetrade umbrella.Campaign OverviewBanking trojan targeting financial…
Threat Actor Abuses Gophish to Deliver New PowerRAT and DCRAT
CategoryDetailsThreat ActorsUnknown Threat actor using Open-Source Gophish ToolkitCampaign OverviewPhishing campaign using modular infection chains (Maldoc…
Beyond the Surface: the evolution and expansion of the SideWinder APT group
CategoryDetailsThreat ActorsSideWinder (also T-APT-04, RattleSnake)Campaign OverviewProlific APT group active since 2012, targeting military & government…
The Crypto Game of Lazarus APT: Investors vs. Zero-days
CategoryDetailsThreat ActorsLazarus APT, BlueNoroff subgroupCampaign OverviewAttackers used a fake decentralized finance (DeFi) NFT-based tank game…
BlindEagle flying high in Latin America
CategoryDetailsThreat ActorsBlindEagle (APT-C-36)Campaign OverviewTargeting entities in Latin America (primarily Colombia) with espionage and financial attacks.Target…
Diplomats Beware: Cloaked Ursa Phishing With a Twist
CategoryDetailsThreat ActorsCloaked Ursa (aka APT29, UAC-0004, Midnight Blizzard/Nobelium, Cozy Bear), linked to Russia's Foreign Intelligence…
Top Tools for Email OSINT: Discover, Validate, and Investigate
Tool NameSnov.io Email FinderTool DescriptionA web-based tool to find email addresses associated with domains or…
Fortinet VPN zero-day exploited by Chinese threat actor
CategoryDetailsThreat ActorsBrazenBamboo (China-linked threat actor).Campaign OverviewExploiting a zero-day vulnerability in Fortinet’s FortiClient VPN for Windows…