• APT
  • November 19, 2024
Unveiling LIMINAL PANDA: A Closer Look at China's Cyber Threats to the Telecom Sector

CategoryDetailsThreat ActorsLIMINAL PANDA, associated with China-nexus cyber operations.Campaign OverviewActive since at least 2020, LIMINAL PANDA…

Russian National in US custody in Phobos ransomware investigation

Category Details Threat Actors Phobos ransomware operators, including alleged administrator Evgenii Ptitsyn (aliases: "derxan" and…

Ransomware Gang Akira leaks unprecedented number of victims’ data in one day

Category Details Threat Actors Akira ransomware Group (Ransomware-as-a-Service). Campaign Overview Published data from 35 victims…

Security Brief: ClickFix Social Engineering Technique Floods Threat Landscape

CategoryDetailsThreat ActorsTA571, ClearFake, various financially motivated and espionage groups (e.g., UAC-0050, Russian espionage targeting Ukraine).Campaign…

Dark Web Profile: Cadet Blizzard

CategoryDetailsThreat ActorsCadet Blizzard (DEV-0586), a Russian GRU-affiliated cyber threat group, part of Unit 29155.Campaign OverviewActive…

18th November – Threat Intelligence Report

CategoryDetailsChinese Cyber-Espionage CampaignFBI and CISA issued a joint statement on a major Chinese cyber-espionage campaign…

Ransomware Group called Hunters Claims attack for Mantinga.

CategoryDetailsThreat ActorsHunters International ( Acquired the Hive source code and website from the Original Developers. )Campaign…

OSINT Updates for November 18, 2024

https://twitter.com/marktsec46065/status/1858429053016912154 https://twitter.com/Ethic10Hackz/status/1858425229480976418 https://twitter.com/FalconFeedsio/status/1858299994794795372 https://twitter.com/DailyRansomware/status/1858422637107560596 https://twitter.com/fuxsociety1337/status/1858362542810190332 https://twitter.com/OSINTMilitia/status/1858371638452011326

Dissecting Sodinokibi Ransomware Attacks: Bringing Incident Response and Intelligence Together in the Fight

Category Details Threat Actors Sodinokibi (REvil), QakBot operators, Valak operators, Ransomware affiliates Campaign Overview Ransomware…

Threat actor believed to be spreading new MedusaLocker variant since 2022

CategoryDetailsThreat ActorsFinancially motivated group, possibly an Initial Access Broker (IAB) or affiliate of a ransomware…