CYBER CAMPAIGN/OPERATION (380) 2026 | 2025 | 2024 | 2023 | 2022 | 2021 | 2020 | 2019 | 2018 | 2017 | 2016 | 2015 | 2014 | 2013 | 2012 | 2011 | 2010 | 2009 | 2008 | ALL
|
DATE |
NAME |
INFO |
CATEGORY |
SUBCATE |
|
23.9.26 |
Operation Conflict Compass | Since 2009, the Democratic People’s Republic of Korea (DPRK) has fully integrated cyber operations into its national strategy, leveraging state-nexus threat groups to execute cyberespionage, conduct sabotage and influence operations, and generate revenue for state-sponsored nuclear weapons programs. | OPERATION | OPERATION |
|
22.9.26 |
Clop Hack | ShinyHunters has turned the tables on rival cybercrime operation Clop (a.k.a. Cl0p), hijacking and defacing the ransomware gang’s own Dark Web leak site (DLS) | OPERATION | OPERATION |
|
19.9.26 |
Operation RapidRust | In August 2026, Zscaler ThreatLabz observed new activity by the Pakistan-nexus threat actor APT36 in a campaign we’re tracking as Operation RapidRust. Since our last publication about the group’s activity in January 2026, APT36 has maintained a high operational tempo and updated their tactics, techniques, and procedures (TTPs) in continued attacks targeting government and defense organizations in India and Afghanistan. | OPERATION | OPERATION |
|
12.9.26 |
ShadowPane | ZeroBEC uncovered a phishing campaign we track as ShadowPane that uses browser-in-the-browser deception to make malicious RMM installations appear to originate from Adobe. | CAMPAIGN | CAMPAIGN |
|
8.9.26 |
BigBear 2.0 | CloudSEK researchers uncovered BigBear 2.0, a global Microsoft 365 phishing-as-a-service operation targeting hundreds of organizations across 40+ countries. | OPERATION | OPERATION |
|
8.9.26 |
BengalSEO | BengalSEO Part 1: Anatomy of the Operation | OPERATION | OPERATION |
|
7.9.26 |
SourTrade | SourTrade: Browser-Assembled Malware Delivered Through Malvertising | CAMPAIGN | CAMPAIGN |
| 24.8.26 | ClearFake | ClearFake gets more evasive with new living off the land (LOTL) techniques | CAMPAIGN | CAMPAIGN |
| 21.8.26 | Operation QUICSILVER | Contents Introduction Key Targets Industries Affected Geographical focus Infection Chain Campaign Timeline Initial Findings Looking into the Decoy Document Technical Analysis Stage 1 | OPERATION | OPERATION |
|
19.8.26 |
Operation CameraSwarm | Operation CameraSwarm: Over 14,000 Dahua cameras compromised across Ukraine and Russia | OPERATION | OPERATION |
|
18.8.26 |
Operation ASTERIX | Operation ASTERIX: Anatomy of a Crypto Fraud Pipeline | OPERATION | OPERATION |
|
2026 |
Operation Capsule Vault | Operation Capsule Vault: RokRAT Attack Chain Analysis Using EMBED_PAYLOAD_v2 | OPERATION | OPERATION |
| 2026 | Flooding Dropper | 'Flooding Dropper' Campaign Hits npm With Nearly 850 Malicious Packages | CAMPAIGN | CAMPAIGN |
| 2026 | Payroll Pirates | Payroll Pirates: Strange New Tides in Business Email Compromise | CAMPAIGN | CAMPAIGN |
|
2026 |
ChainDrop | ChainDrop: When Opening a Repository Becomes Execution | CAMPAIGN | CAMPAIGN |
|
2026 |
ShadowRay 2.0 | New Intelligence Links TeamPCP to ShadowRay 2.0 and Traces Activity back to 2020 | CAMPAIGN | CAMPAIGN |
|
2026 |
macOS ClickFix campaign | From open lures to cloaked gates: How a macOS ClickFix campaign learned to hide | CAMPAIGN | CAMPAIGN |
| 2026 | keyv and cacheable compromise | On August 4, 2026, a threat actor compromised the source or release credentials for the widely used keyv and cacheable npm packages and published trojanized versions of at least ten packages, beginning with keyv@6.0.0 at 09:35 UTC. Unlike a typical dependency swap, each version carries a malicious preinstall hook (setup.mjs) that downloads a standalone Bun runtime and executes an obfuscated ~728 KB second stage (Math_Symbol.js). | CAMPAIGN | CAMPAIGN |
| 2026 | QuickFox | QuickFox Supply Chain Attack Used to Deploy FDMTP Implant | CAMPAIGN | CAMPAIGN |
|
2026 |
Powercat malware campaign | Powercat malware campaign: Fake game cheats deliver infostealer | CAMPAIGN | CAMPAIGN |
|
2026 |
SMOKE#SCREEN | Analyzing SMOKE#SCREEN: ScreenConnect RMM Abuse, Cloudflare Tunnels, and Trusted Software Lures | CAMPAIGN | CAMPAIGN |
|
2026 |
ExfilSquad | ExfilSquad Targets Misconfigured Microsoft Power Pages Portals | CAMPAIGN | CAMPAIGN |
| 2026 | CaptiveCrunch | CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft | CAMPAIGN | CAMPAIGN |
| 2026 |
Targeted Attack on Government Entities in the Middle East | Part 1 |
|||
|
2026 |
Operation Double Barrel | This technical analysis report was prepared as part of the joint cybersecurity advisory titled “Advisory on Cyberattacks Targeting Korean Citizens and Businesses by State-Sponsored Hacking Groups, | OPERATION | OPERATION |
|
2026 |
Operation BlueDash | Operation BlueDash: Multi-RMM Workplace Phishing | OPERATION | OPERATION |
|
2026 |
[Op Report] From SSA Phish to AdaptixC2: A Multi-RAT Intrusion | Over five days in mid-May 2026, an operator engaged a deception workstation in the Deception.Pro environment and executed a near-complete commodity intrusion chain from initial access through domain reconnaissance. | OPERATION | OPERATION |
|
2026 |
JadeProx | JadeProx: Tracing a China-nexus Operation Through an OPSEC Mistake | OPERATION | OPERATION |
| 2026 | Operation Muck and Load | Malicious Go Module Exposes GitHub Malware Lure Network Spanning 222 Repositories | OPERATION | OPERATION |
|
2026 |
Operation Henhouse | Operation Henhouse: Hundreds of arrests and millions in assets seized in month tackling fraud | OPERATION | OPERATION |
|
2026 |
Operation ShadowRecruit | Contents Introduction Key Targets Industries Affected Geographical focus Infection Chain Initial Findings Looking into the Decoy Document | ||
| 2026 |
Since 2015, Qi An Xin Threat Intelligence Center has been closely monitoring the gambling and fraud industries in East Asia and Southeast Asia. |
|||
|
2026 |
SourTrade Ad Campaigns | SourTrade: Browser-Assembled Malware Delivered Through Malvertising | CAMPAIGN | CAMPAIGN |
|
2026 |
FakeGit campaign | AI-Assisted Fake GitHub Repositories Fuel SmartLoader and LummaStealer Distribution | CAMPAIGN | CAMPAIGN |
| 2026 | Large-Scale campaigne | Large-Scale GitHub Actions Abuse Powers a Distributed cPanel and WHM Exploitation Campaign | CAMPAIGN | CAMPAIGN |
| 2026 | Patriot Bait | One Man, One AI, One Fake Persona: Inside the 5-Year Influence and Fraud ‘Patriot Bait’ Campaign | CAMPAIGN | CAMPAIGN |
|
2026 |
HelloNet campaign | We identified targeted infection attempts against large Russian organizations using the ViPNet update system (a software suite for creating secure networks). | CAMPAIGN | CAMPAIGN |
| 2026 | PhantomGate Campaign | The PhantomGate Campaign — Obfuscation, Persistence, and Covert Surveillance | CAMPAIGN | CAMPAIGN |
|
2026 |
EVALUSION | EVALUSION Campaign Delivers Amatera Stealer and NetSupport RAT | CAMPAIGN | CAMPAIGN |
|
2026 |
TetrisPhantom | Kaspersky uncovers APT campaign targeting APAC government entities | CAMPAIGN | CAMPAIGN |
| 2026 | codemado | One Misconfigured Server, Three Active Campaigns: Full exposure of three AiTM Phishing Operators | CAMPAIGN | CAMPAIGN |
|
2026 |
mail-argenta | One Misconfigured Server, Three Active Campaigns: Full exposure of three AiTM Phishing Operators | CAMPAIGN | CAMPAIGN |
|
2026 |
saroula01 | One Misconfigured Server, Three Active Campaigns: Full exposure of three AiTM Phishing Operators | CAMPAIGN | CAMPAIGN |
| 2026 | GPPStorm | GPPStorm: Fake Google Partner Invitations Target Workspace Credentials | CAMPAIGN | CAMPAIGN |
| 2026 | LapDogs Campaign | Unmasking A New China-Linked Covert ORB Network: Inside the LapDogs Campaign | CAMPAIGN | CAMPAIGN |
| 2026 | Rogue Agent | Rogue Agent: How a Single Code Block Could Hijack Your AI Conversations in Google’s DialogFlow | CAMPAIGN | CAMPAIGN |
|
2026 |
PolinRider | PolinRider: North Korea-Linked Supply Chain Campaign Expands Across Open Source Ecosystems | CAMPAIGN | CAMPAIGN |
|
2026 |
LSHIY CAMPAIGN | No (Bad) CAP: Inside an Ongoing LSHIY Password Spray Attack | CAMPAIGN | CAMPAIGN |
| 2026 | Operation Navy Ghost | Operation Navy Ghost: How Attackers Planted a Telegram-Powered Backdoor Across Fake pyrogram Packages on PyPI | OPERATION | OPERATION |
|
2026 |
Operation Contagious Interview | The most effective social engineering campaigns don’t rely on obvious red flags or technical exploits. | OPERATION | OPERATION |
|
2026 |
Operation DragonReturn | Authors: Dixit Panchal & Soumen Burma Table of Contents: Introduction: | OPERATION | OPERATION |
| 2026 | Dismantling FortiBleed | Inside a Russian Fortinet compromise operation. | OPERATION | OPERATION |
| 2026 | Operation FanTrap | Operation FanTrap reveals FIFA 2026 fraud ecosystem with 4,000+ fake domains, phishing, streaming scams, and dark web-driven cybercrime activity. | OPERATION | OPERATION |
|
2026 |
Operation Poisson | Cato CTRL™ Threat Research: Operation Poisson – Analyzing a Cybercriminal’s Entire Operation | OPERATION | OPERATION |
|
2026 |
Velvet Ant’s Operation Highland: How a China-Nexus Actor Infiltrated an Internal Network Undetected |
|||
| 2026 | Phantom Mantis Operation | Phantom Mantis, initially known as ArmCorp, is a financially motivated threat group active since March 2025. | OPERATION | OPERATION |
| 2026 | StegoAd | Inside StegoAd: How We Disrupted a Massive Malicious Extension Campaign | CAMPAIGN | CAMPAIGN |
|
2026 |
Photo ZIP campaign | Photo ZIP campaign targeting hospitality industry delivers Node.js implant for persistent access | CAMPAIGN | CAMPAIGN |
|
2026 |
FortiBleed | FortiBleed: 75,000 Fortinet Firewalls Compromised: Global Enterprises Exposed – Claim Your Ethical Disclosure | CAMPAIGN | CAMPAIGN |
|
2026 |
easy-day-js: Supply Chain Campaign | easy-day-js: Supply Chain Campaign Targets Mastra npm Packages | CAMPAIGN | CAMPAIGN |
|
2026 |
UNK_DeadDrop | Don't Fear the Repo: UNK_DeadDrop Phishing Campaign Targets Developers to Steal Cryptocurrency | CAMPAIGN | CAMPAIGN |
| 2026 | Sniper’s Nest | Sniper’s Nest: From Brand Impersonation to Browser Hijacking and CPA Fraud | CAMPAIGN | CAMPAIGN |
| 2026 | Atomic Arch | Atomic Arch: Attackers Hijack Trusted AUR Packages to Deliver Rootkit-Like Malware | CAMPAIGN | CAMPAIGN |
|
2026 |
Miasma Worm Campaign | Shai-Hulud Descends to Hades: Miasma Worm Campaign Spreads with New PyPI Wave | CAMPAIGN | CAMPAIGN |
|
2026 |
Miasma credential-stealing campaign | Microsoft Threat Intelligence identified a large-scale npm supply chain attack affecting 32 maliciously modified packages across more than ... | CAMPAIGN | CAMPAIGN |
| 2026 | GHOST STADIUM | The GHOST STADIUM Score: Billions At Stake At The World’s Largest Football Tournament | CAMPAIGN | CAMPAIGN |
| 2026 | Game Over: WeedHack | Game Over: WeedHack – The Rise of Minecraft Malware-as-a-Service Campaigns | CAMPAIGN | CAMPAIGN |
|
2026 |
Operation FlutterBridge | Operation FlutterBridge: macOS Malvertising Campaign Spreads New FlutterShell Backdoor | OPERATION | OPERATION |
| 2026 | Operation Dragon Weave | Contents Introduction Key Targets Industries Affected Geographical focus Infection Chain Initial Findings Looking into the Decoy Document | OPERATION | OPERATION |
| 2026 | Operation XENOFISCAL | Authors: Dixit Panchal & Vaibhav Krushna Billade Table of Contents: Introduction: | OPERATION | OPERATION |
|
2026 |
Nimbus Manticore Operations | The Iranian, IRGC affiliated, threat actor Nimbus Manticore resurfaced during Operation Epic Fury, the US military campaign against Iran launched on ... | OPERATION | OPERATIONS |
| 2026 | Operation Dragon Whistle | Table of Contents: Introduction: Key Targets: Infection Chain: Initial Findings about Campaign: Analysis of Decoys & Spear phishing Email: | OPERATION | OPERATION |
| 2026 | Operation NoVoice | Operation NoVoice: Android Malware Found in 50+ Apps Can Hijack Devices | OPERATION | OPERATION |
| 2026 | Operation GriefLure | Table of Contents: Introduction: Key Targets: Infection Chain: Initial Findings about Campaign: Analysis of Decoys: | OPERATION | OPERATION |
| 2026 | Operation Silent Rotor | Operation Silent Rotor: Targeted Campaign Compromises Unmanned Aviation Sector Ahead of Moscow Summit Table of Content Introduction Key | OPERATION | OPERATION |
| 2026 | Operation HumanitarianBait | Cyble analyzes Operation HumanitarianBait, a stealthy espionage campaign using aid-themed lures to deploy a fileless Python infostealer. | OPERATION | OPERATION |
| 2026 | Iranian-Nexus Operation | Iranian-Nexus Operation Against Oman's Government: 12 Ministries Hit and 26,000 Citizen Records Exposed | OPERATION | OPERATION |
| 2026 | Operation TrustTrap | CRIL uncovered 16,800+ spoofed domains by analyzing URL trust abuse, cloud infra clustering, and human‑centric deception instead of technical exploits. | OPERATION | OPERATION |
| 2026 | Operation NoVoice | Operation NoVoice: Rootkit Tells No Tales | OPERATION | OPERATION |
| 2026 | Operation TrueChaos | Check Point Research identified a zero-day vulnerability in the TrueConf client application, tracked as CVE-2026-3502, with a CVSS score of 7.8. | OPERATION | OPERATION |
| 2026 | Operation DualScript | Operation DualScript – A Multi-Stage PowerShell Malware Campaign Targeting Cryptocurrency and Financial Activity Introduction During our investigation, | OPERATION | OPERATION |
| 2026 | Multi-Tool Mining Operation | Fake Installers to Monero: A Multi-Tool Mining Operation | OPERATION | OPERATION |
| 2026 | Operation GhostMail | Contents Introduction Key Targets Industries Affected Geographical focus Geopolitical Context Infection | OPERATION | OPERATION |
| 2026 | LeakNet’s | Casting a Wider Net: ClickFix, Deno, and LeakNet’s Scaling Threat | OPERATION | OPERATION |
| 2026 | Operation CamelClone: | Contents Introduction Key Targets Industries Affected Geographical focus Geopolitical Context Infection | OPERATION | OPERATION |
| 2026 | Operation Epic Fury/Roaring Lion | Retaliatory Hacktivist DDoS Activity Following Operation Epic Fury/Roaring Lion | OPERATION | OPERATION |
| 2026 | Operation MacroMaze | Operation MacroMaze: new APT28 campaign using basic tooling and legit infrastructure | OPERATION | OPERATION |
| 2026 | Operation Olalampo | MuddyWater APT has launched a new cyber offensive operation, dubbed Operation Olalampo, deploying new malware variants and leveraging .. | OPERATION | OPERATION |
| 2026 | Operation Neusploit | APT28 Leverages CVE-2026-21509 in Operation Neusploit | OPERATION | OPERATION |
| 2026 | Operation DupeHike | Contents Introduction Key Targets. Industries Affected. Geographical Focus. Infection Chain. Initial Findings. | OPERATION | OPERATION |
| 2026 | Operation Covert Access | Table of Contents: Introduction: Infection Chain: Targeted sectors: Initial Findings about Campaign: Analysis of Decoy: | OPERATION | OPERATION |
| 2026 | Operation Nomad Leopard | Contents Introduction Key Targets Industries Affected Geographical focus Infection Chain. | OPERATION | OPERATION |
| 2026 | Megalodon | Megalodon: Mass GitHub Repo Backdooring via CI Workflows | CAMPAIGN | CAMPAIGN |
| 2026 | GemStuffer Campaign | GemStuffer Campaign Abuses RubyGems as Exfiltration Channel Targeting UK Local Government | CAMPAIGN | CAMPAIGN |
| 2026 | Multi-stage ‘code of conduct’ phishing campaign | Phishing campaigns continue to improve sophistication and refinement in blending social engineering, delivery and hosting infrastructure, .. | CAMPAIGN | CAMPAIGN |
| 2026 | VENOMOUS#HELPER | You’re invited: Four phishing lures in campaigns dropping RMM tools | CAMPAIGN | CAMPAIGN |
| 2026 | Snow Flurries | Snow Flurries: How UNC6692 Employed Social Engineering to Deploy a Custom Malware Suite | CAMPAIGN | CAMPAIGN |
| 2026 | Rotten Apple | Rotten Apple: An Invasive Threat Actor Targeting Civil Society in Lebanon | CAMPAIGN | CAMPAIGN |
| 2026 | Pawn Storm Campaign | Pawn Storm Campaign Deploys PRISMEX, Targets Government and Critical Infrastructure Entities | CAMPAIGN | CAMPAIGN |
| 2026 | Internet-exposed ComfyUI instances | Hackers Are Attempting to Turn ComfyUI Servers Into a Cryptomining Proxy Botnet | CAMPAIGN | CAMPAIGN |
| 2026 | Iran-nexus Password Spray Campaign | Iran-nexus Password Spray Campaign Targeting Cloud Environments, with a Focus on the Middle East | CAMPAIGN | CAMPAIGN |
| 2026 |
DPRK-Related Campaigns with LNK and GitHub C2 |
How DPRK actors use LNK files and GitHub C2 to evade detection and maintain persistence | CAMPAIGN | CAMPAIGN |
| 2026 | WhatsApp malware campaign | WhatsApp malware campaign delivers VBScript and MSI backdoors | CAMPAIGN | CAMPAIGN |
| 2026 |
Augmented Marauder’s Multi-Pronged Casbaneiro Campaigns |
Unpacking Augmented Marauder’s Multi-Pronged Casbaneiro Campaigns | CAMPAIGN | CAMPAIGN |
| 2026 | Analyzing FAUX#ELEVATE | Analyzing FAUX#ELEVATE: Threat Actors Target France with CV Lures to Deploy Crypto miners and Infostealers Targeting Enterprise Environments | CAMPAIGN | CAMPAIGN |
| 2026 | ForceMemo | ForceMemo: Hundreds of GitHub Python Repos Compromised via Account Takeover and Force-Push | CAMPAIGN | CAMPAIGN |
| 2026 | KakaoTalk | Analysis of the Spear-Phishing and KakaoTalk-Linked Threat Campaign by the Konni Group | CAMPAIGN | CAMPAIGN |
| 2026 | StegaBin | Novel DPRK stager using Pastebin and text steganography | CAMPAIGN | CAMPAIGN |
| 2026 | GRIDTIDE | GRIDTIDE Global Cyber Espionage Campaign | CAMPAIGN | CAMPAIGN |
| 2026 | Monero Mining Campaign | Technical Deep Dive: The Monero Mining Campaign | CAMPAIGN | CAMPAIGN |
| 2026 | Monero Mining Campaign | In the contemporary threat landscape, while ransomware grabs headlines with high-impact disruptions, cryptojacking operations.. | CAMPAIGN | CAMPAIGN |
| 2026 | AiFrame | “AiFrame”- Fake AI Assistant Extensions Targeting 260,000 Chrome Users via injected iframes | CAMPAIGN | CAMPAIGN |
| 2026 | Massiv | Massiv: When your IPTV app terminates your savings | CAMPAIGN | CAMPAIGN |
| 2026 | CRESCENTHARVEST | CRESCENTHARVEST: Iranian protestors and dissidents targeted in cyberespionage campaign | CAMPAIGN | CAMPAIGN |
| 2026 | Fake recruiter campaign | A new branch of a fake job recruitment campaign, dubbed "graphalgo," is targeting developers with a RAT. | CAMPAIGN | CAMPAIGN |
| 2026 | SideCopy Launch Cross-Platform RAT Campaigns | Espionage Without Noise: Understanding APT36’s Enduring Campaigns | CAMPAIGN | CAMPAIGN |
| 2026 | TeamPCP | Threat Alert: TeamPCP, An Emerging Force in the Cloud Native and Ransomware Landscape | CAMPAIGN | CAMPAIGN |
| 2026 | Shadow Campaigns | The Shadow Campaigns: Uncovering Global Espionage | CAMPAIGN | CAMPAIGN |
| 2026 | NGINX Configurations Enable Large- | Web Traffic Hijacking: When Your Nginx Configuration Turns Malicious | CAMPAIGN | CAMPAIGN |
| 2026 | Dead#Vax | Analyzing Dead#Vax: Analyzing Multi-Stage VHD Delivery and Self-Parsing Batch Scripts to Deploy In-Memory Shellcode | CAMPAIGN | CAMPAIGN |
| 2026 | RedKitten | RedKitten: AI-accelerated campaign targeting Iranian protests | CAMPAIGN | CAMPAIGN |
| 2026 | ShinyHunters | Vishing for Access: Tracking the Expansion of ShinyHunters-Branded SaaS Data Theft | CAMPAIGN | CAMPAIGN |
| 2026 | SyncFuture Espionage Targeted Campaign | Weaponized in China, Deployed in India: The SyncFuture Espionage Targeted Campaign | CAMPAIGN | CAMPAIGN |
| 2026 | AI-orchestrated cyber espionage campaign | We have developed sophisticated safety and security measures to prevent the misuse of our AI models. | CAMPAIGN | CAMPAIGN |
| 2026 | doxxing campaign | Shifts in the Underground: The Impact of Water Kurita’s (Lumma Stealer) Doxxing | CAMPAIGN | CAMPAIGN |
| 2026 | GhostPoster Campaign | Browser Extensions Gone Rogue: The Full Scope of the GhostPoster Campaign | CAMPAIGN | CAMPAIGN |
| 2026 | Fortinet FortiGate Devices via SSO Accounts | Arctic Wolf has observed a new cluster of automated malicious activity involving unauthorized firewall configuration changes on FortiGate devices. | CAMPAIGN | CAMPAIGN |
| 2026 | Campaign Targeting LastPass Customers | New Phishing Campaign Targeting LastPass Customers | CAMPAIGN | PHISHING |
| 2026 | Contagious Interview campaign | Threat Actors Expand Abuse of Microsoft Visual Studio Code | CAMPAIGN | CAMPAIGN |
| 2026 | SHADOW#REACTOR | SHADOW#REACTOR – Text-Only Staging, .NET Reactor, and In-Memory Remcos RAT Deployment | CAMPAIGN | CAMPAIGN |
| 2026 | Boto-Cor-de-Rosa | Boto-Cor-de-Rosa campaign reveals Astaroth WhatsApp-based worm activity in Brazil | CAMPAIGN | CAMPAIGN |
| 2026 | Operation Poseidon | Operation Poseidon: Spear-Phishing Attacks Abusing Google Ads Redirection Mechanisms | OPERATION | OPERATION |