Group 2026 2026() 2025() 2024()
DATE |
NAME |
INFO |
CATEGORY |
SUBCATE |
|
3.10.26 |
UAT-11587 | China-nexus UAT-11587 targets government and policy organizations across Asia with Antino backdoor | GROUPS | GROUPS |
|
28.9.26 |
JADEPUFFER | Storm-3168: Agentic-driven cloud attacks using compromised service principals | GROUPS | GROUPS |
|
24.9.26 |
UNK_CondorFiltration | Spraying in the Andes: TeamFiltration Returns to Exploit Forgotten Service Accounts | GROUPS | CLUSTER |
|
19.9.26 |
Lemmings | Data posted to a darknet forum by an account named okenit_hackers in October 2025 reveals that Russian actors have potentially upgraded their disinformation methods through the automated creation and management of fake personae. | GROUPS | GROUPS |
|
19.9.26 |
Sudeep Singh | Tracking nation-state adversaries — hunting their malware, infrastructure and tradecraft across China-, Russia-, Iran-, Pakistan- and North Korea-nexus operations. | GROUPS | GROUPS |
|
16.9.26 |
Tajin Group’s | Tajin Group detailed its operational challenges and announced key plans and changes, showcasing its ability to adapt and evolve to conduct payment card theft and money laundering activities. | GROUPS | GROUPS |
|
15.9.26 |
Red Heron | Red Heron exploits Gitea n-day flaw in multinational campaign, exposing new Linux rootkit | GROUPS | HACKER |
|
19.8.26 |
TENGU RANSOMWARE | This is the initial report of Tengu Ransomware. New Information was last added on 16th March 2026. | RANSOM | RANSOM |
|
11.8.26 |
DeadLock ransomware | DeadLock ransomware: Breaking down a Rust-based encryptor with decentralized recovery infrastructure | RANSOM | RANSOM |
|
11.8.26 |
#StopRansomware: Gunra Ransomware | Gunra is a ransomware-as-a-service (RaaS) used by affiliates to target government, critical infrastructure, and other organizations. | GROUP | RANSOM |
|
11.8.26 |
AA26-222A StopRansomware Gunra Ransomware | The FBI originally observed Gunra ransomware in April 2025. The threat actors quickly established a DLS on the Tor network to list victims and publish exfiltrated data. | GROUP | RANSOM |
|
8.8.26 |
Pink | New Data Extortion Group “Pink” Goes Big Game Hunting With Evasive Phishing Kits | GROUP | GROUP |
|
8.8.26 |
UNC6671 | UNC6671 Rebrands: Multi-Brand Vishing Extortion Targets Financial Services and Enterprise Cloud Environments | GROUP | GROUP |
|
3.8.26 |
Larva-24009 | Analysis of a Phishing Email Attack Case by the Larva-24009 Threat Actor | GROUP | GROUP |
|
30.7.26 |
Toy Ghouls | Toy Ghouls’ new toy: the GenieLocker ransomware | RANSOM | RANSOM |
|
30.7.26 |
Toy Ghouls | Toy Ghouls’ new toy: the GenieLocker ransomware | GROUP | GROUP |
|
30.7.26 |
SilverFox Evolves | Cato CTRL™ Threat Research: SilverFox Evolves: Abuse of New Drivers and Trusted Software Hijacking Enable Remote Access with ValleyRAT in Japan | GROUP | GROUP |
|
30.7.26 |
TA488 | Cleaning Out Inboxes: TA488 Comes for Outlook with Another Half-Click Exploit | GROUP | GROUP |
|
25.7.26 |
The Gentlemen RaaS | The Gentlemen RaaS: Origins, OPSEC & OSINT | RANSOM | RaaS |
|
25.7.26 |
DEVMAN Ransomware | DEVMAN Ransomware: Analysis of New DragonForce Variant | RANSOM | RANSOM |
|
25.7.26 |
Funky Mantis | Funky Mantis operates as a centralized ransomware-as-a-service model. Administrators manage affiliates, distribute access, and support extortion through private communications and a dedicated web platform. The platform combines payload building, finance, negotiation, support, and victim management, giving the service control over affiliate access and operational progress. | GROUP | GROUP |
|
24.7.26 |
TAG-195 | TAG-195 Upgrades MaaS Ecosystem with Modular Tools | GROUP | GROUP |
|
23.7.26 |
Chaos RaaS | Unmasking the new Chaos RaaS group attacks | GROUP | GROUP |
|
21.7.26 |
JADEPUFFER | JADEPUFFER evolves: The agentic threat actor deploys ransomware built to destroy AI models | RANSOM | AI |
|
18.7.26 |
SuccessKey | ChainVeil: A Malicious npm Supply Chain Attack by SuccessKey | ||
|
18.7.26 |
UAT-11795 | Cisco Talos is disclosing UAT-11795, a sophisticated, Russian-speaking, financially motivated adversary that has been conducting a malicious campaign targeting users in the U.S. and Europe since at least June 2025. | ||
|
17.7.26 |
Introducing CylindricalCanine: The GoldenEyeDog subgroup responsible for the April DigiCert incident |
|||
| 12.7.26 | Helix | Helix, a New Name in the Data Extortion Ecosystem? | GROUP | Vishing |
| 12.7.26 | UNK_MassTraction | One Email Closer to the Edge: UNK_MassTraction & the Physics of Exploitation | GROUP | Cluster |
| 9.7.26 | Beast Ransomware | The Nature of the Beast Ransomware | RANSOM | RANSOM |
| 9.7.26 | GodDamn Ransomware | GodDamn Ransomware: Latest Beast Rebrand Uses Malicious Driver to Disable Defenses | RANSOM | RANSOM |
| 7.7.26 | Cavern Manticore | Cavern Manticore: Exposing Iran-Linked Modular C2 Framework | GROUP | GROUP |
| 2.7.26 | JADEPUFFER | JADEPUFFER: Agentic ransomware for automated database extortion | RANSOM | RANSOM |
| 29.6.26 | Payouts King Ransomware | Payouts King Ransomware Initial Access Broker Deploys New Edgecution Malware | RANSOM | RANSOM |
| 21.6.26 | Prinz Eugen ransomware | Prinz Eugen ransomware: a deep dive into a new Go-based encryptor | RANSOM | RANSOM |
|
13.6.26 |
China-Nexus Threat Group ‘Velvet Ant’ Abuses F5 Load Balancers for Persistence |
|||
| 8.6.26 | UNC3753 | Seeking Counsel: Ongoing Targeted Campaign Against US Law Firms | GROUP | GROUP |
| 6.6.26 | TA505 exploits SolarWinds Serv-U vulnerability (CVE-2021-35211) for initial access | NCC Group’s global Cyber Incident Response Team has observed an increase in Clop ransomware victims in the past weeks. | GROUP | GROUP |
| 5.6.26 | Cluster OP-512 | ReliaQuest's Agentic AI Uncovers New China-Linked Cluster OP-512 | GROUP | GROUP |
| 4.6.26 | TA4922 | TA4922: The Suspected Chinese Crime Group is Going Global | GROUP | GROUP |
| 3.6.26 | UAC-0184 | UAC-0184: From HTA to a Signed Network Stack | GROUP | GROUP |
| 29.5.26 | GREYVIBE | GREYVIBE: A Russia-nexus group leveraging AI across state-aligned operations | GROUP | GROUP |
| 28.5.26 | JINX-0164 | Commit to Compromise: A New Threat Actor Targeting the Cryptocurrency Industry's Software Development Infrastructure | GROUP | GROUP |
| 23.5.26 | Storm-2949 | How Storm-2949 turned a compromised identity into a cloud-wide breach | GROUP | GROUP |
| 20.5.26 | Disrupting Fox Tempest | Disrupting Fox Tempest: A cybercrime service that turned “verified” software into a pathway for ransomware | GROUPS | RANSOMWARE |
| 18.5.26 | Fast16 | Fast16: Pre-Stuxnet Sabotage Tool Was Built to Subvert Nuclear Weapons Simulations | GROUP | GROUP |
| 14.5.26 | UNC1151 | UNC1151 exploiting Roundcube to steal user credentials in a spearphishing campaign | GROUP | GROUP |
| 14.5.26 | FrostyNeighbor | FrostyNeighbor: Fresh mischief and digital shenanigans | GROUP | GROUP |
| 6.5.26 | UAT-8302 | UAT-8302 and its box full of malware | GROUP | GROUP |
| 1.5.26 | Cordial Spider | CORDIAL SPIDER is a financially motivated eCrime adversary that has performed data theft and extortion since at least October 2025. | GROUP | GROUP |
| 1.5.26 | Snarky Spider | SNARKY SPIDER is a financially motivated eCrime adversary that has performed data theft and extortion and cryptocurrency theft since at least October 2025. T | GROUP | GROUP |
| 1.5.26 | Shadow-Earth-053 | Inside Shadow-Earth-053: A China-Aligned Cyberespionage Campaign Against Government and Defense Sectors in Asia | GROUP | GROUP |
| 28.4.26 | VECT 2.0 Ransomware | A new ransomware gang calling itself Vect is recruiting affiliates and preparing for further operations. Operating as a ransomware-as-a-service (RaaS), the group launched its affiliate program in late December 2025 and began active operations a week later. | RANSOM | RANSOM |
| 26.4.26 | Cordial Spider | CORDIAL SPIDER is a financially motivated eCrime adversary that has performed data theft and extortion since at least October 2025. CORDIAL SPIDER gains initial access to victim systems via voice phishing (vishing) calls in which they direct targeted users to single sign-on (SSO)–themed phishing pages. | GROUP | GROUP |
| 25.4.26 | UNC6692 | Google Threat Intelligence Group (GTIG) identified a multistage intrusion campaign by a newly tracked threat group, UNC6692, that leveraged persistent social engineering, a custom modular malware suite, and deft pivoting inside the victim’s environment to achieve deep network penetration. | GROUP | GROUP |
| 25.4.26 | UAT-4356's | Cisco Talos is aware of UAT-4356's continued active targeting of Cisco Firepower devices’ Firepower eXtensible Operating System (FXOS). UAT-4356 exploited n-day vulnerabilities (CVE-2025-20333 and CVE-2025-20362) to gain unauthorized access to vulnerable devices. | GROUP | GROUP |
| 24.4.26 | UNC6692 | GROUP | GROUP | |
| 22.4.26 | Kyber Ransomware | Kyber Ransomware Double Trouble: Windows and ESXi Attacks Explained | RANSOM | RANSOM |
| 22.4.26 | DFIR Report – The Gentlemen & SystemBC | DFIR Report – The Gentlemen & SystemBC: A Sneak Peek Behind the Proxy | RANSOM | RANSOM |
| 17.4.26 | UAC-0247 | Лікарні, органи місцевого самоврядування та оператори FPV - у фокусі кластера кіберзагроз UAC-0247 | GROUP | GROUP |
| 12.4.26 | Storm-2755 | Investigating Storm-2755: “Payroll pirate” attacks targeting Canadian employees | GROUP | GROUP |
| 8.4.26 | FrostArmada | A DNS setting change on a single router can quietly reroute an entire network’s authentication traffic. In FrostArmada, Lumen observed Forest Blizzard using that technique to feed targeted logins into Attacker-in-the-Middle (AitM) infrastructure, scaling from limited activity to thousands of victims worldwide. | GROUP | GROUP |
| 8.4.26 | Pay2Key | Pay2Key Iranian-Linked Ransomware is Back, Back Again | GROUP | RANSOMWARE |
| 8.4.26 | Storm-1175 | Storm-1175 focuses gaze on vulnerable web-facing assets in high-tempo Medusa ransomware operations | GROUP | GROUP |
| 8.4.26 | PIONEER KITTEN | Who Is PIONEER KITTEN? | GROUP | APT |
| 5.4.26 | TA416 | I’d come running back to EU again: TA416 resumes European government espionage campaigns | GROUP | GROUP |
| 3.4.26 | UAT-10608 | UAT-10608: Inside a large-scale automated credential harvesting operation targeting web applications | GROUP | GROUP |
| 1.4.26 | UNC1069 | North Korea-Nexus Threat Actor Compromises Widely Used Axios NPM Package in Supply Chain Attack | GROUP | GROUP |
| 27.3.26 | Bearlyfy | Bearlyfy Hits Russian Firms with Custom GenieLocker Ransomware | GROUP | GROUP |
| 14.3.26 | Handala Hack | Handala Hack is an online persona operated by Void Manticore (aka Red Sandstorm, Banished Kitten), an actor affiliated with Iranian Ministry of Intelligence and Security (MOIS) | GROUP | GROUP |
| 14.3.26 | CL-STA-1087 | Suspected China-Based Espionage Operation Against Military Targets in Southeast Asia | GROUP | CLUSTER |
| 14.3.26 | Storm-2561 | Storm-2561 uses SEO poisoning to distribute fake VPN clients for credential theft | GROUP | GROUP |
| 10.3.26 | Sednit | Sednit reloaded: Back in the trenches | GROUP | GROUP |
| 8.3.26 | Anubis | Anubis: A New Ransomware Threat | RANSOM | RANSOM |
| 8.3.26 | Jasper Sleet | Jasper Sleet: North Korean remote IT workers’ evolving tactics to infiltrate organizations | GROUP | GROUP |
| 6.3.26 | UAT-9244 | UAT-9244 targets South American telecommunication providers with three new malware implants | GROUP | GROUP |
| 3.3.26 | SloppyLemming | SloppyLemming is an advanced actor that uses multiple cloud service providers to facilitate different aspects of their activities, such as credential harvesting, malware delivery and command and control (C2). This actor conducts extensive operations targeting Pakistani, Sri Lanka, Bangladesh, and China. | GROUP | GROUP |
| 1.3.26 | COOKIE SPIDER | COOKIE SPIDER (active since at least October 2018) develops and rents Atomic macOS Stealer (AMOS), an information stealer targeting macOS victims via multiple delivery methods, including search engine optimization (SEO) poisoning, fake job advertisements, and malicious VSCode extensions. | GROUP | GROUP |
| 1.3.26 | Diesel Vortex | Diesel Vortex: Inside the Russian cybercrime group targeting US & EU freight | GROUP | GROUP |
| 27.2.26 | APT37 | APT37 Adds New Capabilities for Air-Gapped Networks | GROUP | GROUP |
| 26.2.26 | Scattered LAPSUS$ Hunters | Cyber Intel Brief: Scattered Lapsus$ Hunters (SLH) Kicks Off Campaign to Recruit Women | GROUP | GROUP |
| 26.2.26 | UNC2814 | Exposing the Undercurrent: Disrupting the GRIDTIDE Global Cyber Espionage Campaign | GROUP | GROUP |
| 15.2.26 | Storm-2603 | Storm-2603 Exploits CVE-2026-23760 to Stage Warlock Ransomware | GROUP | GROUP |
| 14.2.26 | UAT-9921 | New threat actor, UAT-9921, leverages VoidLink framework in campaigns | GROUP | GROUP |
| 11.2.26 | UNC1069 | UNC1069 Targets Cryptocurrency Sector with New Tooling and AI-Enabled Social Engineering | GROUP | GROUP |
| 10.2.26 | UNC3886 | Largest Multi-Agency Cyber Operation Mounted to Counter Threat Posed by Advanced Persistent Threat (APT) Actor UNC3886 to Singapore’s Telecommunications Sector | GROUP | GROUP |
| 9.2.26 | Stan Ghouls | Stan Ghouls targeting Russia and Uzbekistan with NetSupport RAT | GROUP | GROUP |
| 2.2.26 | UAT-8099 | Dissecting UAT-8099: New persistence mechanisms and regional focus | GROUP | GROUP |
| 25.1.26 | UAT-9686 | UAT-9686 actively targets Cisco Secure Email Gateway and Secure Email and Web Manager | GROUP | GROUP |
| 23.1.26 | Osiris Ransomware | Osiris Ransomware: New Addition to the Locky Family | RANSOM | RANSOM |
| 22.1.26 | PurpleBravo | PurpleBravo’s Targeting of the IT Software Supply Chain | GROUP | GROUP |
| 16.1.26 | UAT-8837 | UAT-8837 targets critical infrastructure sectors in North America | GROUP | GROUP |
| 8.1.26 | UAT-7290 | UAT-7290 targets high value telecommunications infrastructure in South Asia | GROUP | GROUP |
| 7.1.26 | UAC-0184 | UAC-0184 | GROUP | GROUP |