Campaign 2026(5) 2025(58) 2024(58) 2023(1) 2022(0)
DATE |
NAME |
INFO |
CATEGORY |
SUBCATE |
|
21.9.26 |
Codex ClickFix Campaign | When Trust Becomes the Payload in a Fake Codex ClickFix Campaign | CAMPAIGN | CAMPAIGN |
|
16.9.26 |
GhostCode | In late August 2026, eSentire's Threat Response Unit (TRU) identified an active device code phishing campaign distributed through web contact forms. In the campaign, threat actors posed as a procurement officer of a legitimate business. TRU is tracking the device code phishing kit used in the campaign as "GhostCode". | CAMPAIGN | CAMPAIGN |
|
16.9.26 |
Smish | A widespread smishing campaign was identified in which victims received fraudulent SMS messages impersonating official entities and were instructed to click a link inside the SMS in order to “complete a verification“, “settle an outstanding fee”, or “re-confirm delivery details”. | CAMPAIGN | CAMPAIGN |
|
12.9.26 |
ShadowPane | ZeroBEC uncovered a phishing campaign we track as ShadowPane that uses browser-in-the-browser deception to make malicious RMM installations appear to originate from Adobe. | CAMPAIGN | CAMPAIGN |
|
7.9.26 |
SourTrade | SourTrade: Browser-Assembled Malware Delivered Through Malvertising | CAMPAIGN | CAMPAIGN |
| 26.8.26 | Vercel-hosted RMM attacks | As ANY.RUN analysis shows, a campaign that initially appears to target Canadians with fake Canada Revenue Agency (CRA) T4 tax documents is actually part of a much broader remote-access campaign spanning 46 countries, with 45% of observed activity associated with the United States. | CAMPAIGN | CAMPAIGN |
| 26.8.26 | Disrupting a new covert influence campaign from Russia | Our mission is to ensure that artificial general intelligence benefits all of humanity. We advance this mission by deploying our innovations to build AI tools that help people solve hard problems. This includes building tools that enable us to detect, investigate, disrupt and expose covert influence operations (IO): deceptive attempts to manipulate public opinion or influence political outcomes without revealing the true identity or intentions of the actors behind them. | CAMPAIGN | CAMPAIGN |
| 24.8.26 | ClearFake | ClearFake gets more evasive with new living off the land (LOTL) techniques | CAMPAIGN | CAMPAIGN |
|
8.8.26 |
Flooding Dropper | 'Flooding Dropper' Campaign Hits npm With Nearly 850 Malicious Packages | CAMPAIGN | CAMPAIGN |
|
7.8.26 |
Payroll Pirates | Payroll Pirates: Strange New Tides in Business Email Compromise | CAMPAIGN | CAMPAIGN |
|
7.8.26 |
ChainDrop | ChainDrop: When Opening a Repository Becomes Execution | CAMPAIGN | CAMPAIGN |
|
7.8.26 |
ShadowRay 2.0 | New Intelligence Links TeamPCP to ShadowRay 2.0 and Traces Activity back to 2020 | CAMPAIGN | CAMPAIGN |
|
6.8.26 |
macOS ClickFix campaign | From open lures to cloaked gates: How a macOS ClickFix campaign learned to hide | CAMPAIGN | CAMPAIGN |
|
5.8.26 |
keyv and cacheable compromise | On August 4, 2026, a threat actor compromised the source or release credentials for the widely used keyv and cacheable npm packages and published trojanized versions of at least ten packages, beginning with keyv@6.0.0 at 09:35 UTC. Unlike a typical dependency swap, each version carries a malicious preinstall hook (setup.mjs) that downloads a standalone Bun runtime and executes an obfuscated ~728 KB second stage (Math_Symbol.js). | CAMPAIGN | CAMPAIGN |
|
5.8.26 |
QuickFox | QuickFox Supply Chain Attack Used to Deploy FDMTP Implant | CAMPAIGN | CAMPAIGN |
|
4.8.26 |
Powercat malware campaign | Powercat malware campaign: Fake game cheats deliver infostealer | CAMPAIGN | CAMPAIGN |
|
4.8.26 |
SMOKE#SCREEN | Analyzing SMOKE#SCREEN: ScreenConnect RMM Abuse, Cloudflare Tunnels, and Trusted Software Lures | CAMPAIGN | CAMPAIGN |
|
3.8.26 |
ExfilSquad | ExfilSquad Targets Misconfigured Microsoft Power Pages Portals | CAMPAIGN | CAMPAIGN |
|
1.8.26 |
CaptiveCrunch | CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft | CAMPAIGN | CAMPAIGN |
|
27.7.26 |
Targeted Attack on Government Entities in the Middle East | Part 1 |
|||
|
26.7.26 |
SourTrade Ad Campaigns | SourTrade: Browser-Assembled Malware Delivered Through Malvertising | CAMPAIGN | CAMPAIGN |
|
23.7.26 |
FakeGit campaign | AI-Assisted Fake GitHub Repositories Fuel SmartLoader and LummaStealer Distribution | CAMPAIGN | CAMPAIGN |
|
23.7.26 |
Large-Scale campaigne | Large-Scale GitHub Actions Abuse Powers a Distributed cPanel and WHM Exploitation Campaign | CAMPAIGN | CAMPAIGN |
|
20.7.26 |
Patriot Bait | One Man, One AI, One Fake Persona: Inside the 5-Year Influence and Fraud ‘Patriot Bait’ Campaign | CAMPAIGN | CAMPAIGN |
|
18.7.26 |
HelloNet campaign | We identified targeted infection attempts against large Russian organizations using the ViPNet update system (a software suite for creating secure networks). | CAMPAIGN | CAMPAIGN |
|
18.7.26 |
PhantomGate Campaign | The PhantomGate Campaign — Obfuscation, Persistence, and Covert Surveillance | CAMPAIGN | CAMPAIGN |
| 17.7.26 | EVALUSION | EVALUSION Campaign Delivers Amatera Stealer and NetSupport RAT | CAMPAIGN | CAMPAIGN |
| 17.7.26 | TetrisPhantom | Kaspersky uncovers APT campaign targeting APAC government entities | CAMPAIGN | CAMPAIGN |
| 13.7.26 | codemado | One Misconfigured Server, Three Active Campaigns: Full exposure of three AiTM Phishing Operators | CAMPAIGN | CAMPAIGN |
| 13.7.26 | mail-argenta | One Misconfigured Server, Three Active Campaigns: Full exposure of three AiTM Phishing Operators | CAMPAIGN | CAMPAIGN |
| 13.7.26 | saroula01 | One Misconfigured Server, Three Active Campaigns: Full exposure of three AiTM Phishing Operators | CAMPAIGN | CAMPAIGN |
| 13.7.26 | GPPStorm | GPPStorm: Fake Google Partner Invitations Target Workspace Credentials | CAMPAIGN | CAMPAIGN |
| 9.7.26 | LapDogs Campaign | Unmasking A New China-Linked Covert ORB Network: Inside the LapDogs Campaign | CAMPAIGN | CAMPAIGN |
| 8.7.26 | Rogue Agent | Rogue Agent: How a Single Code Block Could Hijack Your AI Conversations in Google’s DialogFlow | CAMPAIGN | CAMPAIGN |
| 5.7.26 | PolinRider | PolinRider: North Korea-Linked Supply Chain Campaign Expands Across Open Source Ecosystems | CAMPAIGN | CAMPAIGN |
| 1.7.26 | LSHIY CAMPAIGN | No (Bad) CAP: Inside an Ongoing LSHIY Password Spray Attack | CAMPAIGN | CAMPAIGN |
| 29.6.26 | StegoAd | Inside StegoAd: How We Disrupted a Massive Malicious Extension Campaign | CAMPAIGN | CAMPAIGN |
| 27.6.26 | Photo ZIP campaign | Photo ZIP campaign targeting hospitality industry delivers Node.js implant for persistent access | CAMPAIGN | CAMPAIGN |
| 19.6.26 | FortiBleed | FortiBleed: 75,000 Fortinet Firewalls Compromised: Global Enterprises Exposed – Claim Your Ethical Disclosure | CAMPAIGN | CAMPAIGN |
| 17.6.26 | easy-day-js: Supply Chain Campaign | easy-day-js: Supply Chain Campaign Targets Mastra npm Packages | CAMPAIGN | CAMPAIGN |
| 16.6.26 | UNK_DeadDrop | Don't Fear the Repo: UNK_DeadDrop Phishing Campaign Targets Developers to Steal Cryptocurrency | CAMPAIGN | CAMPAIGN |
| 15.6.26 | Sniper’s Nest | Sniper’s Nest: From Brand Impersonation to Browser Hijacking and CPA Fraud | CAMPAIGN | CAMPAIGN |
|
13.6.26 |
Atomic Arch | Atomic Arch: Attackers Hijack Trusted AUR Packages to Deliver Rootkit-Like Malware | CAMPAIGN | CAMPAIGN |
| 9.6.26 | Miasma Worm Campaign | Shai-Hulud Descends to Hades: Miasma Worm Campaign Spreads with New PyPI Wave | CAMPAIGN | CAMPAIGN |
| 6.6.26 | Miasma credential-stealing campaign | Microsoft Threat Intelligence identified a large-scale npm supply chain attack affecting 32 maliciously modified packages across more than 90 versions under the @redhat-cloud-services npm scope. | CAMPAIGN | CAMPAIGN |
| 5.6.26 | GHOST STADIUM | The GHOST STADIUM Score: Billions At Stake At The World’s Largest Football Tournament | CAMPAIGN | CAMPAIGN |
| 3.6.26 | Game Over: WeedHack | Game Over: WeedHack – The Rise of Minecraft Malware-as-a-Service Campaigns | CAMPAIGN | CAMPAIGN |
| 23.5.26 | Megalodon | Megalodon: Mass GitHub Repo Backdooring via CI Workflows | CAMPAIGN | CAMPAIGN |
| 13.5.26 | GemStuffer Campaign | GemStuffer Campaign Abuses RubyGems as Exfiltration Channel Targeting UK Local Government | CAMPAIGN | CAMPAIGN |
| 5.5.26 | Multi-stage ‘code of conduct’ phishing campaign leads to AiTM token compromise | Phishing campaigns continue to improve sophistication and refinement in blending social engineering, delivery and hosting infrastructure, and authentication abuse to remain effective against evolving security controls. | CAMPAIGN | CAMPAIGN |
| 5.5.26 | VENOMOUS#HELPER | You’re invited: Four phishing lures in campaigns dropping RMM tools | CAMPAIGN | CAMPAIGN |
| 2.5.26 | Snow Flurries | Snow Flurries: How UNC6692 Employed Social Engineering to Deploy a Custom Malware Suite | CAMPAIGN | CAMPAIGN |
| 10.4.26 | Rotten Apple | Rotten Apple: An Invasive Threat Actor Targeting Civil Society in Lebanon | CAMPAIGN | CAMPAIGN |
| 10.4.26 | Pawn Storm Campaign | Pawn Storm Campaign Deploys PRISMEX, Targets Government and Critical Infrastructure Entities | CAMPAIGN | CAMPAIGN |
| 8.4.26 | Internet-exposed ComfyUI instances | Hackers Are Attempting to Turn ComfyUI Servers Into a Cryptomining Proxy Botnet | CAMPAIGN | CAMPAIGN |
| 8.4.26 | Iran-nexus Password Spray Campaign Targeting Cloud Environments | Iran-nexus Password Spray Campaign Targeting Cloud Environments, with a Focus on the Middle East | CAMPAIGN | CAMPAIGN |
| 8.4.26 | DPRK-Related Campaigns with LNK and GitHub C2 | How DPRK actors use LNK files and GitHub C2 to evade detection and maintain persistence | CAMPAIGN | CAMPAIGN |
| 1.4.26 | WhatsApp malware campaign | WhatsApp malware campaign delivers VBScript and MSI backdoors | CAMPAIGN | CAMPAIGN |
| 1.4.26 | Augmented Marauder’s Multi-Pronged Casbaneiro Campaigns | Unpacking Augmented Marauder’s Multi-Pronged Casbaneiro Campaigns | CAMPAIGN | CAMPAIGN |
|
25.3.26 |
Analyzing FAUX#ELEVATE: Threat Actors Target France with CV Lures to Deploy Crypto miners and Infostealers Targeting Enterprise Environments |
|||
| 17.3.26 | ForceMemo | ForceMemo: Hundreds of GitHub Python Repos Compromised via Account Takeover and Force-Push | CAMPAIGN | CAMPAIGN |
| 17.3.26 | KakaoTalk | Analysis of the Spear-Phishing and KakaoTalk-Linked Threat Campaign by the Konni Group | CAMPAIGN | CAMPAIGN |
| 2.3.26 | StegaBin | Novel DPRK stager using Pastebin and text steganography | CAMPAIGN | CAMPAIGN |
| 26.2.26 | GRIDTIDE | GRIDTIDE Global Cyber Espionage Campaign | CAMPAIGN | CAMPAIGN |
| 24.2.26 | Monero Mining Campaign | Technical Deep Dive: The Monero Mining Campaign | CAMPAIGN | CAMPAIGN |
| 21.2.26 | Monero Mining Campaign | In the contemporary threat landscape, while ransomware grabs headlines with high-impact disruptions, cryptojacking operations have quietly evolved into sophisticated, persistent threats. | CAMPAIGN | CAMPAIGN |
| 20.2.26 | AiFrame | “AiFrame”- Fake AI Assistant Extensions Targeting 260,000 Chrome Users via injected iframes | CAMPAIGN | CAMPAIGN |
| 19.2.26 | Massiv | Massiv: When your IPTV app terminates your savings | CAMPAIGN | CAMPAIGN |
| 19.2.26 | CRESCENTHARVEST | CRESCENTHARVEST: Iranian protestors and dissidents targeted in cyberespionage campaign | CAMPAIGN | CAMPAIGN |
| 13.2.26 | Fake recruiter campaign | A new branch of a fake job recruitment campaign, dubbed "graphalgo," is targeting developers with a RAT. | CAMPAIGN | CAMPAIGN |
|
11.2.26 |
SideCopy Launch Cross-Platform RAT Campaigns | Espionage Without Noise: Understanding APT36’s Enduring Campaigns | CAMPAIGN | CAMPAIGN |
| 9.2.26 | TeamPCP | Threat Alert: TeamPCP, An Emerging Force in the Cloud Native and Ransomware Landscape | CAMPAIGN | CAMPAIGN |
| 6.2.26 | Shadow Campaigns | The Shadow Campaigns: Uncovering Global Espionage | CAMPAIGN | CAMPAIGN |
| 5.2.26 | NGINX Configurations Enable Large-Scale Web Traffic Hijacking Campaign | Web Traffic Hijacking: When Your Nginx Configuration Turns Malicious | CAMPAIGN | CAMPAIGN |
| 5.2.26 | Dead#Vax | Analyzing Dead#Vax: Analyzing Multi-Stage VHD Delivery and Self-Parsing Batch Scripts to Deploy In-Memory Shellcode | CAMPAIGN | CAMPAIGN |
| 2.2.26 | RedKitten | RedKitten: AI-accelerated campaign targeting Iranian protests | CAMPAIGN | CAMPAIGN |
| 2.2.26 | ShinyHunters | Vishing for Access: Tracking the Expansion of ShinyHunters-Branded SaaS Data Theft | CAMPAIGN | CAMPAIGN |
| 27.1.26 | SyncFuture Espionage Targeted Campaign | Weaponized in China, Deployed in India: The SyncFuture Espionage Targeted Campaign | CAMPAIGN | CAMPAIGN |
| 26.1.26 | AI-orchestrated cyber espionage campaign | We have developed sophisticated safety and security measures to prevent the misuse of our AI models. | CAMPAIGN | CAMPAIGN |
| 25.1.26 | doxxing campaign | Shifts in the Underground: The Impact of Water Kurita’s (Lumma Stealer) Doxxing | CAMPAIGN | CAMPAIGN |
| 25.1.26 | GhostPoster Campaign | Browser Extensions Gone Rogue: The Full Scope of the GhostPoster Campaign | CAMPAIGN | CAMPAIGN |
| 22.1.26 | Fortinet FortiGate Devices via SSO Accounts | Arctic Wolf has observed a new cluster of automated malicious activity involving unauthorized firewall configuration changes on FortiGate devices. | CAMPAIGN | CAMPAIGN |
| 21.1.26 | Campaign Targeting LastPass Customers | New Phishing Campaign Targeting LastPass Customers | CAMPAIGN | PHISHING |
| 21.1.26 | Contagious Interview campaign | Threat Actors Expand Abuse of Microsoft Visual Studio Code | CAMPAIGN | CAMPAIGN |
| 14.1.26 | SHADOW#REACTOR | SHADOW#REACTOR – Text-Only Staging, .NET Reactor, and In-Memory Remcos RAT Deployment | CAMPAIGN | CAMPAIGN |
| 8.1.26 | Boto-Cor-de-Rosa | Boto-Cor-de-Rosa campaign reveals Astaroth WhatsApp-based worm activity in Brazil | CAMPAIGN | CAMPAIGN |