Group  Group

DATE

NAME

CATEGORY

SUBCATE

INFO

14.7.24

CRYSTALRAY GROUP GROUP CRYSTALRAY: Inside the Operations of a Rising Threat Actor Exploiting OSS Tools

30.6.24

Unfurling Hemlock GROUP GROUP Unfurling Hemlock: New threat group uses cluster bomb campaign to distribute malware

30.6.24

KADOKAWA GROUP GROUP Service Outages on Multiple Websites of the KADOKAWA Gro
27.6.24 ChamelGang Group Gang ChamelGang & Friends | Cyberespionage Groups Attacking Critical Infrastructure with Ransomware
26.6.24 FIN9 GROUP APTInside the DEA Tool Hackers Allegedly Used to Extort Targets
26.6.24 ExCobalt GROUP Cyber Gang ExCobalt: GoRed, the hidden-tunnel technique
19.6.24 UNC3886 GROUP CAMPAIGNCloaked and Covert: Uncovering UNC3886 Espionage Operations
14.6.24 UNC4899 GROUPGROUP Insights on Cyber Threats Targeting Users and Enterprises in Brazil
11.6.24 UNC5537 GROUPGROUP UNC5537 Targets Snowflake Customer Instances for Data Theft and Extortion
10.6.24 Sticky Werewolf GROUPGROUP Howling at the Inbox: Sticky Werewolf's Latest Malicious Aviation Attacks

7.6.24

GhostWriter

GROUP

GROUP

Ghostwriter is referred as an 'activity set', with various incidents tied together by overlapping behavioral characteristics and personas, rather than as an actor or group in itself.

7.6.24

Commando Cat

GROUP

Cryptojacking

Commando Cat: A Novel Cryptojacking Attack Abusing Docker Remote API Servers

3.6.24

Andariel

GROUP

APT

Analysis of APT Attack Cases Using Dora RAT Against Korean Companies (Andariel Group)

31.5.24

UAC-0006 GroupGroup UAC-0006 is a financially motivated threat actor that has been active since at least 2013. They primarily target Ukrainian organizations, particularly accountants, with phishing emails containing the SmokeLoader malware. Their goal is to steal credentials and execute unauthorized fund transfers, posing a significant risk to financial systems.

31.5.24

FlyingYeti GroupGroup Cloudforce One is publishing the results of our investigation and real-time effort to detect, deny, degrade, disrupt, and delay threat activity by the Russia-aligned threat actor FlyingYeti during their latest phishing campaign targeting Ukraine.

30.5.24

LilacSquid GroupGroup The stealthy trilogy of PurpleInk, InkBox and InkLoader

29.5.24

Moonstone Sleet GroupAPT Moonstone Sleet emerges as new North Korean threat actor with new bag of tricks

27.5.24

Storm-0539 GroupGroup Navigating cyberthreats and strengthening defenses in the era of AI

25.5.24

Space Pirates

Group

Group

Space Pirates: analyzing the tools and connections of a new hacker group

25.5.24

ShadowSyndicate

Group

Group

No sleep until the Cybercrime Fighters Club is done with finding the answer as to who is behind this new ransomware-as-a-service affiliate.

24.5.24

SHARP DRAGON

Group

APT 

SHARP DRAGON EXPANDS TOWARDS AFRICA AND THE CARIBBEAN

23.5.24

Unfading Sea Haze

Group

Group

Deep Dive Into Unfading Sea Haze: A New Threat Actor in the South China Sea

21.5.24

Void Manticore GroupGroup BAD KARMA, NO JUSTICE: VOID MANTICORE DESTRUCTIVE ACTIVITIES IN ISRAEL

21.5.24

GitCaught GroupGroup GitCaught: Threat Actor Leverages GitHub Repository for Malicious Infrastructure

18.5.24

Kinsing GroupHacking Kinsing Demystified A Comprehensive Technical Guide

16.5.24

Storm-1811 GroupGroup Threat actors misusing Quick Assist in social engineering attacks leading to ransomware
19.4.24 FIN7 GroupAPT Threat Group FIN7 Targets the U.S. Automotive Industry
16.4.24 Muddled Libra GroupGroup Muddled Libra also uses the legitimate scalability and native functionality of CSP services to create new resources to assist with data exfiltration. All CSPs have terms of service (TOS) policies that explicitly prohibit activities like those performed by Muddled Libra.
12.4.24 TA547 GroupGroup Security Brief: TA547 Targets German Organizations with Rhadamanthys Stealer

11.4.24

Virtual Invaders

Group

Group

There is no indication that this campaign is linked to any known group; however, we are tracking the threat actors behind it under the moniker Virtual Invaders.

9.4.24 Starry Addax GroupGroup Starry Addax targets human rights defenders in North Africa with new malware
5.4.24 UTA0178 GroupGroup While Volexity largely observed the attacker essentially living off the land, they still deployed a handful of malware files and tools during the course of the incident which primarily consisted of webshells, proxy utilities, and file modifications to allow credential harvesting.
5.4.24 CoralRaider GroupGroup CoralRaider targets victims’ data and social media accounts
2.4.24 Earth Freybug Group Group This article provides an in-depth look into two techniques used by Earth Freybug actors: dynamic-link library (DLL) hijacking and application programming interface (API) unhooking to prevent child processes from being monitored via a new malware we’ve discovered and dubbed UNAPIMON.
28.3.24 NARWHAL SPIDER Group APT NARWHAL SPIDER’s operation of Cutwail v2 was limited to country-specific spam campaigns, although late in 2019 there appeared to be an effort to expand by bringing in INDRIK SPIDER as a customer.
27.3.24 Earth Krahang Group APT Earth Krahang Exploits Intergovernmental Trust to Launch Cross-Government Attacks
27.3.24 Earth Lusca  Group APT Earth Lusca Uses Geopolitical Lure to Target Taiwan Before Elections
27.3.24 BRONZE VINEWOOD Group APT DETAILS ON BRONZE VINEWOOD, IMPLICATED IN TARGETING OF THE U.S. ELECTION CAMPAIGN
26.3.24 Lord Nemesis Strikes GroupHacktivism “Lord Nemesis Strikes: Supply Chain Attack on the Israeli Academic Sector
26.3.24 TA450 GroupAPT Security Brief: TA450 Uses Embedded Links in PDF Attachments in Latest Campaign
24.3.24 Springtail GroupAPT Springtail APT group abuses valid certificate of known Korean public entity
24.3.24 Kimsuky GroupAPT The Updated APT Playbook: Tales from the Kimsuky threat actor group
22.3.24 UNC302 GroupGroup BRONZE SPRING is a threat group that CTU researchers assess with high confidence operates on behalf of China in the theft of intellectual property from defense, engineering, pharmaceutical and technology companies
22.3.24 UNC3886 GroupGroup UNC3886 is an advanced cyber espionage group with unique capabilities in how they operate on-network as well as the tools they utilize in their campaigns. UNC3886 has been observed targeting firewall and virtualization technologies which lack EDR support.
22.3.24 UNC5221 GroupGroup While Volexity largely observed the attacker essentially living off the land, they still deployed a handful of malware files and tools during the course of the incident which primarily consisted of webshells, proxy utilities, and file modifications to allow credential harvesting.

20.3.24

Andariel

Group

Group

Andariel Group (MeshAgent) is attacking by abusing domestic asset management solutions

18.3.24

ITG05 

Group

Group

Ongoing ITG05 operations leverage evolving malware arsenal in global campaigns

14.3.24 APT-C-36 GroupAPT Since April 2018, an APT group (Blind Eagle, APT-C-36) suspected coming from South America carried out continuous targeted attacks against Colombian government institutions as well as important corporations in financial sector, petroleum industry, professional manufacturing, etc.
14.3.24 DarkCasino GroupAPT DarkCasino is an economically motivated APT group that targets online trading platforms, including cryptocurrencies, online casinos, network banks, and online credit platforms. They are skilled at stealing passwords to access victims' online accounts and have been active for over a year. DarkCasino exploits vulnerabilities, such as the WinRAR vulnerability CVE-2023-38831, to launch phishing attacks and steal online property.
11.3.24 BianLian GroupRansomware BianLian is a ransomware developer, deployer, and data extortion cybercriminal group that has targeted organizations in multiple U.S. critical infrastructure sectors since June 2022.
7.3.24 Evasive Panda GroupAPT Evasive Panda is an APT group that has been active since at least 2012, conducting cyberespionage targeting individuals, government institutions and organizations.
7.3.24 TA4903 GroupPhishing TA4903: Actor Spoofs U.S. Government, Small Businesses in Phishing, BEC Bids
7.3.24 8220 Mining Group Group Cryptocurrency Returned Libra, also known as 8220 Mining Group, is a cloud threat actor group that has been active since at least 2017. Tools commonly employed during their operations are PwnRig or DBUsed which are customized variants of the XMRig Monero mining software.
6.3.24 GhostSec Group Ransomware GhostSec is a hacktivist group that emerged as an offshoot of Anonymous. They primarily focused on counterterrorism efforts and monitoring online activities associated with terrorism. They gained prominence following the 2015 Charlie Hebdo shooting in Paris and the rise of ISIS.
6.3.24 UNC1945 GroupAPT UNC1945 is an APT group that has been targeting telecommunications companies globally. They use Linux-based implants to maintain long-term access in compromised networks. UNC1945 has demonstrated advanced technical abilities, utilizing various tools and techniques to evade detection and move laterally through networks.
6.3.24 APT32 GroupAPT Cyber espionage actors, now designated by FireEye as APT32 (OceanLotus Group), are carrying out intrusions into private sector companies across multiple industries and have also targeted foreign governments, dissidents, and journalists. FireEye assesses that APT32 leverages a unique suite of fully-featured malware, in conjunction with commercially-available tools, to conduct targeted operations that are aligned with Vietnamese state interests.
6.3.24 Kimsuky GroupAPT JOINT CYBERSECURITY ADVISORY North Korean Advanced Persistent Threat Focus: Kimsuky
5.3.24 TA577 GroupGroup TA577’s Unusual Attack Chain Leads to NTLM Data Theft
2.3.24 Scattered Spider GroupHacking Scattered Spider, a highly active hacking group, has made headlines by targeting more than 130 organizations, with the number of victims steadily increasing.
2.3.24 BlackTech GroupCyberSpy BlackTech is a cyber espionage group operating against targets in East Asia, particularly Taiwan, and occasionally, Japan and Hong Kong. Based on the mutexes and domain names of some of their C&C servers, BlackTech’s campaigns are likely designed to steal their target’s technology.
2.3.24 Peach Sandstorm GroupAPT Our analysis reveals that APT33 is a capable group that has carried out cyber espionage operations since at least 2013. We assess APT33 works at the behest of the Iranian government.
2.3.24 LightBasin GroupAPT UNC1945 is an APT group that has been targeting telecommunications companies globally. They use Linux-based implants to maintain long-term access in compromised networks.
1.3.24 UNC1549 BigBrother CyberSpyWhen Cats Fly: Suspected Iranian Threat Actor UNC1549 Targets Israeli and Middle East Aerospace and Defense Sectors
1.3.24 UNC3886 GroupGroup UNC3886 is an advanced cyber espionage group with unique capabilities in how they operate on-network as well as the tools they utilize in their campaigns. UNC3886 has been observed targeting firewall and virtualization technologies which lack EDR support.
1.3.24 Tortoiseshell GroupGroup A previously undocumented attack group is using both custom and off-the-shelf malware to target IT providers in Saudi Arabia in what appear to be supply chain attacks with the end goal of compromising the IT providers’ customers. The group, which we are calling Tortoiseshell, has been active since at least July 2018.
1.3.24 Bohrium GroupGroup Bohrium is an Iranian threat actor that has been involved in spear-phishing operations targeting organizations in the US, Middle East, and India.
19.2.24 TAG-70 GroupGroup Russia-Aligned TAG-70 Targets European Government and Military Mail Servers in New Espionage Campaign

6.2.24

GambleForce

Group

Group

Analysis of TTPs tied to GambleForce, which carried out SQL injection attacks against companies in the APAC region

3.2.24

COLDRIVER GroupGroup The Coldriver Group, also known as Callisto and SEABORGIUM, is a threat actor known to attack government organizations, think tanks, and journalists in Europe and the Caucasus regions through spearphishing campaigns.

3.2.24

Shuckworm GroupGroup Shuckworm: Inside Russia’s Relentless Cyber Campaign Against Ukraine

3.2.24

LitterDrifter GroupGroup Malware Spotlight – Into the Trash: Analyzing LitterDrifter

3.2.24

UAC-0027 GroupGroup UAC-0027 Attack Detection: Hackers Target Ukrainian Organizations Using DIRTYMOE (PURPLEFOX) Malware

2.2.24

UNC5221 GroupCyberSpy UNC5221: Unreported and Undetected WIREFIRE Web Shell Variant

2.2.24

Volt Typhoon GroupGroup [Microsoft] Volt Typhoon, a state-sponsored actor based in China that typically focuses on espionage and information gathering. Microsoft assesses with moderate confidence that this Volt Typhoon campaign is pursuing development of capabilities that could disrupt critical communications infrastructure between the United States and Asia region during future crises.

1.2.24

UNC4990 GroupGroup Evolution of UNC4990: Uncovering USB Malware's Hidden Depths

19.1.24

COLDRIVER GroupGroup Russian threat group COLDRIVER expands its targeting of Western officials to include the use of malware