Operation 2026()  2025()  2024()  2023()  2022()  OTHER()  ALL(211) |

DATE

NAME

INFO

CATEGORY

SUBCATE

23.9.26

Operation Conflict Compass Since 2009, the Democratic People’s Republic of Korea (DPRK) has fully integrated cyber operations into its national strategy, leveraging state-nexus threat groups to execute cyberespionage, conduct sabotage and influence operations, and generate revenue for state-sponsored nuclear weapons programs. OPERATION OPERATION

22.9.26

Clop Hack ShinyHunters has turned the tables on rival cybercrime operation Clop (a.k.a. Cl0p), hijacking and defacing the ransomware gang’s own Dark Web leak site (DLS) OPERATION OPERATION

19.9.26

Operation RapidRust In August 2026, Zscaler ThreatLabz observed new activity by the Pakistan-nexus threat actor APT36 in a campaign we’re tracking as Operation RapidRust. Since our last publication about the group’s activity in January 2026, APT36 has maintained a high operational tempo and updated their tactics, techniques, and procedures (TTPs) in continued attacks targeting government and defense organizations in India and Afghanistan. OPERATION OPERATION

19.9.26

Operation RapidRust In August 2026, Zscaler ThreatLabz observed new activity by the Pakistan-nexus threat actor APT36 in a campaign we’re tracking as Operation RapidRust. Since our last publication about the group’s activity in January 2026, APT36 has maintained a high operational tempo and updated their tactics, techniques, and procedures (TTPs) in continued attacks targeting government and defense organizations in India and Afghanistan. OPERATION OPERATION

8.9.26

BigBear 2.0 CloudSEK researchers uncovered BigBear 2.0, a global Microsoft 365 phishing-as-a-service operation targeting hundreds of organizations across 40+ countries. OPERATION OPERATION

8.9.26

BengalSEO BengalSEO Part 1: Anatomy of the Operation OPERATION OPERATION

4.9.26

Still Circling This is a collaborative follow-up to our original post, developed jointly with Emmanuel C., a security researcher not affiliated with LevelBlue, who contributed additional infrastructure and tooling findings based on an analysis of the same GitHub staging account. OPERATION OPERATION

2.9.26

Plump Spider's Operations New Details on Plump Spider's Operations in Pix Fraud Schemes OPERATION OPERATION
27.8.26 Tortoiseshell Tortoiseshell: New Toolset and Operational Infrastructure Exposed OPERATION OPERATION
21.8.26 Operation QUICSILVER OPERATION OPERATION OPERATION

19.8.26

Operation CameraSwarm Operation CameraSwarm: Over 14,000 Dahua cameras compromised across Ukraine and Russia OPERATION OPERATION

18.8.26

Operation ASTERIX Operation ASTERIX: Anatomy of a Crypto Fraud Pipeline OPERATION OPERATION

10.8.26

Operation Capsule Vault Operation Capsule Vault: RokRAT Attack Chain Analysis Using EMBED_PAYLOAD_v2 OPERATION OPERATION

30.7.26

Operation Double Barrel This technical analysis report was prepared as part of the joint cybersecurity advisory titled “Advisory on Cyberattacks Targeting Korean Citizens and Businesses by State-Sponsored Hacking Groups,” issued by the Republic of Korea’s National Intelligence Service (NIS), National Police Agency (NPA), Korea Internet & Security Agency (KISA), and Financial Security Institute (FSI). OPERATION OPERATION

27.7.26

Operation BlueDash Operation BlueDash: Multi-RMM Workplace Phishing OPERATION OPERATION

27.7.26

[Op Report] From SSA Phish to AdaptixC2: A Multi-RAT Intrusion Over five days in mid-May 2026, an operator engaged a deception workstation in the Deception.Pro environment and executed a near-complete commodity intrusion chain from initial access through domain reconnaissance. OPERATION OPERATION

23.7.26

JadeProx JadeProx: Tracing a China-nexus Operation Through an OPSEC Mistake OPERATION OPERATION

23.7.26

Operation Muck and Load Malicious Go Module Exposes GitHub Malware Lure Network Spanning 222 Repositories OPERATION OPERATION

18.7.26

Operation Henhouse Operation Henhouse: Hundreds of arrests and millions in assets seized in month tackling fraud OPERATION OPERATION

18.7.26

Operation ShadowRecruit Contents Introduction Key Targets Industries Affected Geographical focus Infection Chain Initial Findings Looking into the Decoy Document Technical Analysis Stage 1 – Initial Infection through LNK file Stage 2 – PowerShell Downloader Analysis Stage 3 – The .NET Dropper...

OPERATION

OPERATION

17.7.26

Operation Dragon Breath

Since 2015, Qi An Xin Threat Intelligence Center has been closely monitoring the gambling and fraud industries in East Asia and Southeast Asia. In 2020, we published "A Glimpse into the Southeast Asian Gambling Industry: A Look at the Black Market"  , which provided a general analysis of the background and environment of the gambling industry.

OPERATION

OPERATION

5.7.26 Operation Navy Ghost Operation Navy Ghost: How Attackers Planted a Telegram-Powered Backdoor Across Fake pyrogram Packages on PyPI OPERATION OPERATION
5.7.26 Operation Contagious Interview The most effective social engineering campaigns don’t rely on obvious red flags or technical exploits. They move through familiar business interactions, like hiring conversations, project discussions, and routine follow-ups that are designed to feel legitimate from the start. OPERATION OPERATION
4.7.26 Operation DragonReturn Authors: Dixit Panchal & Soumen Burma Table of Contents: Introduction: Key Targets: Infection Chain: Initial Findings about Campaign: Initial Mail: Email Attachment: Lure: Official GoI, Income Tax Document: Technical Analysis: Infrastructural Artefacts & Threat actor Attributions. Campaign Timeline. OPERATION OPERATION
27.6.26 Operation DragonReturn Authors: Dixit Panchal & Soumen Burma Table of Contents: Introduction: Key Targets: Infection Chain: Initial Findings about Campaign: Initial Mail: Email Attachment: Lure: Official GoI, Income Tax Document: Technical Analysis: Infrastructural Artefacts & Threat actor Attributions. Campaign Timeline. Conclusion:... OPERATION OPERATION
24.6.26 Dismantling FortiBleed Inside a Russian Fortinet compromise operation. OPERATION OPERATION
20.6.26 Operation FanTrap Operation FanTrap reveals FIFA 2026 fraud ecosystem with 4,000+ fake domains, phishing, streaming scams, and dark web-driven cybercrime activity. OPERATION OPERATION
18.6.26 Operation Poisson Cato CTRL™ Threat Research: Operation Poisson – Analyzing a Cybercriminal’s Entire Operation OPERATION OPERATION

13.6.26

Operation Highland

Velvet Ant’s Operation Highland: How a China-Nexus Actor Infiltrated an Internal Network Undetected

OPERATION

OPERATION

12.6.26 Phantom Mantis Operation Phantom Mantis, initially known as ArmCorp, is a financially motivated threat group active since March 2025. The group conducts intrusions for extortion and is led by a Russian-speaking criminal tracked as LARVA-368. OPERATION OPERATION
4.6.26 Operation FlutterBridge Operation FlutterBridge: macOS Malvertising Campaign Spreads New FlutterShell Backdoor OPERATION OPERATION
30.5.26 Operation Dragon Weave Contents Introduction Key Targets Industries Affected Geographical focus Infection Chain Initial Findings Looking into the Decoy Document Technical Analysis Stage 1 – Initial Delivery Path A: LNK-Based Execution Path B: Executable-Based Delivery Stage 2 – Script-Based Dropper Chain Stage... OPERATION OPERATION
30.5.26 Operation XENOFISCAL Authors: Dixit Panchal & Vaibhav Krushna Billade Table of Contents: Introduction: Key Targets: Infection Chain: Initial Findings about Campaign: Analysis of Decoy: Technical Analysis: Stage 1: Analysis of LNK File. Stage 2: Analysis of HTA/JavaScript Payload Stage 3: Analysis... OPERATION OPERATION
26.5.26 Nimbus Manticore Operations The Iranian, IRGC affiliated, threat actor Nimbus Manticore resurfaced during Operation Epic Fury, the US military campaign against Iran launched on February 28, 2026, demonstrating newly adopted techniques and enhanced capabilities. OPERATION OPERATIONS
23.5.26 Operation Dragon Whistle Table of Contents: Introduction: Key Targets: Infection Chain: Initial Findings about Campaign: Analysis of Decoys & Spear phishing Email: Technical Analysis: Stage1: Analysis of LNK File. Stage2: Analysis of VBS. Stage3: DLL Side Loading. Infrastructural Artefacts & Threat actor... OPERATION OPERATION
13.5.26 Operation NoVoice Operation NoVoice: Android Malware Found in 50+ Apps Can Hijack Devices OPERATION OPERATION
9.5.26 Operation GriefLure Table of Contents: Introduction: Key Targets: Infection Chain: Initial Findings about Campaign: Analysis of Decoys: Technical Analysis: Campaign-1: Stage-1: Ho so.rar Campaign: 2 Stage-1: download.zip Stage-2: The LNK & Batch file (Common in 1 & 2 both) Stage-3: Analysis OPERATION OPERATION
9.5.26 Operation Silent Rotor Operation Silent Rotor: Targeted Campaign Compromises Unmanned Aviation Sector Ahead of Moscow Summit Table of Content Introduction Key Targets Industries Affected Geographical focus Infection Chain Initial Findings Looking into the Decoy Documents Technical Analysis Stage 1 – Analysis of... OPERATION OPERATION
9.5.26 Operation HumanitarianBait Cyble analyzes Operation HumanitarianBait, a stealthy espionage campaign using aid-themed lures to deploy a fileless Python infostealer. OPERATION OPERATION
6.5.26 Iranian-Nexus Operation Iranian-Nexus Operation Against Oman's Government: 12 Ministries Hit and 26,000 Citizen Records Exposed OPERATION OPERATION
25.4.26 Operation TrustTrap CRIL uncovered 16,800+ spoofed domains by analyzing URL trust abuse, cloud infra clustering, and human‑centric deception instead of technical exploits. OPERATION OPERATION
5.4.26 Operation NoVoice Operation NoVoice: Rootkit Tells No Tales OPERATION OPERATION
4.4.26 Operation TrueChaos: 0-Day Exploitation Against Southeast Asian Government Targets Check Point Research identified a zero-day vulnerability in the TrueConf client application, tracked as CVE-2026-3502, with a CVSS score of 7.8. The flaw stems from the abuse of TrueConf’s updater validation mechanism, allowing an attacker who controls the on-premises TrueConf server to distribute and execute arbitrary files across all connected endpoints. OPERATION OPERATION
4.4.26 Operation DualScript – A Multi-Stage PowerShell Malware Campaign Targeting Cryptocurrency and Financial Activity Operation DualScript – A Multi-Stage PowerShell Malware Campaign Targeting Cryptocurrency and Financial Activity Introduction During our investigation, we identified a multi-stage malware infection leveraging Scheduled Task persistence, VBScript launchers, and PowerShell-based execution. The attack operates through two parallel chains:... OPERATION OPERATION
3.4.26 Multi-Tool Mining Operation Fake Installers to Monero: A Multi-Tool Mining Operation OPERATION OPERATION
21.3.26 Operation GhostMail Contents Introduction Key Targets Industries Affected Geographical focus Geopolitical Context Infection Chain Timeline of Activity Initial Findings Looking into the Decoy Documents Technical Analysis Stage 1 – Malicious Archive Delivery Stage 2 – Malicious Shortcut Execution Stage 3 OPERATION OPERATION
18.3.26 LeakNet’s Casting a Wider Net: ClickFix, Deno, and LeakNet’s Scaling Threat OPERATION OPERATION
14.3.26 Operation CamelClone: Multi-Region Espionage Campaign Targets Government and Defense Entities Amidst Regional Tensions Contents Introduction Key Targets Industries Affected Geographical focus Geopolitical Context Infection Chain Timeline of Activity Initial Findings Looking into the Decoy Documents Technical Analysis Stage 1 – Malicious Archive Delivery Stage 2 – Malicious Shortcut Execution Stage 3 OPERATION OPERATION
5.3.26 Operation Epic Fury/Roaring Lion Retaliatory Hacktivist DDoS Activity Following Operation Epic Fury/Roaring Lion OPERATION OPERATION
24.2.26 Operation MacroMaze Operation MacroMaze: new APT28 campaign using basic tooling and legit infrastructure OPERATION OPERATION
23.2.26 Operation Olalampo MuddyWater APT has launched a new cyber offensive operation, dubbed Operation Olalampo, deploying new malware variants and leveraging Telegram bots for command-and-control. OPERATION OPERATION
3.2.26 Operation Neusploit APT28 Leverages CVE-2026-21509 in Operation Neusploit OPERATION OPERATION
24.1.26 Operation DupeHike Contents Introduction Key Targets. Industries Affected. Geographical Focus. Infection Chain. Initial Findings. Looking into the decoy-document Technical Analysis Stage 1 – Malicious LNK Script Stage 2 – DUPERUNNER Implant Stage 3 – AdaptixC2 Beacon. Infrastructural Artefacts. Conclusion SEQRITE Protection.... OPERATION OPERATION
24.1.26 Operation Covert Access Table of Contents: Introduction: Infection Chain: Targeted sectors: Initial Findings about Campaign: Analysis of Decoy: Technical Analysis: Stage-1: Analysis of Windows Shortcut file (.LNK). Stage-2: Analysis of Batch file. Stage-3: Details analysis of Covert RAT. Conclusion: Seqrite Coverage: IOCs... OPERATION OPERATION
24.1.26 Operation Nomad Leopard Contents Introduction Key Targets Industries Affected Geographical focus Infection Chain. Initial Findings Looking into the decoy-document Technical Analysis Stage 1 – Malicious ISO File Stage 2 – Malicious LNK File Stage 3 – Final Payload: FALSECUB Infrastructure & Attribution... OPERATION OPERATION
19.1.26 Operation Poseidon Operation Poseidon: Spear-Phishing Attacks Abusing Google Ads Redirection Mechanisms OPERATION OPERATION