Operation 2026() 2025() 2024() 2023() 2022() OTHER() ALL(211) |
|
DATE |
NAME |
INFO |
CATEGORY |
SUBCATE |
|
23.9.26 |
Operation Conflict Compass | Since 2009, the Democratic People’s Republic of Korea (DPRK) has fully integrated cyber operations into its national strategy, leveraging state-nexus threat groups to execute cyberespionage, conduct sabotage and influence operations, and generate revenue for state-sponsored nuclear weapons programs. | OPERATION | OPERATION |
|
22.9.26 |
Clop Hack | ShinyHunters has turned the tables on rival cybercrime operation Clop (a.k.a. Cl0p), hijacking and defacing the ransomware gang’s own Dark Web leak site (DLS) | OPERATION | OPERATION |
|
19.9.26 |
Operation RapidRust | In August 2026, Zscaler ThreatLabz observed new activity by the Pakistan-nexus threat actor APT36 in a campaign we’re tracking as Operation RapidRust. Since our last publication about the group’s activity in January 2026, APT36 has maintained a high operational tempo and updated their tactics, techniques, and procedures (TTPs) in continued attacks targeting government and defense organizations in India and Afghanistan. | OPERATION | OPERATION |
|
19.9.26 |
Operation RapidRust | In August 2026, Zscaler ThreatLabz observed new activity by the Pakistan-nexus threat actor APT36 in a campaign we’re tracking as Operation RapidRust. Since our last publication about the group’s activity in January 2026, APT36 has maintained a high operational tempo and updated their tactics, techniques, and procedures (TTPs) in continued attacks targeting government and defense organizations in India and Afghanistan. | OPERATION | OPERATION |
|
8.9.26 |
BigBear 2.0 | CloudSEK researchers uncovered BigBear 2.0, a global Microsoft 365 phishing-as-a-service operation targeting hundreds of organizations across 40+ countries. | OPERATION | OPERATION |
|
8.9.26 |
BengalSEO | BengalSEO Part 1: Anatomy of the Operation | OPERATION | OPERATION |
|
4.9.26 |
Still Circling | This is a collaborative follow-up to our original post, developed jointly with Emmanuel C., a security researcher not affiliated with LevelBlue, who contributed additional infrastructure and tooling findings based on an analysis of the same GitHub staging account. | OPERATION | OPERATION |
|
2.9.26 |
Plump Spider's Operations | New Details on Plump Spider's Operations in Pix Fraud Schemes | OPERATION | OPERATION |
| 27.8.26 | Tortoiseshell | Tortoiseshell: New Toolset and Operational Infrastructure Exposed | OPERATION | OPERATION |
| 21.8.26 | Operation QUICSILVER | OPERATION | OPERATION | OPERATION |
|
19.8.26 |
Operation CameraSwarm | Operation CameraSwarm: Over 14,000 Dahua cameras compromised across Ukraine and Russia | OPERATION | OPERATION |
|
18.8.26 |
Operation ASTERIX | Operation ASTERIX: Anatomy of a Crypto Fraud Pipeline | OPERATION | OPERATION |
|
10.8.26 |
Operation Capsule Vault | Operation Capsule Vault: RokRAT Attack Chain Analysis Using EMBED_PAYLOAD_v2 | OPERATION | OPERATION |
|
30.7.26 |
Operation Double Barrel | This technical analysis report was prepared as part of the joint cybersecurity advisory titled “Advisory on Cyberattacks Targeting Korean Citizens and Businesses by State-Sponsored Hacking Groups,” issued by the Republic of Korea’s National Intelligence Service (NIS), National Police Agency (NPA), Korea Internet & Security Agency (KISA), and Financial Security Institute (FSI). | OPERATION | OPERATION |
|
27.7.26 |
Operation BlueDash | Operation BlueDash: Multi-RMM Workplace Phishing | OPERATION | OPERATION |
|
27.7.26 |
[Op Report] From SSA Phish to AdaptixC2: A Multi-RAT Intrusion | Over five days in mid-May 2026, an operator engaged a deception workstation in the Deception.Pro environment and executed a near-complete commodity intrusion chain from initial access through domain reconnaissance. | OPERATION | OPERATION |
|
23.7.26 |
JadeProx | JadeProx: Tracing a China-nexus Operation Through an OPSEC Mistake | OPERATION | OPERATION |
|
23.7.26 |
Operation Muck and Load | Malicious Go Module Exposes GitHub Malware Lure Network Spanning 222 Repositories | OPERATION | OPERATION |
|
18.7.26 |
Operation Henhouse | Operation Henhouse: Hundreds of arrests and millions in assets seized in month tackling fraud | OPERATION | OPERATION |
|
18.7.26 |
Operation ShadowRecruit | Contents Introduction Key Targets Industries Affected Geographical focus Infection Chain Initial Findings Looking into the Decoy Document Technical Analysis Stage 1 – Initial Infection through LNK file Stage 2 – PowerShell Downloader Analysis Stage 3 – The .NET Dropper... | ||
|
17.7.26 |
Since 2015, Qi An Xin Threat Intelligence Center has been closely monitoring the gambling and fraud industries in East Asia and Southeast Asia. In 2020, we published "A Glimpse into the Southeast Asian Gambling Industry: A Look at the Black Market" , which provided a general analysis of the background and environment of the gambling industry. |
|||
| 5.7.26 | Operation Navy Ghost | Operation Navy Ghost: How Attackers Planted a Telegram-Powered Backdoor Across Fake pyrogram Packages on PyPI | OPERATION | OPERATION |
| 5.7.26 | Operation Contagious Interview | The most effective social engineering campaigns don’t rely on obvious red flags or technical exploits. They move through familiar business interactions, like hiring conversations, project discussions, and routine follow-ups that are designed to feel legitimate from the start. | OPERATION | OPERATION |
| 4.7.26 | Operation DragonReturn | Authors: Dixit Panchal & Soumen Burma Table of Contents: Introduction: Key Targets: Infection Chain: Initial Findings about Campaign: Initial Mail: Email Attachment: Lure: Official GoI, Income Tax Document: Technical Analysis: Infrastructural Artefacts & Threat actor Attributions. Campaign Timeline. | OPERATION | OPERATION |
| 27.6.26 | Operation DragonReturn | Authors: Dixit Panchal & Soumen Burma Table of Contents: Introduction: Key Targets: Infection Chain: Initial Findings about Campaign: Initial Mail: Email Attachment: Lure: Official GoI, Income Tax Document: Technical Analysis: Infrastructural Artefacts & Threat actor Attributions. Campaign Timeline. Conclusion:... | OPERATION | OPERATION |
| 24.6.26 | Dismantling FortiBleed | Inside a Russian Fortinet compromise operation. | OPERATION | OPERATION |
| 20.6.26 | Operation FanTrap | Operation FanTrap reveals FIFA 2026 fraud ecosystem with 4,000+ fake domains, phishing, streaming scams, and dark web-driven cybercrime activity. | OPERATION | OPERATION |
| 18.6.26 | Operation Poisson | Cato CTRL™ Threat Research: Operation Poisson – Analyzing a Cybercriminal’s Entire Operation | OPERATION | OPERATION |
|
13.6.26 |
Velvet Ant’s Operation Highland: How a China-Nexus Actor Infiltrated an Internal Network Undetected |
|||
| 12.6.26 | Phantom Mantis Operation | Phantom Mantis, initially known as ArmCorp, is a financially motivated threat group active since March 2025. The group conducts intrusions for extortion and is led by a Russian-speaking criminal tracked as LARVA-368. | OPERATION | OPERATION |
| 4.6.26 | Operation FlutterBridge | Operation FlutterBridge: macOS Malvertising Campaign Spreads New FlutterShell Backdoor | OPERATION | OPERATION |
| 30.5.26 | Operation Dragon Weave | Contents Introduction Key Targets Industries Affected Geographical focus Infection Chain Initial Findings Looking into the Decoy Document Technical Analysis Stage 1 – Initial Delivery Path A: LNK-Based Execution Path B: Executable-Based Delivery Stage 2 – Script-Based Dropper Chain Stage... | OPERATION | OPERATION |
| 30.5.26 | Operation XENOFISCAL | Authors: Dixit Panchal & Vaibhav Krushna Billade Table of Contents: Introduction: Key Targets: Infection Chain: Initial Findings about Campaign: Analysis of Decoy: Technical Analysis: Stage 1: Analysis of LNK File. Stage 2: Analysis of HTA/JavaScript Payload Stage 3: Analysis... | OPERATION | OPERATION |
| 26.5.26 | Nimbus Manticore Operations | The Iranian, IRGC affiliated, threat actor Nimbus Manticore resurfaced during Operation Epic Fury, the US military campaign against Iran launched on February 28, 2026, demonstrating newly adopted techniques and enhanced capabilities. | OPERATION | OPERATIONS |
| 23.5.26 | Operation Dragon Whistle | Table of Contents: Introduction: Key Targets: Infection Chain: Initial Findings about Campaign: Analysis of Decoys & Spear phishing Email: Technical Analysis: Stage1: Analysis of LNK File. Stage2: Analysis of VBS. Stage3: DLL Side Loading. Infrastructural Artefacts & Threat actor... | OPERATION | OPERATION |
| 13.5.26 | Operation NoVoice | Operation NoVoice: Android Malware Found in 50+ Apps Can Hijack Devices | OPERATION | OPERATION |
| 9.5.26 | Operation GriefLure | Table of Contents: Introduction: Key Targets: Infection Chain: Initial Findings about Campaign: Analysis of Decoys: Technical Analysis: Campaign-1: Stage-1: Ho so.rar Campaign: 2 Stage-1: download.zip Stage-2: The LNK & Batch file (Common in 1 & 2 both) Stage-3: Analysis | OPERATION | OPERATION |
| 9.5.26 | Operation Silent Rotor | Operation Silent Rotor: Targeted Campaign Compromises Unmanned Aviation Sector Ahead of Moscow Summit Table of Content Introduction Key Targets Industries Affected Geographical focus Infection Chain Initial Findings Looking into the Decoy Documents Technical Analysis Stage 1 – Analysis of... | OPERATION | OPERATION |
| 9.5.26 | Operation HumanitarianBait | Cyble analyzes Operation HumanitarianBait, a stealthy espionage campaign using aid-themed lures to deploy a fileless Python infostealer. | OPERATION | OPERATION |
| 6.5.26 | Iranian-Nexus Operation | Iranian-Nexus Operation Against Oman's Government: 12 Ministries Hit and 26,000 Citizen Records Exposed | OPERATION | OPERATION |
| 25.4.26 | Operation TrustTrap | CRIL uncovered 16,800+ spoofed domains by analyzing URL trust abuse, cloud infra clustering, and human‑centric deception instead of technical exploits. | OPERATION | OPERATION |
| 5.4.26 | Operation NoVoice | Operation NoVoice: Rootkit Tells No Tales | OPERATION | OPERATION |
| 4.4.26 | Operation TrueChaos: 0-Day Exploitation Against Southeast Asian Government Targets | Check Point Research identified a zero-day vulnerability in the TrueConf client application, tracked as CVE-2026-3502, with a CVSS score of 7.8. The flaw stems from the abuse of TrueConf’s updater validation mechanism, allowing an attacker who controls the on-premises TrueConf server to distribute and execute arbitrary files across all connected endpoints. | OPERATION | OPERATION |
| 4.4.26 | Operation DualScript – A Multi-Stage PowerShell Malware Campaign Targeting Cryptocurrency and Financial Activity | Operation DualScript – A Multi-Stage PowerShell Malware Campaign Targeting Cryptocurrency and Financial Activity Introduction During our investigation, we identified a multi-stage malware infection leveraging Scheduled Task persistence, VBScript launchers, and PowerShell-based execution. The attack operates through two parallel chains:... | OPERATION | OPERATION |
| 3.4.26 | Multi-Tool Mining Operation | Fake Installers to Monero: A Multi-Tool Mining Operation | OPERATION | OPERATION |
| 21.3.26 | Operation GhostMail | Contents Introduction Key Targets Industries Affected Geographical focus Geopolitical Context Infection Chain Timeline of Activity Initial Findings Looking into the Decoy Documents Technical Analysis Stage 1 – Malicious Archive Delivery Stage 2 – Malicious Shortcut Execution Stage 3 | OPERATION | OPERATION |
| 18.3.26 | LeakNet’s | Casting a Wider Net: ClickFix, Deno, and LeakNet’s Scaling Threat | OPERATION | OPERATION |
| 14.3.26 | Operation CamelClone: Multi-Region Espionage Campaign Targets Government and Defense Entities Amidst Regional Tensions | Contents Introduction Key Targets Industries Affected Geographical focus Geopolitical Context Infection Chain Timeline of Activity Initial Findings Looking into the Decoy Documents Technical Analysis Stage 1 – Malicious Archive Delivery Stage 2 – Malicious Shortcut Execution Stage 3 | OPERATION | OPERATION |
| 5.3.26 | Operation Epic Fury/Roaring Lion | Retaliatory Hacktivist DDoS Activity Following Operation Epic Fury/Roaring Lion | OPERATION | OPERATION |
| 24.2.26 | Operation MacroMaze | Operation MacroMaze: new APT28 campaign using basic tooling and legit infrastructure | OPERATION | OPERATION |
| 23.2.26 | Operation Olalampo | MuddyWater APT has launched a new cyber offensive operation, dubbed Operation Olalampo, deploying new malware variants and leveraging Telegram bots for command-and-control. | OPERATION | OPERATION |
| 3.2.26 | Operation Neusploit | APT28 Leverages CVE-2026-21509 in Operation Neusploit | OPERATION | OPERATION |
| 24.1.26 | Operation DupeHike | Contents Introduction Key Targets. Industries Affected. Geographical Focus. Infection Chain. Initial Findings. Looking into the decoy-document Technical Analysis Stage 1 – Malicious LNK Script Stage 2 – DUPERUNNER Implant Stage 3 – AdaptixC2 Beacon. Infrastructural Artefacts. Conclusion SEQRITE Protection.... | OPERATION | OPERATION |
| 24.1.26 | Operation Covert Access | Table of Contents: Introduction: Infection Chain: Targeted sectors: Initial Findings about Campaign: Analysis of Decoy: Technical Analysis: Stage-1: Analysis of Windows Shortcut file (.LNK). Stage-2: Analysis of Batch file. Stage-3: Details analysis of Covert RAT. Conclusion: Seqrite Coverage: IOCs... | OPERATION | OPERATION |
| 24.1.26 | Operation Nomad Leopard | Contents Introduction Key Targets Industries Affected Geographical focus Infection Chain. Initial Findings Looking into the decoy-document Technical Analysis Stage 1 – Malicious ISO File Stage 2 – Malicious LNK File Stage 3 – Final Payload: FALSECUB Infrastructure & Attribution... | OPERATION | OPERATION |
| 19.1.26 | Operation Poseidon | Operation Poseidon: Spear-Phishing Attacks Abusing Google Ads Redirection Mechanisms | OPERATION | OPERATION |