🎉 New here? Use code WELCOME10 for 10% off any plan at checkout
Threat Intel · free

APT & threat-intel feed

A curated feed of real threat-intel vendor research — APT campaigns, ransomware, malware, ICS, supply-chain and more. Every entry links to the original source; nothing here is republished. Filter and sort across 37 posts from 19 sources.

Explore the same data as a knowledge graph →
37 of 37 posts
Supply Chain·CrowdStrike·2026-09-15
PhantomRaven: An LLM-Generated Information Stealer Developed for Bug Bounty Hunting

A single financially motivated operator seeded typosquatted npm packages with an apparently AI-written credential and CI-secret stealer, framing the theft as bug-bounty research.

Target sector: Technology
Phishing·Group-IB·2026-09-14Smishing Triad
Smish. Click. Drained: Inside the Smishing Triad’s Phishing Cockpit

Group-IB profiles a Chinese-language sub-crew within a larger SMS-phishing-as-a-service ecosystem, showing a real-time operator dashboard for harvesting card data.

Target region: Global
Malware·Fortinet FortiGuard Labs·2026-09-10Casbaneiro
Casbaneiro: A Banking Trojan with Distributed Data-Receiving Servers

This Latin American banking trojan uses a multi-server exfiltration relay and geofencing to serve malicious payloads only to victims in its target countries.

Target sector: Financial Services · Target region: South America
Vulnerability·Cisco Talos·2026-09-09
Active exploitation of Cisco Secure Firewall Management Center vulnerabilities

Talos is tracking in-the-wild attacks against known flaws in Cisco Secure Firewall Management Center appliances.

Cybercrime·Microsoft Threat Intelligence·2026-09-09Storm-3121
Passkey-themed social engineering leads to identity and cloud compromise

Attackers pose as IT helpdesk to trick users into "reconfiguring" passkeys/MFA, then re-register their own authenticator to keep access even after a password reset, followed by bulk mailbox and file-storage data theft.

Vulnerability·Proofpoint·2026-09-09TA412
Once in a BlueMoon: Multiple State-Aligned Threat Actors Rapidly Adopt Novel Exploit Chain Using Chrome and Windows Zero-Days

Several distinct China-aligned clusters adopted the same browser and OS exploit chain within days of each other, suggesting the exploit itself was shared or sold rather than independently discovered.

Target sector: Nonprofit · Target region: North America
Vulnerability·Volexity·2026-09-09UTA0560
Mind the (Patch) Gap: Multiple Chinese Threat Actors Chain 0-day Exploits in Chrome & Windows

Two separate China-nexus groups independently deployed identical shellcode against a browser bug that had been fixed upstream in open source but not yet shipped in a stable release.

Target sector: Nonprofit · Target region: North America
Cryptocurrency·Cisco Talos·2026-09-08
ClickFix moves into the browser: Cryptocurrency theft with Google-hosted C2

Criminals abuse the Google Visualization API to serve obfuscated JavaScript from public Google Sheets, tricking crypto-forum users into pasting code into their browser address bar to drain wallets.

Target sector: Cryptocurrency
Malware·Cisco Talos·2026-09-08
ClearFake WebDAV infection chain delivers Amatera stealer, ZigCryptoStealer, and NetSupport Manager

A fake-update infection chain now uses WebDAV to push a bundle of info-stealers and a remote-access tool onto victim machines.

Nation-state·SEKOIA·2026-09-07
Beyond Lazarus: Organization of DPRK cyber capabilities

SEKOIA maps how the North Korean state cyber apparatus has fragmented into distinct sub-clusters, all funding state programs through crypto theft, ransomware and fake IT-worker schemes.

Target sector: Financial Services · Target region: Global
Cybercrime·Microsoft Threat Intelligence·2026-09-02
Impersonating IT support: how threat actors turn a remote session into enterprise-wide access

A helpdesk-impersonation vishing/Teams campaign talks victims into a remote session, then silently installs an implant and pivots toward domain controllers.

Cybercrime·Check Point Research·2026-09-02Gambling Goblin
Gaming the system: how a Chinese-speaking actor turned Brazilian government sites into an SEO weapon

A Chinese-speaking cybercrime cluster hijacked compromised Brazilian government web servers to boost search rankings for fake gambling apps, using a custom loader/backdoor toolkit.

Target sector: Government · Target region: South America
APT·AhnLab ASEC·2026-09-02Kimsuky
Kim Sooki again? This time, it was disguised as a request for seafood ingredients

A malicious shortcut file disguised as a seafood purchase order drops a decoy document plus a script that phones home to cloud storage every few minutes; AhnLab ties the code to a known espionage cluster.

Target region: Asia
Cybercrime·Google Threat Intelligence Group·2026-09-01BREEZE COMET
Financially Motivated Threat Actor BREEZE COMET Targets Brazil

A financially motivated group formerly tracked as UNC5669 moved from off-the-shelf remote-access tools to a custom malware suite and AI-assisted tradecraft to defraud Brazilian banking and payment-rail systems.

Target sector: Financial Services · Target region: South America
Malware·Microsoft Threat Intelligence·2026-09-01Silver Fox
Counterfeit installers to system compromise: Tracking a deceptive software download campaign

Fake vendor sites impersonating well-known software brands serve trojanized installers that disable Windows defenses; Microsoft moderately links the activity to a publicly reported cluster without nation-state attribution.

Target region: Asia
Cybercrime·CrowdStrike·2026-09-01SALTY SPIDER
Peer Pressure: Inside the Sality Botnet Disruption Operation

CrowdStrike and an international law-enforcement coalition dismantled a two-decade-old peer-to-peer botnet whose operator used a clipboard-hijacking tool to steal cryptocurrency.

Target region: Global
APT·Kaspersky·2026-09-01Mirage Kitten
Mirage Kitten targeting aviation and FinTech sectors across the Middle East and Africa with a new malware set

Kaspersky documents this group’s first known use of JavaScript-based remote-access trojans, delivered via fake coding-challenge lures against airline and fintech targets.

Target sector: Aviation · Target region: Africa
Cryptocurrency·Check Point Research·2026-08-31
Breaking the Seal: Static Deobfuscation of JSCeal’s Compiled V8 Bytecode

Check Point reverse-engineered a compiled-bytecode stealer that intercepts HTTPS traffic to crypto-exchange sites and replays logins.

Target sector: Cryptocurrency
Phishing·Palo Alto Unit 42·2026-08-31
Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teams

Two related Teams-based vishing campaigns impersonated IT helpdesks to push remote-access tools or attempt credential-relay attacks against domain controllers.

Cybercrime·Proofpoint·2026-08-27TA4922
Carry-On Compromise: TA4922 Packs PackClient

A suspected Chinese crime group shifted its tax-themed phishing lures from mainland-China targets to impersonating a foreign tax authority, deploying a modular command-and-control framework marketed on Telegram.

Target sector: Government · Target region: Asia
APT·Arctic Wolf·2026-08-26Dark Caracal
Dark Caracal Reloaded: New Malware, Same Hunting Grounds

This espionage group deployed a new modular implant that notably falls back on a public blockchain to fetch replacement command-and-control addresses if primary infrastructure is taken down.

Target sector: Government · Target region: South America
Nation-state·Google Threat Intelligence Group·2026-08-20UNC6293
Going with the Flow(s): Distinct Clusters Target Individuals of Interest to Russia

GTIG links three separate intrusion sets abusing OAuth, device-code phishing and messaging-app linking flows to compromise personal accounts of diplomats, researchers and NATO-adjacent individuals, assessing a Russian nexus with high confidence.

Target sector: Government · Target region: Europe
APT·Kaspersky·2026-08-14HoneyMyte
APT group HoneyMyte upgrades CoolClient: the backdoor gets a kernel-level Windows rootkit

This China-nexus espionage group added a signed kernel-mode rootkit driver to its backdoor, deployed via DLL side-loading against Asian government targets.

Target sector: Government · Target region: Asia
APT·Kaspersky·2026-08-13Armored Likho
Armored Likho expands its cyber-espionage toolkit

New tooling lets this group hijack victims’ authenticated messaging-app sessions and covertly record microphone audio using voice-activity detection.

Target sector: Government · Target region: Europe
IoT·Fortinet FortiGuard Labs·2026-08-13
Multi-Functional Linux Botnet "Evooo1Bot"

A Mirai-derived Linux botnet with encrypted command-and-control, SSH brute-forcing and a proxy relay is actively compromising routers, firewalls and IP cameras through multiple known vulnerabilities.

Target region: Global
Cybercrime·Google Threat Intelligence Group·2026-08-06UNC6671
UNC6671 Rebrands: Multi-Brand Vishing Extortion Targets Financial Services and Enterprise Cloud Environments

After one of its extortion brands reportedly retired, this vishing crew rebranded across several labels while reusing shared infrastructure and phishing kits to hit finance, PE and law firms for multimillion-dollar ransoms.

Target sector: Financial Services
Supply Chain·Fortinet FortiGuard Labs·2026-08-04
QuickFox Supply Chain Attack Used to Deploy FDMTP Implant

Attackers tampered with a VPN/game-accelerator app’s installer to selectively drop an implant on machines showing signs of professional or developer use, avoiding gaming systems.

Target sector: Technology · Target region: Asia
Malware·CrowdStrike·2026-07-29Astaroth
Inside Astaroth's New Spambot Component

The Brazilian banking trojan family Astaroth added a messaging-app spam module to spread itself through victims’ own contact lists instead of email.

Target sector: Financial Services · Target region: South America
Phishing·Trend Micro·2026-07-22Sneaky2FA
Law Enforcement Takes Down Kratos/Sneaky2FA Phishing Service, With an Assist From TrendAI

Trend Micro helped law enforcement dismantle a phishing-as-a-service platform used to harvest cloud-account credentials at scale.

Target region: Global
Nation-state·SentinelOne·2026-07-21
Iran War Cyber Threat Landscape | A Midyear Assessment on What Matters

A midyear rundown of Iran-nexus operators shows persona-led hack-and-leak groups and espionage actors prioritizing durable access over one-off disruption.

Cybercrime·Trend Micro·2026-07-14bandcampro
Six Minutes to Compromise: How "Patriot Bait" Actor Used AI to Build and Deploy a C&C Botnet

Trend Micro caught a lone operator using an AI coding assistant to build and deploy botnet command-and-control infrastructure end to end in six minutes, then pivoting toward a fraud scheme.

Target region: North America
APT·SentinelOne·2026-07-09TAG-179
One Target, Two Flags | Rival Espionage Actors Converge On Pakistani Law Enforcement

Two independently operating espionage clusters compromised Pakistani police systems holding biometric and criminal records, for apparently different strategic reasons.

Target sector: Government · Target region: Asia
Nation-state·ESET·2026-06-25Gamaredon
Gamaredon in 2025: Leveraging tunnels, workers, dead drops, and new alliances

ESET's yearly Gamaredon rundown shows the group hiding C2 behind cloud storage and tunneling services while sticking to Ukrainian government and military targets ahead of Russian holidays.

Target sector: Government · Target region: Europe
Cybercrime·ESET·2026-06-24Amadey
ESET takes part in Operation Endgame to disrupt Amadey and Stealc

ESET contributed intelligence to a law-enforcement takedown of infrastructure behind a major botnet loader and info-stealer.

Ransomware·Rapid7·2026-05-06MuddyWater
Muddying the Tracks: The State-Sponsored Shadow Behind Chaos Ransomware

What looked like an opportunistic ransomware infection was actually a state-linked intrusion that deliberately skipped file encryption, using the ransomware as cover for long-term espionage access.

Target sector: Manufacturing · Target region: North America
ICS/OT·Dragos·2026-03-24VOLTZITE
OT Threat Landscape 2026: What OT Cybersecurity Defenders Need to Know

This annual OT threat rundown tracks intensifying industrial-control-system reconnaissance and control-loop mapping by several tracked groups, including one acting as an initial-access broker handing off footholds to a deeper-stage specialist.

Target sector: Industrial/OT
Nation-state·Volexity·2025-12-04UTA0355
Dangerous Invitations: Russian Threat Actor Spoofs European Security Events in Targeted Phishing Attacks

This cluster built fake conference-registration sites mimicking real European security and foreign-policy events to lure targets into credential phishing, then asked victims to hand over colleagues’ contacts to expand the operation.

Target sector: Government · Target region: Europe

Curated links to third-party research — titles and dates as published, summaries are our own paraphrase. Attribution fields (actor, origin, target) are populated only when the source post states them; we do not infer attribution. Always verify against the original source before citing.

Frequently asked questions

Where does this content come from?

Every post links directly to the original vendor or CERT research — Cisco Talos, Mandiant, Recorded Future, Microsoft, ESET, and similar. We link and summarize; we never republish the original text. Click through to read the full research at its source.

Are the attribution fields (actor, origin country) verified?

They reflect only what the source post itself states. If a vendor names a threat actor or suspected origin, we show it; if they don’t, the field is left blank rather than guessed. Treat every attribution as that vendor’s assessment, not an independently confirmed fact.

How often is this updated?

This is a curated, hand-reviewed feed, not a live automated scrape — entries are added in batches, not continuously. For the freshest research, follow the source vendors directly.

Is this free?

Yes, entirely free with no signup. Filtering and sorting run in your browser.

APT & Threat-Intel Feed — Filter 10+ Ways (Free) · PlayCISO