APT & threat-intel feed
A curated feed of real threat-intel vendor research — APT campaigns, ransomware, malware, ICS, supply-chain and more. Every entry links to the original source; nothing here is republished. Filter and sort across 37 posts from 19 sources.
Explore the same data as a knowledge graph →A single financially motivated operator seeded typosquatted npm packages with an apparently AI-written credential and CI-secret stealer, framing the theft as bug-bounty research.
Group-IB profiles a Chinese-language sub-crew within a larger SMS-phishing-as-a-service ecosystem, showing a real-time operator dashboard for harvesting card data.
This Latin American banking trojan uses a multi-server exfiltration relay and geofencing to serve malicious payloads only to victims in its target countries.
Talos is tracking in-the-wild attacks against known flaws in Cisco Secure Firewall Management Center appliances.
Attackers pose as IT helpdesk to trick users into "reconfiguring" passkeys/MFA, then re-register their own authenticator to keep access even after a password reset, followed by bulk mailbox and file-storage data theft.
Several distinct China-aligned clusters adopted the same browser and OS exploit chain within days of each other, suggesting the exploit itself was shared or sold rather than independently discovered.
Two separate China-nexus groups independently deployed identical shellcode against a browser bug that had been fixed upstream in open source but not yet shipped in a stable release.
Criminals abuse the Google Visualization API to serve obfuscated JavaScript from public Google Sheets, tricking crypto-forum users into pasting code into their browser address bar to drain wallets.
A fake-update infection chain now uses WebDAV to push a bundle of info-stealers and a remote-access tool onto victim machines.
SEKOIA maps how the North Korean state cyber apparatus has fragmented into distinct sub-clusters, all funding state programs through crypto theft, ransomware and fake IT-worker schemes.
A helpdesk-impersonation vishing/Teams campaign talks victims into a remote session, then silently installs an implant and pivots toward domain controllers.
A Chinese-speaking cybercrime cluster hijacked compromised Brazilian government web servers to boost search rankings for fake gambling apps, using a custom loader/backdoor toolkit.
A malicious shortcut file disguised as a seafood purchase order drops a decoy document plus a script that phones home to cloud storage every few minutes; AhnLab ties the code to a known espionage cluster.
A financially motivated group formerly tracked as UNC5669 moved from off-the-shelf remote-access tools to a custom malware suite and AI-assisted tradecraft to defraud Brazilian banking and payment-rail systems.
Fake vendor sites impersonating well-known software brands serve trojanized installers that disable Windows defenses; Microsoft moderately links the activity to a publicly reported cluster without nation-state attribution.
CrowdStrike and an international law-enforcement coalition dismantled a two-decade-old peer-to-peer botnet whose operator used a clipboard-hijacking tool to steal cryptocurrency.
Kaspersky documents this group’s first known use of JavaScript-based remote-access trojans, delivered via fake coding-challenge lures against airline and fintech targets.
Check Point reverse-engineered a compiled-bytecode stealer that intercepts HTTPS traffic to crypto-exchange sites and replays logins.
Two related Teams-based vishing campaigns impersonated IT helpdesks to push remote-access tools or attempt credential-relay attacks against domain controllers.
A suspected Chinese crime group shifted its tax-themed phishing lures from mainland-China targets to impersonating a foreign tax authority, deploying a modular command-and-control framework marketed on Telegram.
This espionage group deployed a new modular implant that notably falls back on a public blockchain to fetch replacement command-and-control addresses if primary infrastructure is taken down.
GTIG links three separate intrusion sets abusing OAuth, device-code phishing and messaging-app linking flows to compromise personal accounts of diplomats, researchers and NATO-adjacent individuals, assessing a Russian nexus with high confidence.
This China-nexus espionage group added a signed kernel-mode rootkit driver to its backdoor, deployed via DLL side-loading against Asian government targets.
New tooling lets this group hijack victims’ authenticated messaging-app sessions and covertly record microphone audio using voice-activity detection.
A Mirai-derived Linux botnet with encrypted command-and-control, SSH brute-forcing and a proxy relay is actively compromising routers, firewalls and IP cameras through multiple known vulnerabilities.
After one of its extortion brands reportedly retired, this vishing crew rebranded across several labels while reusing shared infrastructure and phishing kits to hit finance, PE and law firms for multimillion-dollar ransoms.
Attackers tampered with a VPN/game-accelerator app’s installer to selectively drop an implant on machines showing signs of professional or developer use, avoiding gaming systems.
The Brazilian banking trojan family Astaroth added a messaging-app spam module to spread itself through victims’ own contact lists instead of email.
Trend Micro helped law enforcement dismantle a phishing-as-a-service platform used to harvest cloud-account credentials at scale.
A midyear rundown of Iran-nexus operators shows persona-led hack-and-leak groups and espionage actors prioritizing durable access over one-off disruption.
Trend Micro caught a lone operator using an AI coding assistant to build and deploy botnet command-and-control infrastructure end to end in six minutes, then pivoting toward a fraud scheme.
Two independently operating espionage clusters compromised Pakistani police systems holding biometric and criminal records, for apparently different strategic reasons.
ESET's yearly Gamaredon rundown shows the group hiding C2 behind cloud storage and tunneling services while sticking to Ukrainian government and military targets ahead of Russian holidays.
ESET contributed intelligence to a law-enforcement takedown of infrastructure behind a major botnet loader and info-stealer.
What looked like an opportunistic ransomware infection was actually a state-linked intrusion that deliberately skipped file encryption, using the ransomware as cover for long-term espionage access.
This annual OT threat rundown tracks intensifying industrial-control-system reconnaissance and control-loop mapping by several tracked groups, including one acting as an initial-access broker handing off footholds to a deeper-stage specialist.
This cluster built fake conference-registration sites mimicking real European security and foreign-policy events to lure targets into credential phishing, then asked victims to hand over colleagues’ contacts to expand the operation.
Curated links to third-party research — titles and dates as published, summaries are our own paraphrase. Attribution fields (actor, origin, target) are populated only when the source post states them; we do not infer attribution. Always verify against the original source before citing.
Frequently asked questions
Where does this content come from?
Every post links directly to the original vendor or CERT research — Cisco Talos, Mandiant, Recorded Future, Microsoft, ESET, and similar. We link and summarize; we never republish the original text. Click through to read the full research at its source.
Are the attribution fields (actor, origin country) verified?
They reflect only what the source post itself states. If a vendor names a threat actor or suspected origin, we show it; if they don’t, the field is left blank rather than guessed. Treat every attribution as that vendor’s assessment, not an independently confirmed fact.
How often is this updated?
This is a curated, hand-reviewed feed, not a live automated scrape — entries are added in batches, not continuously. For the freshest research, follow the source vendors directly.
Is this free?
Yes, entirely free with no signup. Filtering and sorting run in your browser.