Threat Actors

'PhantomRaven' Supply-Chain Campaign Floods npm Registry with Malicious Packages
Application Security
‘PhantomRaven’ Supply-Chain Campaign Floods npm Registry with Malicious Packages
'PhantomRaven' attacks are affecting JavaScript developers by targeting the npm registry with dozens of malicious packages designed to steal sensitive...
Russian Threat Actors Targeting Signal and WhatsApp Accounts of Officials
News
Russian Threat Actors Targeting Signal and WhatsApp Accounts of Officials
Russian hackers are targeting Signal and WhatsApp accounts of officials globally, posing cyber risks.
Dutch Police Give Suspected Scammers a Two-Week Deadline to Surrender
News
Dutch Police Give Suspected Scammers a Two-Week Deadline to Surrender
Dutch police give 100 alleged scammers two weeks to surrender, or their images could be displayed nationwide.
Iranian MOIS-Linked MuddyWater Cyber Group Deploys New Custom Implant
Cybersecurity
Iranian MOIS-Linked MuddyWater Cyber Group Deploys New Custom Implant
An Iranian MOIS-linked cybercrew infiltrates U.S. firms with a sophisticated implant.
Ukrainian National Gets Five Years for Helping North Korean IT Workers Infiltrate U.S. Companies
News
Ukrainian National Gets Five Years for Helping North Korean IT Workers Infiltrate U.S. Companies
A Ukrainian hacker aided North Korea in infiltrating U.S. companies by providing stolen identities, resulting in a five-year prison sentence.
The Rise of TGR-STA-1030 The Global 'Shadow Campaigns' Targeting Government Infrastructure
News
The Rise of TGR-STA-1030: The Global ‘Shadow Campaigns’ Targeting Government Infrastructure
A new cyberespionage group, TGR-STA-1030/UNC6619, known for its "Shadow Campaigns," has targeted government infrastructure in 155 countries, highlighting a new global threat landscape.
UAT-9921 Emerges with VoidLink to Challenge Technology and Financial Entities
News
UAT-9921 Emerges with VoidLink to Challenge Technology and Financial Entities
The newly identified threat actor UAT-9921 is utilizing VoidLink, a sophisticated modular attack framework, to compromise technology and financial sectors, according to Cisco Talos.
RedKitten Campaign Targets NGOs Amid Iranian Unrest
News
RedKitten Campaign Targets NGOs Amid Iranian Unrest
A group likely linked to Iranian state interests, RedKitten, targets NGOs working on human rights documentation. This activity arose during the nationwide unrest in Iran.
China-linked Threat Actor UAT-8099 Targets Asian IIS Servers
News
China-linked Threat Actor UAT-8099 Targets Asian IIS Servers
Cisco Talos uncovered an operation by UAT-8099 aimed at compromised Internet Information Services servers throughout Asia, focusing heavily on Thailand and Vietnam.
Exploitations of WinRAR Vulnerability CVE-2025-8088 Emerge as a Major Threat
CVE Vulnerability Alerts
Exploitations of WinRAR Vulnerability CVE-2025-8088 Emerge as a Major Threat
Cyber attackers leverage the CVE-2025-8088 high-severity WinRAR vulnerability. This security loophole is targeted for initial access and malware delivery, affecting numerous organizations globally.