ArcaneDoor - New espionage-focused campaign found targeting perimeter network devicesCisco Talos·Apr 24, 15:54 UTC · Apr 24, 2024Threat actorCVE-2025-20333CVE-2025-20362CVE-2025-20363+3 CVEs60
Threat actors using MacroPack to deploy Brute Ratel, Havoc and PhantomCore payloadsCisco Talos·Sep 3, 13:14 UTC · Sep 3, 2024Threat actor145
SneakyChef espionage group targets government agencies with SugarGh0st and more infection techniquesCisco Talos·Jun 21, 12:00 UTC · Jun 21, 2024Threat actor45
URLs have always been a great hiding place for threat actorsCisco Talos·Jun 15, 18:00 UTC · Jun 15, 2023Threat actor in the wildCVE-2023-3436260
New campaign uses government, union-themed lures to deliver Cobalt Strike beaconsCisco Talos·Sep 28, 12:12 UTC · Sep 28, 2022Threat actorCVE-2017-019960
Gamaredon APT targets Ukrainian government agencies in new campaignCisco Talos·Sep 15, 13:00 UTC · Sep 15, 2022Threat actor157
A year of Fajan evolution and Bloomberg themed campaignsCisco Talos·Apr 21, 11:59 UTC · Apr 21, 2021Threat actor45
Upgraded Aggah malspam campaign delivers multiple RATsCisco Talos·Apr 29, 15:48 UTC · Apr 29, 2020Threat actor57
How Threat Actors Are Rizzing Up Your AI for ProfitRecorded Future·Jul 20, 00:00 UTC · Jul 20, 2026Threat actor160
New threat actor, UAT-9921, leverages VoidLink framework in campaignsCisco Talos·Feb 11, 00:00 UTC · Feb 11, 2026Threat actor157
Spam campaign targeting Brazil abuses Remote Monitoring and Management toolsCisco Talos·May 8, 10:00 UTC · May 8, 2025Threat actor57
Threat actor believed to be spreading new MedusaLocker variant since 2022Cisco Talos·Oct 3, 10:00 UTC · Oct 3, 2024Threat actor57
APT41 likely compromised Taiwanese government-affiliated research institute with ShadowPad and Cobalt StrikeCisco Talos·Aug 1, 12:00 UTC · Aug 1, 2024Threat actorCVE-2018-0824160
New details on TinyTurla’s post-compromise activity reveal full kill chainCisco Talos·Mar 21, 13:08 UTC · Mar 21, 2024Threat actor57
TinyTurla-NG in-depth tooling and command and control analysisCisco Talos·Feb 22, 13:00 UTC · Feb 22, 2024Threat actor157
Operation Blacksmith: Lazarus targets organizations worldwide using novel TelegramCisco Talos·Dec 11, 13:50 UTC · Dec 11, 2023Threat actorCVE-2021-4422860
Malicious campaigns target government, military and civilian entities in Ukraine, PolandCisco Talos·Jul 13, 10:45 UTC · Jul 13, 2023Threat actor145
Talos uncovers espionage campaigns targeting CIS countries, embassies and EU health care agencyCisco Talos·Mar 14, 11:00 UTC · Mar 14, 2023Threat actor60
Cyware Threat Defender Library strengthens security collaboration between organizationsHelp Net Security·Oct 5, 00:00 UTC · Oct 5, 2022Threat actor60
Transparent Tribe begins targeting education sector in latest campaignCisco Talos·Jul 13, 23:58 UTC · Jul 13, 2022Threat actor57
What’s with the shared VBA code between Transparent Tribe and other threat actors?Cisco Talos·Feb 9, 13:05 UTC · Feb 9, 2022Threat actor57
Russia-linked APT29 group changes TTPs following April advisoriesSecurity Affairs·May 7, 21:03 UTC · May 7, 2021Threat actorCVE-2021-26855CVE-2018-13379CVE-2019-1653+9 CVEs50
NSA warns about Sandworm APT exploiting Exim flawHelp Net Security·May 5, 07:53 UTC · May 5, 2021Threat actorCVE-2019-1014960
Masslogger campaigns exfiltrates user credentialsCisco Talos·Feb 17, 13:00 UTC · Feb 17, 2021Threat actor57
FireEye breach: State-sponsored attackers stole hacking toolsHelp Net Security·Dec 9, 00:00 UTC · Dec 9, 2020Threat actor60
Threat actors attempt to capitalize on coronavirus outbreakCisco Talos·Feb 13, 19:07 UTC · Feb 13, 2020Threat actor45
SWEED: Exposing years of Agent Tesla campaignsCisco Talos·Jul 15, 15:04 UTC · Jul 15, 2019Threat actorCVE-2017-8759CVE-2017-11882160
Operation Blockbuster: Coverage for the Lazarus GroupCisco Talos·Feb 24, 15:23 UTC · Feb 24, 2016Threat actor45