Malicious Campaign Targets Latin America: The seller, The operator and a curious linkCisco Talos·Aug 19, 11:58 UTC · Aug 19, 2021Threat actor57
Upgraded Aggah malspam campaign delivers multiple RATsCisco Talos·Apr 29, 15:48 UTC · Apr 29, 2020Threat actor57
Gamaredon APT targets Ukrainian government agencies in new campaignCisco Talos·Sep 15, 13:00 UTC · Sep 15, 2022Threat actor157
Experts Detect Pakistan-Linked Cyber Campaigns Aimed at Indian Government EntitiesThe Hacker News·Feb 10, 10:41 UTC · Feb 10, 2026Threat actor157
Ukraine's CERT-UA warns of espionage activity by UACSecurity Affairs·May 24, 11:00 UTC · May 24, 2023Threat actor57
DownEx cyberespionage operation targets Central AsiaSecurity Affairs·May 10, 17:02 UTC · May 10, 2023Threat actor57
Blind Eagle Cyber Espionage Group Strikes Again: New Attack Chain UncoveredThe Hacker News·Apr 24, 04:37 UTC · Apr 24, 2023Threat actor57
GhostWriter APT targets state entities of Ukraine with Cobalt Strike BeaconSecurity Affairs·Mar 28, 09:35 UTC · Mar 28, 2022Threat actor57
Cyber-Criminal espionage Operation insists on Italian ManufacturingSecurity Affairs·May 22, 13:42 UTC · May 22, 2020Threat actor57
The Evolution of Aggah: From Roma225 to the RG CampaignSecurity Affairs·Aug 6, 10:46 UTC · Aug 6, 2019Threat actor57
Microsoft warns of spam campaign exploiting CVE-2017Security Affairs·Jun 10, 07:43 UTC · Jun 10, 2019Threat actorCVE-2017-1188260
'Roma225' campaign targets companies in the Italian automotive sectorSecurity Affairs·Dec 31, 08:56 UTC · Dec 31, 2018Threat actor57
The TopHat Campaign: Attacks Within The Middle East Region Using Popular ThirdPalo Alto Unit 42·Nov 1, 11:01 UTC · Nov 1, 2018Threat actorCVE-2017-019960
Fallout exploit kit appeared in threat landscape in malvertising campaignsSecurity Affairs·Sep 10, 07:09 UTC · Sep 10, 2018Threat actorCVE-2018-4878CVE-2018-817460
APT42 Hackers Pose as Journalists to Harvest Credentials and Access Cloud DataThe Hacker News·Nov 14, 14:32 UTC · Nov 14, 2025Threat actor57
Multi-year Chinese APT Campaign Targets South Korean Academic, Government, and Political EntitiesRecorded Future·Aug 22, 00:00 UTC · Aug 22, 2025Threat actor57
RedHotel: A Prolific, Chinese State-Sponsored Group Operating at a Global ScaleRecorded Future·Aug 22, 00:00 UTC · Aug 22, 2025Threat actorCVE-2022-24682CVE-2022-27924CVE-2022-27925+2 CVEs60
UNG0002 Group Hits China, Hong Kong, Pakistan Using LNK Files and RATs in Twin CampaignsThe Hacker News·Jul 21, 06:29 UTC · Jul 21, 2025Threat actor57
N. Korea-linked Kimsuky Shifts to Compiled HTML Help Files in Ongoing CyberattacksThe Hacker News·Apr 2, 04:40 UTC · Apr 2, 2024Threat actor57
New Malvertising Campaign Distributing PikaBot Disguised as Popular SoftwareThe Hacker News·Dec 20, 03:33 UTC · Dec 20, 2023Threat actor57
Cyber Attacks Strike Ukraine's State Bodies in Espionage OperationThe Hacker News·May 26, 03:32 UTC · May 26, 2023Threat actor57
What’s with the shared VBA code between Transparent Tribe and other threat actors?Cisco Talos·Feb 9, 13:05 UTC · Feb 9, 2022Threat actor57
Fox Kitten Campaign - Iranian hackers exploit 1Security Affairs·Feb 17, 06:07 UTC · Feb 17, 2020Threat actorCVE-2019-11510CVE-2018-13379CVE-2019-1579+1 CVEs60
U.S. taxpayers hit by a phishing campaign delivering the Amadey botSecurity Affairs·Sep 20, 14:52 UTC · Sep 20, 2019Threat actor57
OilRig APT group targets high-ranking office in a Middle Eastern nationSecurity Affairs·Sep 14, 13:15 UTC · Sep 14, 2018Threat actor57
Unusual Malspam campaign targets banks with Microsoft Publisher filesSecurity Affairs·Aug 20, 06:58 UTC · Aug 20, 2018Threat actor57