Russian APT activity is resurgent, researchers sayCyberScoop·Nov 20, 14:00 UTC · Nov 20, 2018Exploit / PoC in the wild60
Running for Office: Russian APT Toolkits RevealedRecorded Future·Jun 27, 00:00 UTC · Jun 27, 2025Ransomware in the wildCVE-2014-3897CVE-2013-3897260
Russian APT29 Exploits Gmail App Passwords to Bypass 2FA in Targeted Phishing CampaignThe Hacker News·Jun 19, 08:14 UTC · Jun 19, 2025Threat actor45
APT29 Deploys GRAPELOADER Malware Targeting European Diplomats Through WineThe Hacker News·Apr 20, 04:58 UTC · Apr 20, 2025Malware55
Google says Russian group targeted Mongolian government with exploits used by NSO GroupThe Record·Aug 29, 15:07 UTC · Aug 29, 2024VulnerabilityCVE-2023-41993CVE-2024-5274CVE-2024-4671+1 CVEs47
Microsoft Warns of Widening APT29 Espionage Attacks Targeting Global OrgsThe Hacker News·Jan 27, 06:01 UTC · Jan 27, 2024Threat actor57
Russia’s APT29 Targets Embassies With Ngrok and WinRAR ExploitInfosecurity Magazine·Nov 20, 10:00 UTC · Nov 20, 2023Threat actorCVE-2023-388360
Additional Entities Targeted by DarkSide Affiliate, TAG-21; Links to WellMess and Sliver InfrastructureRecorded Future·Jul 15, 00:00 UTC · Jul 15, 2025Ransomware57
APT29 Hackers Target High-Value Victims Using Rogue RDP Servers and PyRDPThe Hacker News·Dec 19, 06:09 UTC · Dec 19, 2024Threat actor45
CERT-UA Identifies Malicious RDP Files in Latest Attack on Ukrainian EntitiesThe Hacker News·Nov 1, 03:36 UTC · Nov 1, 2024Exploit / PoC60
Kremlin-linked hackers target Ukraine’s state, military agencies in new espionage campaignThe Record·Oct 25, 16:23 UTC · Oct 25, 2024Threat actor45
TeamViewer Detects Security Breach in Corporate IT EnvironmentThe Hacker News·Jul 7, 16:52 UTC · Jul 7, 2024Threat actor in the wild60
Five Eyes Agencies Expose APT29's Evolving Cloud Attack TacticsThe Hacker News·Feb 28, 03:29 UTC · Feb 28, 2024Threat actor57
CISA Issues Alert on APT29’s Cloud Infiltration TacticsInfosecurity Magazine·Feb 26, 17:15 UTC · Feb 26, 2024Threat actor57
Russian SVR-Linked APT29 Targets JetBrains TeamCity Servers in Ongoing AttacksThe Hacker News·Dec 15, 00:00 UTC · Dec 15, 2023Threat actor in the wildCVE-2023-4279360
CISA, FBI, NSA reveal five enterprise bugs exploited by Russia's APT29 groupThe Record·Jan 26, 00:00 UTC · Jan 26, 2023Threat actorCVE-2018-13379CVE-2019-9670CVE-2019-11510+2 CVEs60
MITRE asks vendors to do more to detect stealthy hacksCyberScoop·May 1, 20:31 UTC · May 1, 2019Exploit / PoC in the wild60
Russian-Related Threats to the 2020 US Presidential ElectionRecorded Future·Nov 21, 00:00 UTC · Nov 21, 2025Ransomware57
TeamViewer: Hackers copied employee directory data and encrypted passwordsThe Record·Jul 1, 19:19 UTC · Jul 1, 2024Threat actor45
When Pentest Tools Go Brutal: Red-Teaming Tool Being Abused by Malicious ActorsPalo Alto Unit 42·Jun 5, 20:22 UTC · Jun 5, 2024AI safety & security30
Russian Hackers Use 'WINELOADER' Malware to Target German Political PartiesThe Hacker News·Mar 23, 06:03 UTC · Mar 23, 2024Malware42
Cyber-espionage operation on embassies linked to Russia’s Cozy Bear hackersThe Record·Nov 14, 16:45 UTC · Nov 14, 2023Threat actorCVE-2023-3883160
PDF lures aimed at NATO countries contain a Russian clueThe Record·Aug 15, 20:07 UTC · Aug 15, 2023Malware55
Russian Hackers Targeting Diplomatic Entities in Europe, Americas, and AsiaThe Hacker News·May 11, 02:46 UTC · May 11, 2022Data breach57
Experts Uncover Several C&C Servers Linked to WellMess MalwareThe Hacker News·Jul 30, 10:00 UTC · Jul 30, 2021Malware42
Russian government hackers targeting coronavirus vaccine research, UK, US and Canada warnCyberScoop·Jul 16, 15:47 UTC · Jul 16, 2020Ransomware in the wild60
Enriching User Behavior Analytics With Threat IntelligenceRecorded Future·Jun 24, 00:00 UTC · Jun 24, 2026Exploit / PoC60
Russian hackers using red team tools for largeThe Record·Dec 18, 20:31 UTC · Dec 18, 2024AI safety & security130
German political party targeted by SVR-linked group in spearphishing campaign, Mandiant saysCyberScoop·Mar 22, 17:52 UTC · Mar 22, 2024Threat actor in the wild60
Five Eyes nations warn of evolving Russian cyberespionage practices targeting cloud environmentsCyberScoop·Feb 26, 17:18 UTC · Feb 26, 2024Threat actor in the wild60
HPE Says SolarWinds Hackers Accessed its EmailsInfosecurity Magazine·Jan 25, 09:30 UTC · Jan 25, 2024Threat actor45
Pro-Russian Hackers Exploiting Recent WinRAR Vulnerability in New CampaignThe Hacker News·Nov 18, 05:56 UTC · Nov 18, 2023VulnerabilityCVE-2023-3883160
Russian Hackers Use Zulip Chat App for Covert C&C in Diplomatic Phishing AttacksThe Hacker News·Aug 18, 03:58 UTC · Aug 18, 2023Phishing & fraud55
Microsoft Uncovers New Post-Compromise Malware Used by Nobelium HackersThe Hacker News·Aug 30, 03:22 UTC · Aug 30, 2022Malware42
How attackers use and abuse Microsoft MFAHelp Net Security·Aug 24, 00:00 UTC · Aug 24, 2022Data breach45
Russian hacking unit Cozy Bear adds Google Drive to its arsenal, researchers sayCyberScoop·Jul 19, 10:00 UTC · Jul 19, 2022Threat actor in the wild60
Evidence suggests Russia's SVR is still using 'WellMess' malware, despite US warningsCyberScoop·Jul 30, 14:19 UTC · Jul 30, 2021Malware in the wild60
Researchers Find Additional Infrastructure Used By SolarWinds HackersThe Hacker News·Apr 22, 16:39 UTC · Apr 22, 2021Malware42
Russian APT Crew Actively Targets COVID19 Vaccine DevelopersInfosecurity Magazine·Jul 16, 15:46 UTC · Jul 16, 2020Vulnerability55