Threat Research

    Suspected Chinese cyber actors have increasingly targeted Philippine government, defense, and critical infrastructure amid South China Sea tensions. Digital Defense Report 2025 ranked the Philippines 20th globally among countries most affected by cyber activity in H1 2025....
    QTFY, a China-linked hacking group attributed to Nanjing Xinjiuwei Network Technology Co. (XJW), has conducted cyber operations targeting U.S. critical infrastructure, including the defense industrial base, telecommunications, local governments, and higher education....
    Researchers highlight attacks targeting exposed AI infrastructure, including LiteLLM, RAGFlow, and Kestra, where adversaries exploited AI gateways and orchestration platforms for credential theft, remote code execution, persistence, container discovery, and cryptomining....
    A ValleyRAT campaign targeting organizations in India impersonates the Indian Income Tax Department through bilingual Hindi-English phishing emails and fake tax notices. Victims are directed to download a ZIP archive containing a legitimately signed Overwolf executable, which sideloads a malicious DLL and encrypted payload to deploy ValleyRAT....
    Researchers analyzed 405 AI-enabled malware samples and found that only a small fraction showed evidence of activity in production environments, with most being PoCs, security testing samples, or AI-themed malware....
    CoolClient is a backdoor family linked to the HoneyMyte (Mustang Panda) APT group, targeting organizations across Asia and Russia. It supports capabilities such as keylogging, clipboard theft, credential harvesting, file management, and system reconnaissance....
    Jewelbug is a China-based hackers-for-hire/APT group conducting parallel cyberespionage and cryptocurrency fraud operations across the Middle East, Southeast Asia, and South Asia. The group uses its XG-Web remote-access framework, Antino backdoor, and malicious browser extensions to steal credentials, cookies, and sensitive data while maintaining access to victim networks....
    Malicious npm packages are being used to hide a Linux backdoor inside calendar and streak-calculation tools. The packages provide legitimate date-related functions, making the malicious activity difficult to detect. The attack starts when an affected package is imported into an application....
    UAT-10147 is a Chinese-speaking intrusion actor targeting IIS and Linux servers with a sophisticated post-exploitation toolkit that combines custom malware, SEO fraud, and advanced persistence....
    A researcher was targeted after Black Hat/DEF CON by a threat actor using X DMs and fake conference planning to build trust. The researcher identified the scam but continued engaging with the actor to study their tactics. The campaign targeted both macOS and Windows users with different malware payloads....
    The WeedHack campaign is a Malware-as-a-Service (MaaS) operation that targets Minecraft players through fake gaming websites, SEO poisoning, and YouTube lures distributing malicious mods and clients....
    Medusa is a Ransomware-as-a-Service (RaaS) operation first identified in 2021 that uses double extortion, encrypting victim data while threatening to leak stolen information. As of April 2026, Medusa actors had impacted more than 500 victims across critical sectors including healthcare, education, legal, insurance, technology, and manufacturing....
    Three suspected Russian cyber-espionage clusters are targeting individuals in academia, aerospace and defense, government, and think tanks across Europe and the United States. The groups abuse legitimate authentication and OAuth workflows to make phishing attempts appear more trustworthy and harder to detect....
    Autonomous AI agents are creating new security risks by connecting LLMs directly to operating systems. OpenClaw lets AI execute commands, access files, and modify local environments, expanding the attack surface. Researchers first uncovered a supply chain campaign called ClawHavoc targeting the ClawHub skill registry....
    The StopAndProtect campaign is a multi-stage malware operation that begins with ClickFix social engineering, leading to PowerShell, .NET payloads and the deployment of ransomware, SMB/USB worm, credential stealer, VBS spreader, and LockScreen components....
    Looking for Something?
    Threat Research Categories:
    Tags