threat-intel ISC Stormcast For Friday, August 28th, 2026 https://isc.sans.edu/podcastdetail/10072, (Fri, Aug 28th) The ISC Stormcast highlighted a significant increase in malicious email campaigns targeting financial institutions with sophisticated spear-phishing attacks. The campaigns leveraged compromised credentials and utilized a novel technique to bypass email security filters, resulting in potential data breaches and financia… SANS Internet Storm Center · 2d ago High phishingcredential theftspear-phishing
threat-intel HollowFrame Loader Deploys Matryoshka Backdoor in Spear-Phishing Attack on Law Firm A previously undocumented Go-based loader framework called HollowFrame and a Rust-based malware family named Matryoshka were used in a spear-phishing attack targeting a law firm. The attack involved a multi-stage process… The Hacker News · Jul 31, 2026 High spear-phishinggorust
threat-intel Mirage Kitten targets Middle East and Africa region with new malware The advanced persistent threat (APT) group Mirage Kitten, also known as UNC1549, Smoke Sandstorm, and Nimbus Manticore, is aggressively targeting sectors in the Middle East and Africa, including aerospace, aviation, tele… Securelist · Jul 28, 2026 High EGJOTAaptmalwarethreat-intel
threat-intel China-Nexus JadeProx Uses New TriBack Loader in Government and Healthcare Attacks A China-nexus operation, tracked by Group-IB, dubbed JadeProx, is using a new loader called TriBack Loader to target government, healthcare, and education organizations across Asia and Latin America. The operation levera… The Hacker News · Jul 23, 2026 High CVE-2018-11511CVE-2021-24139CVE-2021-31755CHHOVIloaderspear-phishingvulnerability
threat-intel ISC Stormcast For Thursday, July 23rd, 2026 https://isc.sans.edu/podcastdetail/10020, (Thu, Jul 23rd) The ISC Stormcast highlighted a significant increase in malicious email campaigns targeting financial institutions with sophisticated spear-phishing attacks. The campaigns leveraged stolen credentials and a new, highly c… SANS Internet Storm Center · Jul 23, 2026 High phishingspear-phishingcredential-stuffing
threat-intel ISC Stormcast For Wednesday, July 22nd, 2026 https://isc.sans.edu/podcastdetail/10018, (Wed, Jul 22nd) The ISC Stormcast highlighted a significant increase in malicious email campaigns targeting financial institutions with sophisticated spear-phishing attacks. The campaigns leveraged compromised credentials and utilized a… SANS Internet Storm Center · Jul 22, 2026 High phishingcredential-stuffingemail-security
apt Armored Likho APT Targeting Government, Electric Power Entities The Armored Likho APT group is actively targeting government and electric power entities across multiple countries, including Russia, Brazil, and Kazakhstan. The group utilizes a diverse toolkit of malware, including RAT… SecurityWeek · Jul 6, 2026 High RUBRKZaptspear-phishingrat
threat-intel Armored Likho Targets Government Agencies, Power Sector with BusySnake Stealer Armored Likho, a previously undocumented threat actor, has been actively targeting government agencies and the power sector in Russia, Brazil, and Kazakhstan with a sophisticated campaign utilizing tools like BusySnake S… The Hacker News · Jul 3, 2026 High CVE-2025-9491RUBRKZspear-phishingremote access trojaninformation stealer
malware VEIL#DROP Malware Chain Uses Blogger Platform to Deliver PureLogs Stealer A new multi-stage malware attack chain, dubbed VEIL#DROP, is utilizing social engineering and Blogger pages to deliver the PureLogs stealer. The attack begins with a deceptive JavaScript file, leveraging Google's infrast… The Hacker News · Jul 1, 2026 High USspear-phishingbloggerpurelogs
threat-intel Gamaredon Expands Ukraine Attacks with New Malware and Cloud Service Abuse The Gamaredon APT group continued its aggressive cyberattacks against Ukraine throughout 2025, utilizing a range of new malware and exploiting vulnerabilities to steal sensitive information. The group expanded its tactic… The Hacker News · Jun 29, 2026 High CVE-2025-8088RUUAspear-phishingpersistencecloud-services
threat-intel Fake Microsoft Alerts Used to Deploy North Korean NarwhalRAT Malware North Korean APT37 group utilized a spear-phishing campaign mimicking Microsoft security alerts to deploy NarwhalRAT malware. The campaign leveraged urgency and confusion to trick victims into executing a malicious LNK f… The Hacker News · Jun 16, 2026 High NOSOspear-phishingratnorth korean
threat-intel WhatsApp says NSO targeted users with spearfishing attacks in violation of court order WhatsApp has accused NSO Group of violating a court order by conducting spearfishing attacks against its users, utilizing social engineering techniques to lure individuals into clicking malicious links. This follows a pr… The Record · Jun 8, 2026 High USspear-phishingsocial-engineeringspyware
apt Pakistan Spies on Afghan Finance Ministry With Xeno RAT A Pakistani advanced persistent threat (APT) group, identified as SideCopy and linked to the Transparent Tribe (APT 36), has been conducting espionage against Afghanistan's finance ministry since at least May 2025. The g… Dark Reading · Jun 4, 2026 High AFPKspear-phishingremote-accesspashto
threat-intel China Uses Dual-Method Cyberattack on Czech Orgs This article details a dual-method cyberattack targeting organizations in the Czech Republic and Taiwan, orchestrated by Chinese nation-state threat actors. The campaign, dubbed "Operation Dragon Weave," utilizes a spear… Dark Reading · Jun 2, 2026 High CZCNTWspear-phishingrustazure
threat-intel China-Aligned Groups Ramp Up Attacks: Dragon Weave Hits Czech Republic & Taiwan A new cyber espionage campaign, dubbed Operation Dragon Weave, is targeting government, research, and financial institutions in the Czech Republic and Taiwan using spear-phishing emails and a Rust-based loader to deploy… The Hacker News · Jun 1, 2026 High CZTWINspear-phishingc2azure
threat-intel New Russian-Linked GREYVIBE Targets Ukraine with AI-Powered Cyberattacks A new, Russian-linked cyber threat group, dubbed GREYVIBE, has been targeting Ukraine and related entities since August 2025 with a range of sophisticated attacks. The group utilizes multiple attack vectors, including ph… The Hacker News · May 29, 2026 High RUrussianaigenai