EvilTokens Attack Group Uses Ghost Phishing for Microsoft 365 Account Takeover
EvilTokens is an attack group conducting ghost phishing campaigns targeting US and European businesses. They use Microsoft Device Code Phishing and AES-GCM…
MITRE ATT&CK groups, threat actors, intrusion sets and activity clusters.
EvilTokens is an attack group conducting ghost phishing campaigns targeting US and European businesses. They use Microsoft Device Code Phishing and AES-GCM…
A Chinese threat actor tracked as UAT-7810 is actively refining its bespoke malware to expand its Operational Relay Box (ORB) network by…
UAT-7810 is a Chinese advanced persistent threat (APT) actor responsible for maintaining and proliferating LapDogs, an Operational Relay Box (ORB) network. The…
UAT-5918 is a China-nexus threat actor that has leveraged ORB networks maintained by UAT-7810 to conduct cyber attacks targeting critical infrastructure entities…
Storm-2372 is a nation-state threat actor that was among the first to use device code phishing in the wild, starting in 2024.…
U.S. prosecutors have linked an alleged member of the Scattered Spider cybercriminal group to a May 2025 intrusion at a luxury jewelry…
A suspected China-aligned threat activity cluster tracked as UNK_MassTraction by Proofpoint has been exploiting critical Roundcube webmail vulnerabilities to target physics and…
UNK_MassTraction is a suspected China-aligned threat activity cluster first detected by Proofpoint in May 2026. It targets physics and engineering departments at…
A suspected Chinese state group linked by Sysdig to the SNOWLIGHT-to-VShell toolchain in April 2025. The same tools were used by WP-SHELLSTORM,…
Iranian state-sponsored hackers affiliated with the Ministry of Intelligence and Security (MOIS) have been using a previously undocumented modular command-and-control (C2) framework…