Ghostwriter — Attack group profile
Ghostwriter was identified as a relevant cybersecurity entity in recently ingested reporting. This profile is generated so related cyber news, CVEs, malware,…
MITRE ATT&CK groups, threat actors, intrusion sets and activity clusters.
Ghostwriter was identified as a relevant cybersecurity entity in recently ingested reporting. This profile is generated so related cyber news, CVEs, malware,…
The FBI and CISA have updated their March warning about Russian intelligence phishing Signal accounts, adding a new tactic where attackers coax…
UNC5792, also tracked as UAC-0195, is a Russian threat cluster involved in credential theft campaigns against messaging platforms, targeting government and military…
UNC4221, also known as UAC-0185, is a Russian threat actor conducting phishing attacks on messaging applications to steal user credentials and sensitive…
Russian Intelligence Services (RIS) encompass multiple groups including FSB officers and Russian military personnel. They conduct cyber espionage campaigns targeting government officials,…
An unidentified threat actor assessed by Hunt.io with low-to-medium confidence to be Chinese-speaking or fluent in Chinese. The actor deployed a Hermes…
A Chinese-speaking advanced persistent threat (APT) actor has been linked to a new custom backdoor called TinyRCT as part of cyber attacks…
CL-STA-1062 is a Chinese-speaking advanced persistent threat actor linked to cyber attacks on government entities and critical infrastructure in Southeast Asia. It…
UAT-7237 is a hacking group first flagged by Cisco Talos in August 2025 for campaigns against web infrastructure entities in Taiwan. It…
The FSB is the principal security agency of Russia, responsible for counterintelligence, internal security, and border security. It has been involved in…