COLDRIVER: Russian Hacking Group
COLDRIVER is a Russian hacking group known for phishing campaigns targeting opposition figures and human rights activists. The group was mentioned in…
MITRE ATT&CK groups, threat actors, intrusion sets and activity clusters.
COLDRIVER is a Russian hacking group known for phishing campaigns targeting opposition figures and human rights activists. The group was mentioned in…
RomCom is a Russian hacking group that has exploited CVE-2025-8088, a WinRAR vulnerability, in attacks targeting Ukraine. They are known for cyber…
Google Threat Intelligence Group (GTIG) has attributed a previously undocumented .NET backdoor named STOCKSTAY to the Russian state-sponsored threat actor Turla. The…
The Russian-linked Turla APT group has been deploying backdoors in new campaigns, continuing its long-standing espionage operations.
Sandworm is a Russian state-sponsored hacking group associated with the GRU, known for destructive cyber attacks. UAC-0145 is a sub-cluster within Sandworm.
Gamaredon is a Russian advanced persistent threat group that has been highly active against Ukrainian governmental and military institutions, using spear-phishing, custom…
MuddyWater is an Iranian state-sponsored cyber espionage group known for targeting government and private sectors in the Middle East and elsewhere. It…
ESET has uncovered two campaigns by the Vietnam-aligned threat actor OceanLotus (APT32) targeting domestic entities and stock investors with the SPECTRALVIPER backdoor.…
OceanLotus, also known as APT32, is a Vietnam-aligned advanced persistent threat group active since 2012. It has historically targeted foreign entities, including…
APT32 was identified as a relevant cybersecurity entity in recently ingested reporting. This profile is generated so related cyber news, CVEs, malware,…