FIN7: Cybercrime Group Known for Targeting Endpoint Security
FIN7 is a financially motivated cybercrime group that has been active since at least 2015. They are known for targeting the hospitality,…
MITRE ATT&CK groups, threat actors, intrusion sets and activity clusters.
FIN7 is a financially motivated cybercrime group that has been active since at least 2015. They are known for targeting the hospitality,…
Suspected Russian cyber espionage groups are abusing legitimate authentication flows, including Google OAuth and WhatsApp device linking, to hijack accounts across Europe…
UNC6293 is a suspected Russian cyber espionage sub-cluster of Ice Relic (APT29), first detailed in June 2025. It conducts small-scale phishing campaigns…
UNC5976 is a suspected Russian threat actor active since at least March 2026, using OAuth phishing and automated token collection. It creates…
UNC7005, also known as Storm-2945, is a suspected Russian threat actor identified in February 2026. It targets academia, diplomatic, and nonprofit personnel…
Ice Relic, also known as APT29, Cozy Bear, and Midnight Blizzard, is a Russian state-sponsored threat group. Sub-clusters UNC6293 and UNC7005 are…
Google Threat Intelligence Group attributes the axios npm compromise to MIDNIGHT NEPTUNE, formerly known as UNC1069. The actor is linked to North…
GoldFactory is a Chinese-speaking threat actor linked to multiple Android and iOS banking malware families, including GoldDigger, GoldPickaxe, GoldDiggerPlus, and GoldKefu. The…
A newly uncovered cyber espionage operation dubbed SilkParasite has been targeting government bodies in Central Asia, according to a technical report from…
SilkParasite is a China-nexus cyber espionage threat cluster first discovered in late 2025. It targets government bodies in Central Asia, using a…