UAT-7810: Chinese APT Expanding ORB Networks
UAT-7810 is a Chinese advanced persistent threat (APT) actor responsible for maintaining and proliferating LapDogs, an Operational Relay Box (ORB) network. The…
MITRE ATT&CK groups, threat actors, intrusion sets and activity clusters.
UAT-7810 is a Chinese advanced persistent threat (APT) actor responsible for maintaining and proliferating LapDogs, an Operational Relay Box (ORB) network. The…
UAT-5918 is a China-nexus threat actor that has leveraged ORB networks maintained by UAT-7810 to conduct cyber attacks targeting critical infrastructure entities…
Storm-2372 is a nation-state threat actor that was among the first to use device code phishing in the wild, starting in 2024.…
U.S. prosecutors have linked an alleged member of the Scattered Spider cybercriminal group to a May 2025 intrusion at a luxury jewelry…
A suspected China-aligned threat activity cluster tracked as UNK_MassTraction by Proofpoint has been exploiting critical Roundcube webmail vulnerabilities to target physics and…
UNK_MassTraction is a suspected China-aligned threat activity cluster first detected by Proofpoint in May 2026. It targets physics and engineering departments at…
UNC5174 is a China-nexus espionage cluster that has exploited SAP vulnerabilities such as CVE-2025-31324. The group is associated with cyber espionage operations.
Iranian state-sponsored hackers affiliated with the Ministry of Intelligence and Security (MOIS) have been using a previously undocumented modular command-and-control (C2) framework…
Cavern Manticore is a hacking group affiliated with Iran's Ministry of Intelligence and Security (MOIS), known for using the Cavern C2 framework.…
Lyceum is a sub-group of OilRig, sharing overlaps with Cavern Manticore. It is involved in cyber espionage activities, often using custom malware.