OilRig (APT34): Iranian Threat Actor
OilRig, also known as APT34, is an Iranian threat actor linked to Cavern with low confidence. It has used Microsoft-hosted services for…
MITRE ATT&CK groups, threat actors, intrusion sets and activity clusters.
OilRig, also known as APT34, is an Iranian threat actor linked to Cavern with low confidence. It has used Microsoft-hosted services for…
A suspected China-nexus threat activity cluster, codenamed Operation DragonReturn by Seqrite Labs, has been targeting Indian taxpayers, tax professionals, and corporate finance…
Silver Fox is a threat actor known for using ValleyRAT and other custom payloads. The Spark RAT campaign shows operational similarities to…
REF3864 is an intrusion set attributed by Elastic Security Labs for targeting Chinese-speaking regions with malicious installers for Telegram and Opera, delivering…
Conti is a ransomware group that DevMan claimed to have worked with, according to an interview with security researcher Jon DiMaggio. DevMan…
Black Basta is a ransomware group whose internal chats leaked in February 2025, revealing negotiation patterns similar to the Kairos case.
Kairos is a cyber extortion group that operates without encryption, relying solely on data theft and threats of public exposure. It demanded…
Silent Ransom Group, a Conti offshoot, has conducted pure data-theft extortion against U.S. law and finance firms without using encryptors.
A cluster within the PolinRider campaign that drops malicious VS Code task files into GitHub users' repositories. The tasks use 'runOn: folderOpen'…
North Korean threat actors linked to the Contagious Interview campaign have published 108 unique malicious packages and browser extensions across npm, Packagist,…