North Korea-Linked npm Packages Mimic Rollup Polyfills to Steal Developer Secrets
Threat actors with ties to North Korea have been linked to a fresh set of malicious npm packages that masquerade as Rollup…
MITRE ATT&CK groups, threat actors, intrusion sets and activity clusters.
Threat actors with ties to North Korea have been linked to a fresh set of malicious npm packages that masquerade as Rollup…
A previously undocumented threat actor, Armored Likho, has been attributed to cyber attacks targeting government agencies and the electric power sector across…
Armored Likho is a previously undocumented threat actor targeting government agencies and electric power sectors in Russia, Brazil, and Kazakhstan. They blend…
Eagle Werewolf is a threat cluster tracked by BI.ZONE, active since May 2023, targeting government and defense organizations, especially those involved in…
ToddyCat is an advanced persistent threat group that exploited a search-order flaw in ESET's command-line scanner to load malicious DLLs. This was…
An AI-agent-driven operator first documented by Sysdig. Deployed ENCFORGE ransomware against Langflow servers, using Docker socket for host breakout. Previously used throwaway…
MUT-1244 is a campaign that used fake PoC repositories to steal SSH keys and cloud credentials from red teamers and researchers, similar…
The recently discovered financially-motivated FortiBleed campaign has been attributed to INC and Lynx ransomware operations, indicating that the verified, stolen credentials were…
A ransomware operation linked to the FortiBleed campaign, with an operator using FortiBleed infrastructure to access negotiation panels and deploy ransomware.
A ransomware operation linked to the FortiBleed campaign, with an operator using FortiBleed infrastructure to access negotiation panels and deploy ransomware.