FortiBleed Credential Theft Campaign
A large-scale credential-harvesting operation targeting FortiGate firewalls globally, stealing over 110 million credentials and linked to INC and Lynx ransomware operations.
MITRE ATT&CK groups, threat actors, intrusion sets and activity clusters.
A large-scale credential-harvesting operation targeting FortiGate firewalls globally, stealing over 110 million credentials and linked to INC and Lynx ransomware operations.
A threat actor known for deploying Warlock ransomware by exploiting vulnerabilities in on-premises SharePoint servers since mid-2025. Uses tools like Velociraptor, Cloudflare…
Octo Tempest is an alternative tracking name for the Scattered Spider extortion crew, used by threat intelligence firms to identify the group's…
UNC3944 is Mandiant's designation for the threat actor group known as Scattered Spider. The group has been involved in numerous high-profile extortion…
0ktapus is another alias for the Scattered Spider group, recognized for its use of phishing and social engineering to compromise organizations. The…
A 19-year-old alleged member of the Scattered Spider hacking group, Peter Stokes, has been extradited from Finland to the United States to…
The Brazilian Tetrade is a group of banking trojans identified by Kaspersky, including Grandoreiro, Guildma, Melcoz, and Ousaban (Javali). They originated in…
Kimsuky is a hacking unit under North Korea's Reconnaissance General Bureau, sanctioned by the U.S. Treasury in 2023. It focuses on intelligence…
Kinsing is a threat group known for cryptojacking operations, often deploying cryptocurrency miners on compromised systems. In this campaign, the Lambsys malware…
WatchDog is a threat group involved in cryptojacking, deploying miners on vulnerable systems. The Lambsys malware actively terminates WatchDog processes to maintain…