UNC4221 (UAC-0185): Russian Threat Actor in Messaging Phishing
UNC4221, also known as UAC-0185, is a Russian threat actor conducting phishing attacks on messaging applications to steal user credentials and sensitive…
MITRE ATT&CK groups, threat actors, intrusion sets and activity clusters.
UNC4221, also known as UAC-0185, is a Russian threat actor conducting phishing attacks on messaging applications to steal user credentials and sensitive…
Russian Intelligence Services (RIS) encompass multiple groups including FSB officers and Russian military personnel. They conduct cyber espionage campaigns targeting government officials,…
Chinese-speaking threat actor was identified as a relevant cybersecurity entity in recently ingested reporting. This profile is generated so related cyber news,…
A Chinese-speaking advanced persistent threat (APT) actor has been linked to a new custom backdoor called TinyRCT as part of cyber attacks…
CL-STA-1062 is a Chinese-speaking advanced persistent threat actor linked to cyber attacks on government entities and critical infrastructure in Southeast Asia. It…
UAT-7237 is a hacking group first flagged by Cisco Talos in August 2025 for campaigns against web infrastructure entities in Taiwan. It…
The FSB is the principal security agency of Russia, responsible for counterintelligence, internal security, and border security. It has been involved in…
COLDRIVER is a Russian hacking group known for phishing campaigns targeting opposition figures and human rights activists. The group was mentioned in…
RomCom is a Russian hacking group that has exploited CVE-2025-8088, a WinRAR vulnerability, in attacks targeting Ukraine. They are known for cyber…
Google Threat Intelligence Group (GTIG) has attributed a previously undocumented .NET backdoor named STOCKSTAY to the Russian state-sponsored threat actor Turla. The…