Agenda ransomware — Attack group profile
Agenda ransomware was identified as a relevant cybersecurity entity in recently ingested reporting. This profile is generated so related cyber news, CVEs,…
MITRE ATT&CK groups, threat actors, intrusion sets and activity clusters.
Agenda ransomware was identified as a relevant cybersecurity entity in recently ingested reporting. This profile is generated so related cyber news, CVEs,…
A threat actor documented by Check Point, associated with the WebDAV hijack technique (CVE-2025-33053) used in this campaign.
At least one Russian intelligence service is systematically hijacking internet-connected security cameras across Europe and Ukraine to spy on military logistics, according…
A solo Russian-speaking threat actor known as "bandcampro" has been observed using Google's open-source Gemini CLI AI to control a botnet of…
A solo Russian-speaking threat actor known as bandcampro has been observed using Google Gemini CLI to control a botnet of eight dental…
Russian state-sponsored threat actors from the UAC-0145 sub-cluster, linked to Sandworm and GRU, are using fake CAPTCHA checks on compromised websites to…
UAC-0145 is a sub-cluster within the Sandworm advanced hacking unit, affiliated with Russia's GRU. It has been attributed by CERT-UA to campaigns…
The GRU is Russia's primary foreign military intelligence agency, which sponsors advanced hacking units like Sandworm and its sub-clusters such as UAC-0145.
A previously undocumented threat actor tracked by Volexity, observed exploiting multiple zero-day vulnerabilities in SonicWall SMA VPN appliances to gain root access.
SuccessKey is the threat actor attributed to the ViteVenom and ChainVeil campaigns, which use blockchain-based C2 infrastructure to deliver remote access trojans…