DPRK (North Korea) Cyber Threat Activity
State-sponsored threat actors from North Korea (DPRK) are known for sophisticated cyber operations targeting cryptocurrency, defense, and technology sectors. This campaign uses…
MITRE ATT&CK groups, threat actors, intrusion sets and activity clusters.
State-sponsored threat actors from North Korea (DPRK) are known for sophisticated cyber operations targeting cryptocurrency, defense, and technology sectors. This campaign uses…
REvil, also known as Sodinokibi, is a notorious ransomware-as-a-service group that operated from April 2019 to July 2021, targeting over 1,000 victims…
Sodinokibi is the malware variant associated with the REvil ransomware group, used in attacks from April 2019 to July 2021. It is…
TetrisPhantom is a highly skilled and resourceful threat actor first documented by Kaspersky in October 2023. It targets government entities in the…
DoNot Team is a threat actor that conducted a targeted cyber espionage operation against Bangladesh's military and defence establishments using spear-phishing emails…
Owen Flowers, 18, and Thalha Jubair, 20, were each sentenced to five and a half years at Woolwich Crown Court on July…
PhantomEnigma is an active malware campaign that evolved from a browser-extension banker into a modular Inno/Node.js backdoor. It uses compromised Brazilian government…
A China-linked threat actor is responsible for deploying Daxin and Stupig malware in targeted attacks against governments, critical infrastructure, and manufacturing firms.…
Keksec is a cybercriminal group known for running multiple IoT botnet variants in parallel, including TuxBot, Kaitori, and AISURU. They operate a…
UNK_pyreq2323 is a threat cluster that exploited OAuth client ID spoofing from January to March 2026, using over 700,000 spoofed client IDs…