HollowGraph Malware Overview
HollowGraph is a .NET DLL espionage implant discovered by Group-IB that uses Microsoft 365 calendar events dated to 2050 for command-and-control and…
HollowGraph is a .NET DLL espionage implant discovered by Group-IB that uses Microsoft 365 calendar events dated to 2050 for command-and-control and…
GoSerpent is a previously undocumented Go-based backdoor and remote access trojan (RAT) used in cyber attacks targeting Southeast Asian government and diplomatic…
TetrisPhantom is a highly skilled and resourceful threat actor first documented by Kaspersky in October 2023. It targets government entities in the…
DoNot Team is a threat actor that conducted a targeted cyber espionage operation against Bangladesh's military and defence establishments using spear-phishing emails…
Lyceum is a subgroup of the Iranian OilRig group, involved in cyber espionage. Group-IB notes a low-confidence overlap with the HollowGraph campaign.
OilRig is an Iranian state-sponsored cyber espionage group active since 2014, targeting various sectors globally. Lyceum is a subgroup of OilRig.
The Russian-linked Turla APT group has been deploying backdoors in new campaigns, continuing its long-standing espionage operations.
MuddyWater is an Iranian state-sponsored cyber espionage group known for targeting government and private sectors in the Middle East and elsewhere. It…
Velvet Ant, tracked by Sygnia, is a China-nexus threat actor known for targeting infrastructure components like F5 BIG-IP, Cisco NX-OS, and Linux…
UNC6508 is a China-linked cyber espionage group that compromised REDCap research servers and abused Google Workspace content compliance rules to exfiltrate sensitive…