Ice Relic (APT29/Cozy Bear/Midnight Blizzard): Russian State-Sponsored APT
Ice Relic, also known as APT29, Cozy Bear, and Midnight Blizzard, is a Russian state-sponsored threat group. Sub-clusters UNC6293 and UNC7005 are…
Ice Relic, also known as APT29, Cozy Bear, and Midnight Blizzard, is a Russian state-sponsored threat group. Sub-clusters UNC6293 and UNC7005 are…
FamousSparrow is a threat actor known for targeting government entities in Central Asia, often exploiting vulnerabilities in web applications and using custom…
CL-STA-0048 is a China-nexus espionage cluster that has been linked to the exploitation of SAP NetWeaver vulnerabilities, including CVE-2025-31324.
CVE-2025-31324 is a critical vulnerability in SAP NetWeaver that has been weaponized by China-nexus espionage clusters such as UNC5221, UNC5174, and CL-STA-0048,…
UNC5221 is a China-nexus espionage cluster that has been observed exploiting SAP vulnerabilities, including CVE-2025-31324, to compromise targets. The group is known…
Earth Alux is a threat cluster identified by Trend Micro that overlaps with Jewelbug. It is linked to espionage operations and uses…
REF7707 is a threat cluster tracked by Elastic Security Labs that overlaps with Jewelbug. It is associated with cyber espionage and shares…
GoSerpent is a previously undocumented Go-based backdoor and remote access trojan (RAT) used in cyber attacks targeting Southeast Asian government and diplomatic…
TetrisPhantom is a highly skilled and resourceful threat actor first documented by Kaspersky in October 2023. It targets government entities in the…
DoNot Team is a threat actor that conducted a targeted cyber espionage operation against Bangladesh's military and defence establishments using spear-phishing emails…