TA-NATALSTATUS: Activity Linked to TeamPCP
TA-NATALSTATUS is a threat actor tracked by security researchers, with activity overlapping with TeamPCP. Oligo Security noted that TeamPCP-linked infrastructure has been…
TA-NATALSTATUS is a threat actor tracked by security researchers, with activity overlapping with TeamPCP. Oligo Security noted that TeamPCP-linked infrastructure has been…
IronErn is another threat actor identified by researchers as having overlapping infrastructure and techniques with TeamPCP. The exact relationship remains unclear, but…
MarlboroMan is a threat actor who advertised RedC2 on Hack Forums and operates the Red Offsec website, selling the C2 framework for…
MoYu Group is a threat actor group attributed with high confidence to the BADBOX ad fraud and residential proxy scheme. They were…
Google Threat Intelligence Group attributes the axios npm compromise to MIDNIGHT NEPTUNE, formerly known as UNC1069. The actor is linked to North…
GoldFactory is a Chinese-speaking threat actor linked to multiple Android and iOS banking malware families, including GoldDigger, GoldPickaxe, GoldDiggerPlus, and GoldKefu. The…
Agent IDE is a Microsoft Visual Studio Code extension published in the official marketplace by a threat actor known as 'johnnysilverhe', who…
The North Korean threat actors behind the ClickFix-style campaigns that employ typosquatted Zoom and Microsoft Teams domains have been found to operate…
SuccessKey is the threat actor attributed to the ViteVenom and ChainVeil campaigns, which use blockchain-based C2 infrastructure to deliver remote access trojans…
TetrisPhantom is a highly skilled and resourceful threat actor first documented by Kaspersky in October 2023. It targets government entities in the…