UNC5976: Russian Threat Actor Automating OAuth Token Theft via Cloud Infrastructure
UNC5976 is a suspected Russian threat actor active since at least March 2026, using OAuth phishing and automated token collection. It creates…
UNC5976 is a suspected Russian threat actor active since at least March 2026, using OAuth phishing and automated token collection. It creates…
HEADRUSH is a rogue Excel plugin used by UNC5976 to deliver an HTML Application (HTA) download. Discovered in April 2026, it is…
UNC6353 is a threat actor identified by Censys as potentially leveraging both DarkSword and Coruna exploit kits in attacks targeting Ukrainian entities.…
Ukrainian special services refer to intelligence and security agencies of Ukraine, including the Security Service of Ukraine (SBU). They have been accused…
The Federal Security Service of the Russian Federation (FSB) has charged Telegram founder Pavel Durov with aiding terrorist activity and failing to…
UAC-0099 is a Russia-aligned threat cluster tracked by CERT-UA, active since at least mid-2022. It has used phishing emails and exploits in…
At least one Russian intelligence service is systematically hijacking internet-connected security cameras across Europe and Ukraine to spy on military logistics, according…
Russian state-sponsored threat actors from the UAC-0145 sub-cluster, linked to Sandworm and GRU, are using fake CAPTCHA checks on compromised websites to…
UAC-0145 is a threat cluster tracked by CERT-UA, identified as a subgroup within the Sandworm APT group. It has been active since…
The Computer Emergency Response Team of Ukraine (CERT-UA) is the national cybersecurity incident response team. It disclosed the UAC-0145 campaign and provides…