All Intelligence

Campaigns

Threat actor campaigns, intrusion sets, and coordinated attack activity.

151 items

highCampaignActive

BlueNoroff Operationalises Crypto-Targeted Phishing Through Compromised Industry Contacts and Typosquatted Domains

North Korean threat actor BlueNoroff is running a sophisticated phishing campaign that impersonates Zoom and Microsoft Teams via typosquatted domains to profile cryptocurrency wallet holders before delivering malware. The operation combines trusted industry contact compromise with social engineering to increase success rates.

Zoom, Microsoft Teams, Cryptocurrency wallet users
highCampaignActive

FakeGit Campaign Exploits GitHub's Open Model to Distribute SmartLoader Malware at Scale

A campaign termed FakeGit has created approximately 7,600 malicious GitHub repositories, with over 800 impersonating AI tools and Model Context Protocol servers to deliver SmartLoader malware. The campaign exploits GitHub's accessibility and developer trust in open-source repositories to achieve broad distribution.

GitHub, Developers using GitHub repositories, AI tools and MCP server projects
highCampaignActive

Multi-vector intelligence and malware campaign: Iranian APT activity, macOS CrashStealer, and strategic infrastructure targeting

SecurityWeek aggregates multiple concurrent threats: Iranian state actors tracking US military communications, CrashStealer malware targeting macOS users, ransomware targeting naval defence contractor TKMS, and broader supply-chain compromise vectors. This represents a portfolio of sophisticated, active threats across government, commercial, and critical infrastructure sectors.

US Military communications infrastructure, macOS platforms, TKMS (ThyssenKrupp Marine Systems) +2
highCampaignActive

Abbott's dual breach exposes risks in legacy healthcare infrastructure and cloud portals

Abbott Laboratories is investigating two concurrent cybersecurity incidents: unauthorised access to legacy Exact Sciences systems in its Cancer Diagnostics division and a separate breach of its LabCentral portal with alleged data theft. The incidents highlight vulnerabilities in healthcare IT infrastructure spanning both legacy systems and modern cloud platforms.

Abbott Laboratories, Exact Sciences Cancer Diagnostics, LabCentral portal
highCampaignResolved

Scattered Spider operatives sentenced for £29M TfL ransomware attack demonstrating persistent threat from young, organised cybercriminals

Two members of the Scattered Spider cybercriminal group, Owen Flowers (18) and Thalha Jubair (20), received 5.5-year sentences for orchestrating a 2024 ransomware attack against Transport for London that disabled 148 systems and forced 27,000 employees to reset credentials in person. The sentencing marks a significant law enforcement victory but group's capacity to cause infrastructure-level disruption.

Transport for London
highCampaignActive

Vastaamo psychotherapy breach: international manhunt reveals ongoing fugitive status of alleged attacker

Finnish authorities have issued a wanted notice for a suspect linked to the Vastaamo psychotherapy data breach, with the defendant's legal counsel indicating the individual is believed to be outside Finland. This suggests the investigation remains active and potentially unresolved months or years after the initial breach.

Vastaamo (Finnish psychotherapy clinic chain)
highCampaignActive

Concurrent Chinese and Indian intelligence operations against Pakistani law enforcement reveal strategic divergence in South Asian cyber espionage

Chinese and Indian state-sponsored actors conducted separate espionage campaigns targeting the same Pakistani police organisation, each motivated by distinct geopolitical interests in Pakistan's internal security apparatus. This convergence demonstrates how critical infrastructure becomes a contested domain when multiple regional powers perceive overlapping strategic value.

Pakistani law enforcement agencies
highCampaignActive

Extortion Without Encryption: Kairos Group Monetises Data Theft Against U.S. Government Without Traditional Ransomware

A U.S. government entity paid approximately $1 million to the Kairos group to prevent stolen data from being published, despite no evidence that Kairos deployed encryption or conducted a traditional ransomware attack. This represents a shift in extortion tactics where data theft alone, without operational disruption, suffices to extract payment.

U.S. Government Entity (unspecified)
highCampaignActive

Three disparate security incidents highlight enforcement trends: hacktivist prosecution, open source supply-chain risk, and organised financial crime

SecurityWeek reports on three unrelated incidents: an Anonymous-affiliated Canadian hacker imprisoned, zero-days disclosed in open source projects, and Venezuelan nationals convicted for ATM jackpotting schemes. Collectively, they illustrate sustained pressure on hacktivists, emerging supply-chain vulnerabilities, and organised cybercrime targeting financial infrastructure.

open-source projects, ATM networks
highCampaignActive

Google Disrupts NetNut Residential Proxy Network: Law Enforcement Success Against Distributed Infrastructure Abuse

Google's Threat Intelligence Group, working with the FBI and Lumen, significantly degraded the NetNut residential proxy network by reducing its device pool by millions. This coordinated action targets infrastructure used for credential stuffing, ad fraud, and anonymised malicious activity across compromised home devices.

NetNut (Popa), Home broadband subscribers, Online services targeted by fraud
highCampaignActive

Pegasus Spyware Deployed Against European Parliament Investigator: Targeting of Oversight Creates Political Vulnerability

Stelios Kouloglou, a European Parliament member investigating commercial spyware abuses, was infected with Pegasus spyware twice during his tenure on the PEGA committee. This represents a direct attack on parliamentary oversight mechanisms and suggests threat actors are targeting those scrutinising spyware exports.

Pegasus (NSO Group), European Parliament
highCampaignActive

Scattered Spider operative extradited: teenage member faces US charges for luxury retail breach

A 19-year-old suspect linked to Scattered Spider has been extradited to the US and faces charges for participating in breaches including a luxury jewellery retailer compromise in 2025. This marks a significant law enforcement action against an active criminal collective known for social engineering and supply chain targeting.

Luxury jewellery retailers, Organisations targeted by Scattered Spider
highCampaignActive

Large-scale password spray campaign targets Azure CLI with 81M+ attempts, compromising 78+ Microsoft accounts

A sustained password spray attack originating from an IPv6 range controlled by LSHIY LLC has targeted Azure CLI with over 81 million login attempts between mid-June and late June 2026, successfully compromising at least 78 Microsoft accounts. This represents a significant threat to organisations using Azure command-line tooling without robust account protection measures.

Microsoft Azure CLI, Microsoft Azure accounts
highCampaignActive

Email account compromise as identity system attack vector: why attackers prioritise inbox access

Cybercriminals target email accounts as a primary objective because inbox control grants access to password resets, financial accounts, and identity verification across an individual's digital footprint. This represents a fundamental shift in attack prioritisation from specific services to the authentication hub itself.

Email service users (all providers), Identity verification systems
criticalCampaignActive

Russian Intelligence Deploys Fake Support Messages to Harvest Ukrainian Official Credentials at Scale

Russian intelligence services conducted a sustained phishing campaign using fabricated support messages to compromise messaging accounts of Ukrainian government officials, military personnel, politicians, and activists across Europe and the US. The operation highlights a persistent state-level threat to high-value targets using social engineering rather than zero-days.

Messaging platforms (specific platforms not specified in source), Ukrainian government officials, Ukrainian military personnel +2
criticalCampaignActive

FortiBleed: Large-Scale Credential Harvesting Campaign Targeting 430,000+ FortiGate Firewalls Globally

A Russian-speaking initial access broker has been conducting a sustained credential-harvesting campaign against FortiGate firewalls since February 2026, compromising over 430,000 devices globally and harvesting approximately 110 million credentials. This represents a significant threat to enterprise network security infrastructure and likely serves as a precursor to deeper compromise or sale of access.

Fortinet FortiGate
criticalCampaignActive

UK Critical Infrastructure Faces Pre-positioned Nation-State Threats: NCSC Warns of Intelligence Gathering for Future Kinetic Operations

UK National Cyber Security Centre leadership has warned that hostile nation-states are behind approximately 75% of cyber attacks on British critical infrastructure and are actively pre-positioning access for use in future kinetic conflicts. This represents a shift from opportunistic compromise to strategic preparation for wartime operations.

UK critical infrastructure operators across multiple sectors
highCampaignActive

UNC3753 Executing Sustained Vishing Campaign Against US Legal Services

UNC3753 conducted a financially motivated data theft extortion campaign from January to May 2026 targeting US law firms and financial services using vishing and social engineering to gain remote access. The group's focus on high-value professional services sectors and reliance on human manipulation rather than technical exploits makes this a persistent threat requiring non-technical defences.

US law firms, professional services sector, financial services organisations
highCampaignActive

Gamaredon-Turla Operational Collaboration Signals Rare FSB-Linked Espionage Coordination Against Ukraine

ESET researchers have documented direct operational cooperation between Gamaredon and Turla, two FSB-linked threat actors, with Gamaredon facilitating initial access for Turla against Ukrainian targets in 2025. This represents an unusual departure from typical competitive dynamics between state-sponsored groups and suggests coordinated Russian intelligence operations.

Ukrainian government entities, Critical infrastructure operators in Ukraine
highCampaignActive

Escalating Russian Intelligence Operations Targeting Western Technology via Sanctions Evasion Networks

Russian state intelligence is intensifying efforts to acquire restricted Western technology through front companies, procurement intermediaries, and cyber operations to circumvent sanctions and support strategic infrastructure capabilities. This represents a coordinated supply-chain espionage campaign rather than isolated incidents.

Western technology sector (general), Critical infrastructure operators, Dual-use technology manufacturers
highCampaignActive

Three distinct threat vectors emerge: Trump Mobile breach, FIFA World Cup phishing campaign, and coordinated supply chain attacks prompt CISA response

SecurityWeek reports three concurrent security incidents: Trump Mobile customer data exposure, phishing attacks targeting FIFA World Cup 2026 attendees and stakeholders, and a supply chain attack wave that triggered official CISA intervention. Each represents a distinct threat pattern requiring different defensive responses.

Trump Mobile, FIFA World Cup 2026 infrastructure and stakeholders, unspecified supply chain vendors
highCampaignActive

Coordinated Banking Trojan Campaign Targets Latin America and Europe with Grandoreiro and BTMOB RAT

Two coordinated banking trojan campaigns deliver Grandoreiro malware to Windows systems and BTMOB RAT to Android devices across Spain, Portugal, Mexico, and Brazil. The targeting of financial institutions and mobile users suggests organised cybercriminal activity with cross-platform capabilities.

Windows systems, Android mobile devices, Financial institutions in Spain, Portugal, Mexico, and Brazil
highCampaignActive

Coordinated SEO poisoning and AI chatbot manipulation drives GPU mining malware distribution

Threat actors are executing a multi-vector cryptojacking campaign targeting high-performance computing systems through SEO poisoning and AI chatbot manipulation to distribute GPU mining malware. This hybrid approach exploits both traditional search ranking tactics and emerging AI recommendation systems to reach victims.

Systems with high-performance GPUs, Users of AI chatbot services, Search engine users
highCampaignActive

Multi-vector cryptojacking campaign exploits SEO poisoning, ScreenConnect, and .NET tools to target GPU resources

Threat actors are running a coordinated cryptojacking operation that uses SEO poisoning and AI chatbot abuse to distribute malicious sites, then deploys ScreenConnect and Microsoft .NET utilities as initial access and persistence mechanisms to hijack GPU resources on high-performance systems.

ScreenConnect, Microsoft .NET utilities, High-performance computing systems
highCampaignActive

Lithuania's state registry breach exposes 600,000 records: implications for EU critical infrastructure

Foreign attackers gained unauthorised access to 600,000 records from Lithuania's Centre of Registers, which manages property and legal entity data. This represents a significant compromise of state administrative infrastructure with potential implications for identity fraud and state surveillance.

Centre of Registers (Lithuania), Lithuanian state property records system, Lithuanian legal entity records system
highCampaignContained

Dutch Law Enforcement Dismantles Russian Cyberattack Infrastructure by Seizing 800 Servers and Arresting Hosting Operators

Dutch authorities arrested two co-owners of Internet hosting companies and seized approximately 800 servers used by Russian intelligence to stage cyberattacks, influence operations, and disinformation campaigns targeting the EU. The action disrupts a significant portion of Russia's operational infrastructure in Europe.

Stark Industries Solutions, EU organisations and member states
highCampaignActive

Chinese-language PhaaS ecosystem rivals Russian offerings, lowering attack barriers for regional threat actors

Google's threat intelligence team identified a dozen mature phishing-as-a-service offerings operating in Chinese-language underground forums, representing a significant shift in the geographic distribution of PhaaS infrastructure and suggesting intensified credential theft campaigns targeting organisations with Asia-Pacific exposure.

Organisations with Asia-Pacific operations, Enterprise email systems, Authentication systems
highCampaignContained

First VPN dismantled in Operation Saffron: law enforcement disrupts infrastructure used by 25 ransomware groups

European and North American authorities have shut down First VPN, a criminal VPN service that facilitated ransomware attacks, data theft, and DDoS operations for approximately 25 ransomware groups. The coordinated takedown represents a significant disruption to organised cybercrime infrastructure, though similar services remain operational.

First VPN Service, 25 ransomware groups (unnamed)
highCampaignContained

Interpol-led takedown disrupts Middle East scam infrastructure; 200+ arrests and hundreds of compromised devices recovered

Interpol-coordinated law enforcement operations arrested over 200 individuals operating cybercriminal scam networks across the Middle East and recovered hundreds of compromised devices used in the scheme. This represents a significant disruption to a regional fraud operation, though the technical sophistication and scale suggest similar networks remain active.

Hundreds of end-user devices (specific platforms not disclosed)
criticalCampaignResolved

UNC6671's BlackFile Campaign: Vishing and AiTM as a Vector to Cloud Extortion at Scale

UNC6671 operates BlackFile, an extortion campaign using sophisticated vishing and adversary-in-the-middle techniques to bypass MFA and compromise Microsoft 365 and Okta environments, exfiltrating corporate data for extortion. The attack chain circumvents traditional perimeter defences by targeting human authentication vectors rather than technical infrastructure.

Microsoft 365, Okta, Cloud environments
mediumCampaignResolved

Aggregated Security Digest: Multiple Vectors from Cloud Gaming Breaches to Legislative Pressure

SecurityWeek reports on multiple concurrent security issues including an Nvidia cloud gaming data breach, Canvas LMS compromise by ShinyHunters following FBI warning, Android 17 hardening, and automotive/enterprise vulnerabilities. The clustering suggests defenders face distributed pressure across consumer, educational, and enterprise sectors.

Nvidia, Canvas LMS, Android +2
highCampaignResolved

Chinese-linked FamousSparrow expands targeting to Azerbaijani energy sector via Microsoft Exchange exploitation

A Chinese-affiliated threat actor designated FamousSparrow conducted a multi-wave intrusion against an Azerbaijani oil and gas company between December 2025 and February 2026, exploiting Microsoft Exchange vulnerabilities as an initial access vector. This represents a notable shift in the group's targeting geography and suggests persistent interest in critical infrastructure.

Microsoft Exchange, Azerbaijani oil and gas sector
highCampaignResolved

Sustained Multi-Sector Phishing Campaign Targets 500+ Organisations Across Critical Infrastructure

A years-long phishing campaign has compromised over 500 organisations across aviation, energy, infrastructure, logistics, public administration, and technology sectors. The extended campaign duration and cross-sector targeting suggest either a sophisticated threat actor or multiple coordinated groups with sustained operational capability.

Aviation sector organisations, Critical infrastructure operators, Energy sector organisations +3
highCampaignContained

Juvenile actor breaches French administrative identity system, highlighting insider threat and data commodification risks

A 15-year-old was detained for allegedly stealing and selling data from France Titres (ANTS), the agency managing national identity and administrative documents. The incident demonstrates how young threat actors with technical capability can compromise high-value government systems and monetise sensitive personal data.

France Titres (ANTS), French Ministry of Interior
highCampaignResolved

Scattered Spider operator arrested in Finland: implications for distributed social engineering campaigns

A 19-year-old dual US-Estonian national arrested in Finland faces federal charges for membership in Scattered Spider, a prolific collective known for social engineering and financial fraud targeting critical sectors. The arrest demonstrates law enforcement coordination across jurisdictions but does not significantly disrupt the group's operational capacity.

Financial services, Technology sectors, Healthcare organisations
highCampaignResolved

Social Media Scams Cost Americans $2.1B in 2025: Systemic Platform Failure and Exploitation at Scale

The FTC reports that Americans lost over $2.1 billion to social media scams in 2025, representing a sustained and accelerating trend since 2020. This reflects a fundamental failure of platforms to implement effective fraud detection and user verification controls, creating an environment where scammers operate with minimal friction.

Meta/Facebook, Instagram, TikTok +3
highCampaignResolved

GopherWhisper's Go-Based Backdoor Infrastructure Signals Shift Toward Living-Off-The-Land Tactics in Chinese State Espionage

A China-linked APT group identified as GopherWhisper is conducting targeted campaigns against government entities using multiple Go-based backdoors combined with legitimate service abuse to evade detection. The group's reliance on custom loaders and injectors suggests a maturing operational capability focused on persistence and evasion.

Government agencies (specific sectors not disclosed)
highCampaignResolved

BlackFile extortion gang weaponises vishing at scale against retail and hospitality

BlackFile, a financially motivated threat actor, has orchestrated a coordinated campaign of data theft and extortion attacks against retail and hospitality organisations since February 2026, combining social engineering with data exfiltration. The group's use of vishing as a primary attack vector suggests a shift toward human-centric compromise rather than technical vulnerability exploitation.

Retail sector organisations, Hospitality sector organisations
highCampaignResolved

Teams as attack surface: threat actors weaponise Microsoft's collaboration platform for helpdesk impersonation and lateral movement

Microsoft has observed threat actors increasingly abusing external Teams channels to impersonate helpdesk staff, deceive users into credential disclosure, and establish footholds for lateral movement within enterprise networks. The attack exploits Teams' legitimacy and ubiquity to bypass social engineering defences.

Microsoft Teams, Enterprise organisations using Microsoft 365
highCampaignResolved

Gentlemen ransomware gang escalates infrastructure through SystemBC botnet integration

Gentlemen ransomware operators have integrated SystemBC proxy malware into their attack chain, leveraging a botnet of over 1,570 corporate hosts to obfuscate command-and-control communications and expand operational resilience. This represents a maturation of the gang's infrastructure and signals they are adopting commodity malware to increase attack surface.

Corporate networks (estimated 1,570+ victims)
highCampaignResolved

MSP sector faces escalating phishing-driven attacks; incident response strategies lag behind threat evolution

Phishing remains the primary attack vector for most cybercriminals, and managed service providers are struggling to implement integrated security and recovery strategies proportionate to current threat velocity. MSPs must evolve beyond reactive patching to include workable incident response and business continuity frameworks.

Managed Service Providers (MSPs), Corporate clients of MSPs
highCampaignResolved

Underground Carding Networks Standardise Vendor Vetting: Operationalising Trust in Stolen Payment Data Markets

Cybercrime forums now circulate structured guides teaching threat actors how to evaluate carding shops through data quality metrics, seller reputation scoring, and shop longevity assessment. This professionalisation of underground marketplaces reduces friction in stolen payment data transactions and increases the operational security of organised crime networks.

Payment card holders, Financial institutions, Carding shop operators
highCampaignResolved

Operation PowerOFF disrupts DDoS-for-hire ecosystem, exposing 75,000 botnet operators across 21 countries

Law enforcement and private sector security research identified and disrupted 75,000 DDoS botnet operators and took down 53 infrastructure domains in a coordinated operation spanning 21 countries. This represents significant progress against organised DDoS-as-a-service providers but signals the need for sustained pressure on the ecosystem.

DDoS-for-hire operators, Botnet infrastructure
highCampaignResolved

German Law Enforcement Unmasks REvil and GandCrab Operator: Attribution and the Limits of Operational Security

German authorities have publicly identified Daniil Maksimovich Shchukin, a 31-year-old Russian national, as the operator behind the REvil and GandCrab ransomware groups. The disclosure represents a significant attribution success but raises questions about law enforcement coordination and timing given the geopolitical context.

REvil victims (2019-2021), GandCrab victims (2019-2021), German organisations (130+ incidents)
criticalCampaignContained

Six-month DPRK social engineering campaign nets $285M from Drift DEX, exposing sustained targeting of crypto infrastructure

North Korean threat actors conducted a methodical six-month social engineering operation against Drift, a Solana-based decentralised exchange, culminating in a $285 million theft in April 2026. The campaign demonstrates DPRK's shift toward patient, targeted infiltration of high-value cryptocurrency platforms rather than opportunistic attacks.

Drift (Solana DEX)
criticalCampaignResolved

Automated credential harvesting via React2Shell exploitation in Next.js applications represents shift toward industrialised supply-chain attacks

Threat actors are conducting large-scale automated attacks exploiting CVE-2025-55182 (React2Shell) in vulnerable Next.js applications to harvest credentials at scale. This represents a shift from opportunistic patching cycles to industrialised credential theft targeting the JavaScript framework ecosystem.

CVE-2025-55182
Next.js, React applications
highCampaignContained

Operation Alice dismantles 373K fake CSAM scam infrastructure, exposing predatory fraud economy

International law enforcement shut down 373,000 dark web sites distributing fake child sexual abuse material (CSAM) packages, disrupting a fraud scheme that victimizes both potential offenders seeking illegal content and defrauds them. This represents a significant takedown of deceptive criminal commerce infrastructure.

Dark web marketplaces, Tor infrastructure, Anonymous payment systems
highCampaignResolved

Russian Intelligence Phishing Campaign Targets CMA User Accounts - Encryption Circumvention Through Social Engineering

Russian intelligence services are conducting widespread phishing campaigns targeting commercial messaging application accounts of U.S. government officials, military personnel, and journalists. Attackers have successfully compromised thousands of individual accounts to access messages and contact lists, demonstrating a shift from targeting application encryption to exploiting user-level account security.

Commercial Messaging Applications (generic - specific vendors not named in excerpt), Current and former U.S. government officials, U.S. military personnel +2
criticalCampaignContained

Destructive Microsoft Entra-based attack on Stryker demonstrates cloud identity compromise as primary attack vector for device-level destruction

Stryker suffered a destructive cyberattack that remotely wiped tens of thousands of employee devices through compromised Microsoft cloud credentials, requiring no malware payload and leveraging legitimate administrative access to cloud infrastructure.

Stryker Corporation, Microsoft Entra (Azure AD), Intune or similar MDM platforms
highCampaignContained

Opportunistic Probing of Critical Infrastructure: Poland's Nuclear Research Centre Targeted in Broader Campaign

Poland's National Centre for Nuclear Research (NCBJ) was targeted by cyberattackers who attempted to compromise its IT infrastructure, but intrusion detection systems successfully identified and blocked the attack before any material impact occurred. This incident underscores persistent adversarial interest in critical infrastructure sectors, particularly those with strategic national importance.

National Centre for Nuclear Research (NCBJ), Polish Critical Infrastructure
criticalCampaignResolved

INC Ransomware Expands Oceania Healthcare Targeting, Signals Regional Focus Shift

INC ransomware group is conducting sustained attacks against healthcare infrastructure across Australia, New Zealand, and Tonga, disrupting emergency services and government operations. This regional concentration indicates either a deliberate geographic pivot or emerging local infection vectors.

Australian Government Agencies, New Zealand Healthcare Facilities, Emergency Clinics (Oceania) +1
highCampaignResolved

Social Engineering Campaign Targets Developer Credentials via Fake Recruitment – Supply Chain Risk Vector

Threat actors execute a sophisticated social engineering campaign impersonating recruiters from crypto and AI companies, delivering backdoors (OtterCookie, FlexibleFerret) through fake coding assessments to steal developer credentials, API tokens, and source code. This represents a high-impact supply chain attack vector targeting a critical workforce demographic.

Software developers, Crypto industry, AI/ML companies +1
criticalCampaignResolved

State-Sponsored IoT Exploitation: Israeli Targeting of Iranian Critical Infrastructure via Traffic Camera Network

Israel allegedly exploited Iranian traffic camera systems to conduct surveillance and assist in targeted assassination of Iranian leadership. This demonstrates advanced state-actor capability to weaponize civilian IoT infrastructure for kinetic operations.

Iranian traffic camera network, IoT/CCTV infrastructure, Critical infrastructure (transportation)