Tag

#APT

40 published stories tagged with APT.

highThreat IntelligenceMay 8, 2026·4 min read

Brief: MuddyWater activity masquerades as Chaos ransomware

SecurityWeek reported that Iranian APT-linked activity masqueraded as Chaos ransomware while focusing on social engineering, persistent access, remote access tooling, lateral movem

highThreat IntelligenceMay 8, 2026·4 min read

Defender Guidance: MuddyWater activity masquerades as Chaos ransomware

SecurityWeek reported that Iranian APT-linked activity masqueraded as Chaos ransomware while focusing on social engineering, persistent access, remote access tooling, lateral movem

highThreat IntelligenceMay 8, 2026·4 min read

Detection Notes: MuddyWater activity masquerades as Chaos ransomware

SecurityWeek reported that Iranian APT-linked activity masqueraded as Chaos ransomware while focusing on social engineering, persistent access, remote access tooling, lateral movem

highThreat IntelligenceMay 8, 2026·4 min read

Risk Brief: MuddyWater activity masquerades as Chaos ransomware

SecurityWeek reported that Iranian APT-linked activity masqueraded as Chaos ransomware while focusing on social engineering, persistent access, remote access tooling, lateral movem

highThreat IntelligenceMay 8, 2026·4 min read

Brief: Chinese APT abuses cloud tools to spy on Mongolia

Dark Reading reported Chinese APT activity abusing cloud tools to spy on Mongolia. Cloud logs, identity telemetry, and sanctioned OAuth application review are key defensive areas.

highThreat IntelligenceMay 8, 2026·4 min read

Defender Guidance: Chinese APT abuses cloud tools to spy on Mongolia

Dark Reading reported Chinese APT activity abusing cloud tools to spy on Mongolia. Cloud logs, identity telemetry, and sanctioned OAuth application review are key defensive areas.

highThreat IntelligenceMay 8, 2026·4 min read

Detection Notes: Chinese APT abuses cloud tools to spy on Mongolia

Dark Reading reported Chinese APT activity abusing cloud tools to spy on Mongolia. Cloud logs, identity telemetry, and sanctioned OAuth application review are key defensive areas.

highThreat IntelligenceMay 8, 2026·4 min read

Risk Brief: Chinese APT abuses cloud tools to spy on Mongolia

Dark Reading reported Chinese APT activity abusing cloud tools to spy on Mongolia. Cloud logs, identity telemetry, and sanctioned OAuth application review are key defensive areas.

highThreat IntelligenceMay 8, 2026·4 min read

Brief: Tropic Trooper activity involves home routers and Japan targeting

Dark Reading reported Tropic Trooper activity involving home routers and Japan-related targeting. Edge and home-office routers remain useful attacker infrastructure.

highThreat IntelligenceMay 8, 2026·4 min read

Defender Guidance: Tropic Trooper activity involves home routers and Japan targeting

Dark Reading reported Tropic Trooper activity involving home routers and Japan-related targeting. Edge and home-office routers remain useful attacker infrastructure.

highThreat IntelligenceMay 8, 2026·4 min read

Detection Notes: Tropic Trooper activity involves home routers and Japan targeting

Dark Reading reported Tropic Trooper activity involving home routers and Japan-related targeting. Edge and home-office routers remain useful attacker infrastructure.

highThreat IntelligenceMay 8, 2026·4 min read

Risk Brief: Tropic Trooper activity involves home routers and Japan targeting

Dark Reading reported Tropic Trooper activity involving home routers and Japan-related targeting. Edge and home-office routers remain useful attacker infrastructure.

highThreat IntelligenceMay 8, 2026·4 min read

Brief: BlueNoroff uses fake Zoom calls in social engineering campaigns

Dark Reading reported BlueNoroff activity using fake Zoom calls. Defenders should treat meeting-themed lures as credential and malware delivery risks.

highThreat IntelligenceMay 8, 2026·4 min read

Defender Guidance: BlueNoroff uses fake Zoom calls in social engineering campaigns

Dark Reading reported BlueNoroff activity using fake Zoom calls. Defenders should treat meeting-themed lures as credential and malware delivery risks.

highThreat IntelligenceMay 8, 2026·4 min read

Detection Notes: BlueNoroff uses fake Zoom calls in social engineering campaigns

Dark Reading reported BlueNoroff activity using fake Zoom calls. Defenders should treat meeting-themed lures as credential and malware delivery risks.

highThreat IntelligenceMay 8, 2026·4 min read

Risk Brief: BlueNoroff uses fake Zoom calls in social engineering campaigns

Dark Reading reported BlueNoroff activity using fake Zoom calls. Defenders should treat meeting-themed lures as credential and malware delivery risks.

highThreat IntelligenceMay 8, 2026·4 min read

Brief: China-nexus hackers persist in Southeast Asian military environments

Dark Reading reported that China-nexus hackers maintained access in Southeast Asian military environments. Long dwell time requires identity, endpoint, and network retrospective hu

highThreat IntelligenceMay 8, 2026·4 min read

Defender Guidance: China-nexus hackers persist in Southeast Asian military environments

Dark Reading reported that China-nexus hackers maintained access in Southeast Asian military environments. Long dwell time requires identity, endpoint, and network retrospective hu

highThreat IntelligenceMay 8, 2026·4 min read

Detection Notes: China-nexus hackers persist in Southeast Asian military environments

Dark Reading reported that China-nexus hackers maintained access in Southeast Asian military environments. Long dwell time requires identity, endpoint, and network retrospective hu

highThreat IntelligenceMay 8, 2026·4 min read

Risk Brief: China-nexus hackers persist in Southeast Asian military environments

Dark Reading reported that China-nexus hackers maintained access in Southeast Asian military environments. Long dwell time requires identity, endpoint, and network retrospective hu

highThreat IntelligenceMay 8, 2026·4 min read

Brief: Sednit activity resurfaces in recent threat reporting

Dark Reading reported renewed Sednit activity. Organizations in likely target sectors should validate phishing controls, endpoint visibility, and incident escalation.

highThreat IntelligenceMay 8, 2026·4 min read

Defender Guidance: Sednit activity resurfaces in recent threat reporting

Dark Reading reported renewed Sednit activity. Organizations in likely target sectors should validate phishing controls, endpoint visibility, and incident escalation.

highThreat IntelligenceMay 8, 2026·4 min read

Detection Notes: Sednit activity resurfaces in recent threat reporting

Dark Reading reported renewed Sednit activity. Organizations in likely target sectors should validate phishing controls, endpoint visibility, and incident escalation.

highThreat IntelligenceMay 8, 2026·4 min read

Risk Brief: Sednit activity resurfaces in recent threat reporting

Dark Reading reported renewed Sednit activity. Organizations in likely target sectors should validate phishing controls, endpoint visibility, and incident escalation.

highThreat IntelligenceMay 8, 2026·4 min read

Brief: Fancy Bear secrets theft activity remains a priority threat

Dark Reading reported Fancy Bear activity focused on secrets theft. Defenders should watch for credential harvesting, cloud token abuse, and suspicious OAuth grants.

highThreat IntelligenceMay 8, 2026·4 min read

Defender Guidance: Fancy Bear secrets theft activity remains a priority threat

Dark Reading reported Fancy Bear activity focused on secrets theft. Defenders should watch for credential harvesting, cloud token abuse, and suspicious OAuth grants.

highThreat IntelligenceMay 8, 2026·4 min read

Detection Notes: Fancy Bear secrets theft activity remains a priority threat

Dark Reading reported Fancy Bear activity focused on secrets theft. Defenders should watch for credential harvesting, cloud token abuse, and suspicious OAuth grants.

highThreat IntelligenceMay 8, 2026·4 min read

Risk Brief: Fancy Bear secrets theft activity remains a priority threat

Dark Reading reported Fancy Bear activity focused on secrets theft. Defenders should watch for credential harvesting, cloud token abuse, and suspicious OAuth grants.

highThreat IntelligenceMay 8, 2026·4 min read

Brief: Tomiris updates Havoc-based tooling and tactics

Dark Reading reported Tomiris activity involving Havoc tooling and tactical changes. Defenders should monitor for C2 frameworks and post-exploitation behavior.

highThreat IntelligenceMay 8, 2026·4 min read

Defender Guidance: Tomiris updates Havoc-based tooling and tactics

Dark Reading reported Tomiris activity involving Havoc tooling and tactical changes. Defenders should monitor for C2 frameworks and post-exploitation behavior.

highThreat IntelligenceMay 8, 2026·4 min read

Detection Notes: Tomiris updates Havoc-based tooling and tactics

Dark Reading reported Tomiris activity involving Havoc tooling and tactical changes. Defenders should monitor for C2 frameworks and post-exploitation behavior.

highThreat IntelligenceMay 8, 2026·4 min read

Risk Brief: Tomiris updates Havoc-based tooling and tactics

Dark Reading reported Tomiris activity involving Havoc tooling and tactical changes. Defenders should monitor for C2 frameworks and post-exploitation behavior.

highThreat IntelligenceMay 8, 2026·4 min read

Brief: Iran MOIS reported collaborating with criminal cyber actors

Dark Reading reported Iran MOIS collaboration with criminal actors. Attribution should follow source confidence, but defenders should expect overlap between state and criminal trad

highThreat IntelligenceMay 8, 2026·4 min read

Defender Guidance: Iran MOIS reported collaborating with criminal cyber actors

Dark Reading reported Iran MOIS collaboration with criminal actors. Attribution should follow source confidence, but defenders should expect overlap between state and criminal trad

highThreat IntelligenceMay 8, 2026·4 min read

Detection Notes: Iran MOIS reported collaborating with criminal cyber actors

Dark Reading reported Iran MOIS collaboration with criminal actors. Attribution should follow source confidence, but defenders should expect overlap between state and criminal trad

highThreat IntelligenceMay 8, 2026·4 min read

Risk Brief: Iran MOIS reported collaborating with criminal cyber actors

Dark Reading reported Iran MOIS collaboration with criminal actors. Attribution should follow source confidence, but defenders should expect overlap between state and criminal trad

highThreat IntelligenceMay 8, 2026·4 min read

Brief: Chinese cyber threat activity focuses on critical Asian sectors

Dark Reading reported China-linked cyber threat activity in critical Asian sectors for years. Long-term intrusion risk requires strategic threat hunting and asset visibility.

highThreat IntelligenceMay 8, 2026·4 min read

Defender Guidance: Chinese cyber threat activity focuses on critical Asian sectors

Dark Reading reported China-linked cyber threat activity in critical Asian sectors for years. Long-term intrusion risk requires strategic threat hunting and asset visibility.

highThreat IntelligenceMay 8, 2026·4 min read

Detection Notes: Chinese cyber threat activity focuses on critical Asian sectors

Dark Reading reported China-linked cyber threat activity in critical Asian sectors for years. Long-term intrusion risk requires strategic threat hunting and asset visibility.

highThreat IntelligenceMay 8, 2026·4 min read

Risk Brief: Chinese cyber threat activity focuses on critical Asian sectors

Dark Reading reported China-linked cyber threat activity in critical Asian sectors for years. Long-term intrusion risk requires strategic threat hunting and asset visibility.