Deploy autonomous AI agents that reason, exploit, and validate complex vulnerability chains — not another scanner, an agentic system that thinks like a senior pentester.
Track APT groups, cybercriminal organizations, and the vulnerabilities they exploit
DriveSurge compromises legitimate websites to inject scripts that route visitors through zTDS, leading them to fake browser updates and ClickFix-style prompts. This operation resembles an initial-access broker model, where successful infections generate leads for downstream threat actors. The actor employs tactics that avoid detection by site administrators, allowing infections to go unnoticed during routine checks.
GHOST STADIUM is a Chinese-speaking, financially motivated threat actor operating a sophisticated phishing campaign across over 300 domains, utilizing a custom React-based phishing kit that closely mimics FIFA's official website and exploits the PingIdentity SSO login flow. The campaign has the potential to generate financial losses estimated between $71 million and $474 million from premium ticket fraud alone, with total losses potentially reaching billions. GHOST STADIUM employs Facebook Ads as a primary traffic acquisition channel and has been linked to 2,513 compromised FIFA credentials available on dark-web markets. The actor is part of a broader fraud ecosystem that includes multiple parallel schemes, such as credential phishing and counterfeit merchandise sales.
GREYVIBE is a low-to-moderately sophisticated threat actor associated with Russian state interests, primarily targeting Ukrainian entities. The group employs custom malware like LegionRelay and PhantomRelay, utilizing techniques such as decoy-and-payload execution logic and systematic use of GenAI and LLMs throughout their operations. Their campaigns exhibit operational overlaps with other groups, including shared C2 infrastructure and post-compromise tooling. WithSecure has identified design flaws in their malware that have provided insights into their victimology and operational behavior.
Inteid is a member of the Russian Legion alliance, which includes groups like Cardinal and The White Pulse, and has been involved in DDoS attacks targeting Denmark's health portal, sundhed.dk. The group has also participated in ICS attacks, primarily affecting the Energy & Utilities, Manufacturing, and Agriculture sectors across Europe. Inteid has demonstrated operational coordination with other hacktivist entities, such as Keymous+, to support Iranian cyberwar efforts against Israeli targets.
Narketing163 is a financially motivated threat actor named after one of their frequently used email addresses ([email protected]). Active since at least July 2023, the actor conducts large-scale phishing campaigns distributing commodity infostealer and keylogger malware disguised as business correspondence such as price quotes, order forms, and payment notices. Targets span multiple countries including Russia, Belarus, Kazakhstan, Azerbaijan, Armenia, Turkey, the USA, Germany, the UK, India, and others, across sectors including e-commerce, retail, chemicals, construction, healthcare, insurance, and food. The actor delivers malware via spearphishing attachments (compressed archives) deploying RedLine Stealer, Agent Tesla, FormBook, and Snake Keylogger against Windows systems. Exfiltration is performed via actor-controlled Roundcube mail servers. Emails are sent in Russian, Azerbaijani, Turkish, and English, with rotating sender IPs and use of anonymization tools such as VPNs and proxies.
SHADOW-WATER-063 is a financially motivated threat actor attributed to the Banana RAT banking trojan, primarily targeting Brazilian financial accounts. Analysis of recovered artifacts, including a Python panel and PowerShell stagers, supports a moderate-confidence attribution assessment. The actor's infrastructure and endpoint telemetry indicate a focus on executing fraudulent transactions. Key evidentiary pillars establish their intent to exploit Brazilian financial systems.
SnowSoul is a financially motivated threat actor active since at least early 2026, operating a low-ransom extortion scheme primarily targeting Chinese organizations. The actor sends extortion demands of around $2,000 USD, and when victims refuse to pay, leaks stolen data on hacker forums. Operations are tracked through numbered identifiers (e.g., SnowSoul ID-1265, ID-1270), suggesting a systematic, serial campaign.
Storm-2949 is a sophisticated threat actor that exploited Microsoft’s Self-Service Password Reset process to compromise high-value accounts, primarily targeting IT personnel and senior leadership. They leveraged Azure tools and APIs to conduct reconnaissance, exfiltrate sensitive data from Microsoft 365 applications, and manipulate Azure resources, including Key Vaults and SQL databases. The actor employed social engineering tactics to bypass MFA and utilized custom Python scripts for directory discovery and data exfiltration. Their operations included lateral movement across cloud and endpoint environments while mimicking legitimate administrative behavior.
aka: Zeff Security
ZeffSec is a hacktivist collective focused on infrastructure-level disruption and exposing vulnerabilities in centralized digital networks. In March 2026, the group claimed responsibility for a large-scale DDoS attack against ArvanCloud, Iran's primary cloud and CDN provider, causing widespread service outages across platforms including the online education service Skyroom. The group announced the operation via Telegram, stating their goal was disruption of centralized infrastructure rather than data theft.
SLIME88 is a China-nexus APT that has exploited the critical vulnerability CVE-2026-34197 in Apache ActiveMQ to deploy SoxAgent RAT, compromising Linux devices and establishing an ORB network tracked as GOBLIN14. The group has targeted IT and manufacturing entities in the US, South Korea, India, and France. Additionally, SLIME88 has aimed at Taiwan’s energy sector using phishing emails and fake certificate installers to deploy backdoor programs like AdaptixC2 and CobaltStrike. They often utilize Cloudflare to obscure their C2 IP addresses, evading detection.
TA4922 is a Chinese-speaking cybercrime cluster that employs localized HR, payroll, tax, and invoice lures to deliver various malware families, including Atlas RAT, RomulusLoader, and SilentRunLoader. The actor conducts targeted email campaigns, often impersonating trusted authorities, to facilitate credential phishing and fraud. TA4922's operational tempo is high, with a focus on obtaining remote access for financial gain, and it has shown a rapid evolution in its malware arsenal. The group is also noted for using social engineering to shift communications from email to messaging platforms, enhancing their phishing efforts.
aka: BlackMaskers Team
BlackMaskers Team has emerged as a significant threat actor, particularly targeting Jordan amid the Israel-Iran conflict. They have claimed responsibility for cyberattacks on critical Jordanian entities, including the stock exchange and private sector enterprises, leveraging techniques such as website defacement and data breaches. Their operations have raised concerns about the vulnerability of national infrastructure. Additionally, they have successfully hacked Saudi Arabian web platforms, further demonstrating their capabilities.
UNC6508 is a PRC-nexus threat actor targeting North American academic, medical, and military research institutions, employing tactics such as exploiting REDCap servers and deploying custom malware named INFINITERED. The actor utilized credential harvesting, internal reconnaissance, and a web shell named "help.php" for persistence. They also manipulated content compliance rules for covert data exfiltration, forwarding sensitive email communications to a threat actor-controlled Gmail address. GTIG attributes this espionage activity to UNC6508 with high confidence, based on infrastructure overlaps and specific targeting of defense and medical research sectors.
FulcrumSec is a financially motivated data-theft-extortion group known for sophisticated ransomware attacks and double extortion tactics. They have exploited vulnerabilities such as hardcoded credentials and misconfigured cloud permissions to gain access to targets, including Novo Nordisk and Arup Group. Their operations involve extensive dwell time, with claims of spending months analyzing stolen data before contacting victims. FulcrumSec has demonstrated a targeted approach, often demanding ransoms that are strategically calculated based on the victim's financial profile.
aka: DEV-0605, CyberRoot, MintedSoil
Microsoft threat actor profile. Origin/Threat: India, Private sector offensive actor.
aka: Eagle Werewolf
Armored Likho is an APT group targeting government agencies and the electric power sector across Russia, Brazil, and Kazakhstan. Their operations blend financially motivated campaigns with cyber-espionage, utilizing obfuscated, modular RATs and infostealers designed to evade dynamic analysis. They employ spear-phishing emails with deceptive themes to gain initial access, distributing malicious attachments that mimic legitimate content. Their toolkit includes BusySnake Stealer and AquilaRAT, with a focus on evolving TTPs and leveraging AI tools for payload generation.
UNC2529 is a well-resourced threat actor that conducted a global phishing campaign targeting various industries, utilizing tailored lures and sophisticated malware, including DOUBLEDRAG, DOUBLEDROP, and DOUBLEBACK. They compromised a legitimate domain to enhance their phishing efforts and employed at least 50 domains throughout the campaign. The actor demonstrated target research through personalized email addresses and subject lines, indicating a non-native English speaker. Their activities suggest a financial crime motive, with extensive use of obfuscation and fileless malware to evade detection.
UTA0533 has been linked to compromised SonicWall SMA appliances, with exploitation beginning on June 22, 2026. The actor routed traffic through ExpressVPN and Mullvad exit nodes, utilizing over 200 IP addresses. Notably, several attacker hostnames, including a Kali Linux machine, were leaked during lateral movement, indicating hands-on-keyboard intrusion.
UAT-7810 is an APT actor responsible for maintaining the LapDogs ORB network and developing custom malware, including the backdoors SHORTLEASH and LONGLEASH, as well as DOGLEASH and JARLEASH. They exploit known vulnerabilities in unpatched Ruckus wireless routers and have been observed using infrastructure to host malicious payloads across various hardware platforms. Forensic analysis has revealed their use of multiple IP addresses for hosting and deploying malware, including a test binary named LEASHTEST for functionality checks on MIPS devices. Talos assesses UAT-7810 as a China-nexus threat actor, providing infrastructure to secondary APTs while maintaining distinct objectives.
Hyadina is a threat actor that first emerged in March 2022, deploying its Monster ransomware variant primarily targeting 32-bit Windows systems while avoiding the CIS region. The group rebranded its ransomware as Beast in June 2024, enhancing its toolset to include support for Linux and VMware ESXi, and incorporating extensive use of NirSoft tools. The latest iteration, GodDamn, showcases advanced defensive evasion techniques, including the use of the PoisonX malicious driver component. Hyadina operates as a ransomware-as-a-service, collaborating with affiliates to execute attacks.