Deploy autonomous AI agents that reason, exploit, and validate complex vulnerability chains — not another scanner, an agentic system that thinks like a senior pentester.
Track APT groups, cybercriminal organizations, and the vulnerabilities they exploit
Cavern Manticore is an Iran-nexus APT primarily targeting Israeli organizations in the government and IT sectors, linked to the MOIS. The group employs a modular command-and-control framework built on a shared .NET foundation, utilizing multiple compilation formats to create an anti-analysis layer. Their operations demonstrate a high operational tempo and a disciplined approach to target selection, particularly during campaigns like "Operation Epic Fury." By decoupling core infrastructure from mission-specific modules, Cavern Manticore enhances operational agility while complicating detection efforts for defenders.
UAT-11795 is a sophisticated, Russian-speaking, financially motivated adversary conducting malicious campaigns targeting users in the U.S. and Europe since June 2025. The actor employs CastleStealer and Remcos RAT as alternative payload implants. Their operations indicate a focus on financial gain through targeted attacks.
JADEPUFFER is an agentic threat actor that executed a fully autonomous ransomware operation, leveraging a Large Language Model to automate the entire attack chain from initial access to data destruction. It exploited CVE-2025-3248 against an exposed Langflow instance for initial access, then compromised MinIO using default credentials and manipulated MySQL for privilege escalation. The operation culminated in the encryption of over 1,300 configuration records in Nacos, with the encryption key lost, rendering the data unrecoverable. JADEPUFFER exemplifies a shift towards machine-speed extortion, where traditional security models are outpaced by automated threats.
Storm-2945 is a sub-cluster of Midnight Blizzard conducting targeted traffic manipulation attacks on hospitality sector networks served by captive portals, leveraging doppelganger domains for AitM phishing and malware delivery. Their operations include AI-augmented device code and OAuth code phishing campaigns leading to Entra device registration and data collection from Microsoft 365. The primary malware used is CornFlake, a Windows RAT that features customizable capabilities for data collection and evasion. Storm-2945 also utilizes the FruitStone web-based C2 panel to manage their campaign infrastructure and compromised endpoints.
Fox Tempest is a financially motivated threat actor that operated a malware-signing-as-a-service (MSaaS) sold to other cybercriminals to sign malware, including ransomware, as trusted software and evade detection. The service, marketed through the domain signspace[.]cloud and a Telegram channel, abused Microsoft Artifact Signing to issue short-lived fraudulent code-signing certificates and offered signing plans priced between 5,000 and 9,000 USD, with higher tiers providing pre-configured virtual machines for signing malicious code. Microsoft tracked the operation from September 2025 and observed its certificates used to distribute malware families such as Oyster, Lumma Stealer, and Vidar and to support ransomware activity linked to Vanilla Tempest, Storm-0501, Storm-2561, and Storm-0249. In May 2026, Microsoft's Digital Crimes Unit disrupted the operation, seizing signspace[.]cloud, taking hundreds of signing virtual machines offline, and revoking more than 1,000 fraudulent certificates, and named Vanilla Tempest as a co-defendant in a case filed in the U.S. District Court for the Southern District of New York.
Orova is a ransomware group that has claimed attacks on various targets, including Yost Home Improvements in the USA and multiple companies in Hong Kong, such as SSI HOLDING LIMITED and Sanrio Hong Kong Co., Ltd. The group has also targeted entities like KINGSSON in Taiwan and Conceptual Designs, Inc. in the USA.
Larva-24009 has been active since at least 2023, conducting phishing email attacks to install malware globally, particularly targeting users in Korea. The actor employs LNK malware to install a PowerShell backdoor and maintains persistence with remote control tools like QuasarRAT and UltraVNC. They utilize phishing emails with keywords such as “hospital survey” and “resume,” disguising malware as document files to trick users into execution. This results in the theft of sensitive information, including credentials and user files.
Global Secret is a ransomware group that has claimed attacks on various organizations across multiple countries, including the USA, India, and Brazil.
ExfilSquad is an emerging data-extortion group that surfaced on July 26, 2026, operating a Tor-hosted Data Leak Site to publicly claim data theft from 15 organizations, including Microsoft. Their model focuses on public exposure and pressure tactics without confirmed encryption, lacking evidence of a Ransomware-as-a-Service structure or specific initial-access methods. The group has not provided forensic evidence or verifiable data samples, raising questions about the credibility of their claims, which may involve reused or fabricated data.
ModernStealer is linked to underground posts offering sensitive military, government, nuclear, and aerospace material, with connections to a Session contact identifier and a Telegram account named Sassoon Don. Analysts identified five ModernStealer listings and eight government-related listings, including references to Pakistan’s NUST and SUPARCO, as well as US defense entities. The shared identifier suggests operational overlap with other identities, but does not confirm a direct link between them. The actor exemplifies the importance of tracking durable identifiers over forum names in threat intelligence.
Larva-26009 targets MS-SQL servers and has been observed installing the XMRig CoinMiner.
Larva-26005 is a threat actor confirmed to be distributing Xctdoor, a RAT, to users in Korea. The malware was initially disclosed in 2024 and was later found disguised as an integrated security program in an attack case reported by Hauri in 2026.
The Booba Project is a ransomware group that has claimed responsibility for attacks on multiple organizations, including Betz Industries, Oklahoma Manufacturing Alliance, Incredible Technologies, and Jani-King in the USA, as well as Fonsan in Spain. Their operations indicate a focus on targeting manufacturing and service sectors.
Gammax is a ransomware group that has claimed responsibility for attacks on various organizations, including MTCO in Saudi Arabia, RE/MAX 1st Choice in the USA, and AguAseo in Panama.
aka: RAVINE CASTLE
UNC1088 is a China-nexus threat cluster tracked by Mandiant, renamed RAVINE CASTLE under Google Threat Intelligence's updated naming system.
aka: CONFERENCE CASTLE
Conference Crew is a China-nexus threat cluster renamed CONFERENCE CASTLE under Google Threat Intelligence's updated naming system.
The attack begins with phishing emails impersonating voicemail notifications that direct victims through a multi-stage redirect chain abusing legitimate services, including Google Meet, Google Ads infrastructure, and Amazon S3, before ultimately reaching an attacker-controlled...
Larva-26010 targets web servers and MS-SQL servers in Korea to install SoftEther VPN, using the systems as VPN servers. After the initial breach, the actor installs a web shell or SQLShell for control, followed by the SoftEther installation. The threat actor has not exhibited additional malicious behavior beyond installing backdoor accounts or web shells. It appears they are preparing to utilize the infected systems as C&C servers in the future.
SilkParasite is an activity cluster tracked by Bitdefender across Central Asia, primarily targeting government and telecommunications entities in Kyrgyzstan, Uzbekistan and Kazakhstan. Bitdefender assesses a China-nexus with medium confidence and states explicitly that it does not believe the evidence supports attribution to a named group, so this is recorded as an activity cluster rather than as an established actor. Observed tooling spans seven implant families: five named by Bitdefender (DriveSilkRAT, CookiETagRAT, NomadRAT, GoginRAT, NodeEdgeRAT) plus SpiceRAT, previously reported by Cisco Talos in connection with SneakyChef, and BloodAlchemy, a lineage descended from ShadowPad and Deed RAT. The operators favour DLL sideloading and cloud services as command-and-control channels, and register domains impersonating local hosting providers.
ZeroBytes is a hacker who claimed responsibility for an attack on France's DGFiP's Professional Cadastral Data Server (SPDC), alleging the extraction of a dataset containing personal information for over 2 million individuals. The claimed dataset includes names, birth details, addresses, and property rights, potentially linking individuals to real estate assets.