Deploy autonomous AI agents that reason, exploit, and validate complex vulnerability chains — not another scanner, an agentic system that thinks like a senior pentester.
Track APT groups, cybercriminal organizations, and the vulnerabilities they exploit
aka: UNC5669
BREEZE COMET is a financially motivated threat actor targeting Brazilian financial services, retail, and eCommerce organizations through compromised websites, custom malware, and stolen credentials to manipulate payment systems and execute fraudulent transfers. The group employs custom tools such as REALBREEZE, COBALTSPIN, KICKPLATE, MILDFROST, LIGHTPAINT, and BOATBEAM for reconnaissance, lateral movement, persistence, tunneling, and stealth. Forensic evidence indicates that BREEZE COMET has executed waves of fraudulent transactions within 24-48 hours of compromise, likely stealing tens of thousands of USD in assets. The actor has also leveraged generative AI to enhance malware and script development while expanding its infrastructure across Latin America and Africa.
Exilware is a Brazilian threat actor operating the "Infect Marketplace," which commercializes access to compromised systems using the BraZetsu malware framework. BraZetsu employs a modular architecture and AI-driven reconnaissance to optimize target value across various sectors, including banking and government systems. The actor maintains a controlled operational model, requiring customers to spend quickly to limit exposure and risk. Exilware's activities reflect a sophisticated Initial Access Broker operation, transforming compromised systems into commercial assets through automated intelligence gathering.
QTFY is a state-sponsored group from the People's Republic of China, operating as an infrastructure quartermaster that provides reconnaissance, access, and obfuscation services to various state customers, including the MSS and PLA. It developed QScan and QTRouter, leveraging high-tier commercial proxy services like fastlink.ws to obscure its traffic. QTFY personnel, including former PLA members, engage in exploit brokering and operate within a supply chain rather than merely deploying malware. The group has been linked to specific domains and infrastructure, with evidence of TLS certificate collection as part of its operational tactics.
TheHatman is a highly organized threat actor known for systematically listing and selling internal employee directories stolen from major corporations, including nine Fortune 500 enterprises across various sectors. The actor claims to have obtained the data through compromised credentials, though the initial entry point remains under investigation. The volume of data suggests that after gaining access, TheHatman employed automated scripts, likely utilizing PowerShell modules or Python libraries, to extract the directories in bulk.
CRPxO is a ransomware group that has claimed responsibility for attacks on various organizations, including Encore Enterprises, Inc., KUVEYT TURK, and Johnson & Johnson, among others. The group has targeted entities across multiple countries, including the USA, Turkey, South Korea, Australia, the UK, and China. NCC Group has noted that the claims of responsibility from CRPxO have not been confirmed and highlighted inconsistent evidence regarding their involvement in these attacks.
aka: Thor
VantaCore is a ransomware group believed to be a rebrand of Thor, targeting Russian organizations with custom-built malware and multimillion-dollar ransom demands. F6 says the group has attacked at least seven victims, uses a ransomware-as-a-service model, and reflects a broader shift among pro-Ukrainian hackers toward in-house tooling instead of LockBit 3 Black and Babuk.
DaOnlySpark is a forum actor claiming to have leaked sensitive data from AdvaCare, including internal financial details, and from Jinko, comprising 3.7 GB of patient records, clinical profiles, and private messages. Both claims remain unverified.
ShadowByt3$ is a ransomware group known for exfiltrating sensitive data from various organizations, including John Engel Team, Abbott Laboratories, and Nintendo of America, often demanding substantial ransoms. They employ techniques such as SQL injection to breach systems and threaten to leak stolen data if negotiations are not completed within a specified timeframe. The group has also claimed to operate as a Wiper as a Service (WaaS), focusing on data theft and potential data destruction. Their activities include targeting a range of sectors, from education to healthcare, and they have been linked to mass-scanning campaigns for vulnerabilities.