APT & Nation-State Intelligence
Advanced Persistent Threat intelligence tracking nation-state actors — Lazarus Group, Sandworm, Volt Typhoon, and others. Campaign TTPs, targeted sectors, and SIGMA/KQL detection rules.
APT & Nation-State — Archive & Latest
Moobot/Mirai Botnet Resurgence: Open Directory Exposure of 'StresD Pro+' DDoS-as-a-Service Panel — OTX Pulse Analysis & Detection Pack
OTX pulse reveals exposed Moobot source code and active 'StresD Pro+' DDoS panel post-2024 takedown. IoT botnet ops tied to China-linked infrastructure. High urgency.
Salt Typhoon / Fire Ant TACACS+ Pre-Auth RCE (CVE-2026-48842): OTX Pulse Analysis — Telecom Infrastructure Detection Pack
OTX flags critical pre-auth RCE in TACACS+ (CVE-2026-48842) tied to Salt Typhoon/Fire Ant telecom espionage. Pre-authentication exploitation of network AAA. URGENT.
ClickFix Clipboard Poisoning via third-party.com, Galago Ransomware Emergence, and TACACS+ Pre-Auth RCE: OTX Pulse Analysis — Enterprise Detection Pack
ClickFix lures hijack placeholder domain third-party.com; Galago ransomware hits Icelandic healthcare; critical pre-auth RCE in TACACS+ protocol. Hunt now.
HookBot Android Banking Trojan Leak, ClickFix Clipboard Poisoning & Konni VelvetCake LNK Campaign: OTX Pulse Analysis — Enterprise Detection Pack
OTX pulses expose leaked HookBot/ERMAC panels with default creds, ClickFix lures on third-party[.]com, and Konni's VelvetCake LNK campaign targeting Ukraine. Hunt now.
PavinLoader Multi-Stage Campaign: ClickFix, Fake Captchas & EtherHiding Blockchain C2 — OTX Pulse Analysis with Enterprise Detection Pack
PavinLoader .NET loader distributing Amatera Stealer & HijackLoader via ClickFix/fake captcha lures, using MSBuild abuse and EtherHiding blockchain C2. High urgency.
DPRK Hangro State VPN Infrastructure Exposed: Silibank Mail Relays & Rogue Certificate Hierarchy — OTX Detection Pack
OTX pulse exposes North Korea's Hangro state VPN/mail infrastructure spanning Pyongyang, Russian Far East & Chinese netblocks. Rogue certs, mail relays identified. Hunt now.
ClickFix Fake CAPTCHA Chains, UTA0565 Chrome/Windows 0-Days & Red Heron Kapibala: OTX Pulse Analysis — Enterprise Detection Pack
CRITICAL: Bulletproof-hosted ClickFix malware chains, Chinese APT zero-day phishing (UTA0565), and Red Heron WordPress exploitation hitting governments globally.
INC Ransomware Double-Extortion Campaign + DPRK Hangro VPN Infrastructure: OTX Pulse Detection Pack — IAB Handoffs, BYOVD & SoftEther C2
OTX pulses expose INC ransomware's 17-day IAB-to-affiliate attack chain across 175 endpoints and North Korea's Hangro VPN/mail infrastructure on Russian Far East servers. Hunt now.
Operation DreamJob Resurfaces: Lazarus LightlessCan, NickelLoader and BLINDINGCAN Trojanized Coding Challenges — OTX Detection Pack
Lazarus Operation DreamJob spearphishing targets aerospace via fake Meta recruiter coding tests; hunt LightlessCan, NickelLoader, BLINDINGCAN IOCs now.
Head Mare APT Exploits TrueConf Video Conferencing Servers to Deliver PhantomCore Malware: OTX Pulse Analysis — Supply Chain Detection Pack
Head Mare APT exploited two TrueConf server vulnerabilities to push trojanized client installers and PhantomCore/PhantomGraph malware to conference participants. Patch and hunt now.
Mirage2FA PhaaS Session Hijacking + BlackCore Influence-for-Hire: OTX Pulse Analysis — Enterprise Detection Pack
Mirage2FA PhaaS steals Microsoft 365 sessions via AiTM attacks (4K+ US victims); BlackCore runs global influence-for-hire ops. Detection pack inside.
Offside Wallet Theft Factory, Mirage2FA AiTM, and PurpleDelta DPRK Employment Fraud: OTX Enterprise Detection Pack
OTX: 77 malicious Firefox extensions, Mirage2FA AiTM M365 session theft, and PurpleDelta DPRK job-fraud personas. Enterprise identity/browser risk is high.
EtherHiding Blockchain C2, BlackHatSect0r/DXQRTXX Go C2, Balonx Spyroid PhaaS: OTX Enterprise Detection Pack
OTX pulses expose EtherHiding blockchain C2, BlackHatSect0r/DXQRTXX Go C2 credential harvesting and Balonx Spyroid PhaaS hitting banks; hunt now.
LabubaRAT, EtherHiding Blockchain C2 & PolinRider Supply Chain Campaign: OTX Pulse Analysis — Enterprise Detection Pack
OTX pulses expose a Rust RAT spoofing NVIDIA software, a Polygon blockchain C2 campaign, and a Packagist supply-chain infostealer. Enterprise detection pack inside.
Octagon Android MaaS + APT36 Operation RapidRust + Mirage2FA AiTM Kit: OTX Pulse Analysis — Mobile Banking Fraud, GitHub C2 Backdoors, and M365 Session Hijacking Detection Pack
OTX pulses expose AndroidKitKat's Octagon banking bot, APT36's Rust backdoors hitting India/Afghanistan defense, and Mirage2FA AiTM phishing with 4K+ US victims. High urgency.
VectraRAT MaaS Platform, Noodle RAT Espionage Kit & APT36 Operation RapidRust: OTX Pulse Analysis — Multi-Family Detection Pack
OTX pulses expose VectraRAT MaaS rentals, Chinese-nexus Noodle RAT espionage, and APT36's Rust-based RapidRust campaign targeting government, defense, and finance. High urgency.
NightEagle APT (APT-Q-95) GhostContainer Exchange Backdoor + PeckBirdy Casino Infrastructure: OTX Pulse Analysis — Enterprise Detection Pack
NightEagle APT expands GhostContainer Exchange backdoor ops to Russian enterprises via compromised VPN creds; PeckBirdy gambling infrastructure masks espionage. High urgency.
GrelosGTM Google Tag Manager Skimmer: Magento Checkout JS Sniffer + WebSocket Exfil Detection Pack
GrelosGTM abuses Google Tag Manager to skim Magento checkout data via JS sniffers/WebSocket exfil; retail in US/EU at risk—hunt and block now.
JeetBot Malicious Browser Extension Campaign: Twitch OAuth Token Theft via Russian Proxy Infrastructure — OTX Detection Pack
Malicious 'Twitch Enhanced Viewer | JeetBot' extension exfiltrated OAuth session tokens from 30K+ users to Russian proxies. URGENT: audit extensions, revoke tokens now.
Cl0p LEMURLOOT MFT Exploitation + Jewelbug REF7707 Antino Backdoor: OTX Pulse Analysis — Enterprise Detection Pack
OTX pulses detail Cl0p's zero-day MFT ransomware campaigns and Jewelbug/REF7707 dual espionage-fraud ops via Antino backdoor and XG-Web. Govt, defense, telecom at risk. Act now.
Midnight Blizzard CaptiveCrunch + LegionLoader ClickFix + Melofee Linux Implant: OTX Pulse Analysis — Enterprise Detection Pack
OTX pulses expose APT29 hotel Wi-Fi M365 credential theft, LegionLoader ClickFix distribution, and Melofee Linux rootkit variants. Immediate hunting advised.
GRIMWEDGE Chrome 0-Day Chain, Vwork Work-Profile Evasion & PREY-0058 MFA-Bypass Extortion: OTX Pulse Analysis — Enterprise Detection Pack
Chinese actors chain Chrome/Windows 0-days against NGOs; GoldFactory weaponizes Shelter fork; PREY-0058 runs vishing + AiTM MFA bypass against M365. Hunt now.
Aeternum Blockchain C2 Botnet + XWorm/ZingoStealer Loader Chain: OTX Pulse Analysis — Polygon Smart Contract Detection Pack
AlienVault OTX flags Aeternum, a C++ loader using Polygon smart contracts for C2, dropping XWorm, ZingoStealer and XMRig. Immutable blockchain C2 defeats takedowns — hunt RPC egress now.
APT37 Ted Backdoor + CL-CRI-1171 PPI Nexus: OTX Pulse Detection Pack — Trojanized Linux Daemons, HAProxy Implants, SEO Poisoning
OTX pulses expose DPRK APT37 Linux trojanized binaries in South Korean media/auto plus CL-CRI-1171 PPI malware hitting gamers, government and energy.
BlueMoon Chrome/Windows 0-Day Chain, ClearFake WebDAV Infection & Virtualized Vidar Stealer: OTX Pulse Analysis — Enterprise Detection Pack
OTX pulses reveal APT31/TA412 deploying BlueMoon Chrome+Windows 0-days, ClearFake's WebDAV chain dropping Amatera stealer, and a VM-obfuscated Vidar variant. Enterprise defenders must act now.
Kimsuky 'Operation GitPower' Evolves: AI-Generated Decoys, GitHub PAT C2, and LNK-Based PowerShell Loaders — OTX Detection Pack
Kimsuky's Operation GitPower campaign deploys 13 malicious LNK variants using GitHub PATs for C2 and AI-generated decoys. Finance and government targets at risk. Hunt now.
BengalSEO MayaBot SEO Poisoning Operation: OTX Pulse Analysis — Enterprise Detection Pack for Search Engine Poisoning & Tech Support Scam Infrastructure
BengalSEO (Rajasthan, India) SEO poisoning operation distributing MayaBot and tech support scam lures since 2015. 524 IOCs published. Block domains, hunt endpoints now.
Overlord RAT Fake Zoom macOS Chain + UNC6671 Vishing Extortion: OTX Pulse Detection Pack
Fake Zoom installers drop Overlord/FlexibleFerret on macOS while UNC6671 vishing hits Okta/passkey SSO; urgent identity and endpoint hunt.
MacSync Stealer ClickFix Campaign: Fake CAPTCHA Terminal Commands Deploy Crypto-Draining Mach-O Payloads — OTX Pulse Analysis & Detection Pack
MacSync stealer uses ClickFix fake CAPTCHA lures to trick macOS users into running Terminal commands, deploying Go Mach-O payloads that drain crypto wallets and harvest credentials.
TA416 Mustang Panda EU Espionage: PlugX/Korplug + TONESHELL/PUBLOAD OTX Detection Pack
TA416/Mustang Panda resumes EU government espionage with PlugX/Korplug, TONESHELL and PUBLOAD; hunt web bugs, Turnstile-gated C2 now.
The Gentlemen Ransomware — TukTuk C2 v2.0 & GentleKiller BYOVD EDR Neutralization: OTX Detection Pack
The Gentlemen's TukTuk C2 v2.0 exposed with GentleKiller/EDRKiller BYOVD tooling targeting US defense, healthcare, tech & aerospace. Critical urgency.
Woodgnat 'Node.js Resurgence' Campaign: ClickFix → ModeloRAT + EtherHiding C2 — OTX Detection Engineering Pack
Woodgnat actors abuse signed node.exe via ClickFix lures to deploy ModeloRAT, EtherRAT & AsukaStealer against US gov/tech/finance. High urgency — detect now.
Teams Helpdesk Impersonation + Node.js MSI Implant: Human-Operated Intrusion Chain — OTX Pulse Analysis & Detection Pack
Threat actors impersonating IT helpdesk via Microsoft Teams are deploying MSI loaders and Node.js implants for enterprise-wide access. Urgent: hunt now.
Knight Office AiTM Phishing Kit: M365 Session Token Theft Campaign — OTX Pulse Analysis & Detection Pack
CRITICAL: New 'Knight Office' AiTM phishing kit harvests Microsoft 365 session tokens via DocuSign lures, Monday.com redirects, and .vu C2 domains. Enterprise detection pack inside.
Larva-24009 (HeptaX) QuasarRAT LNK Campaign + Knight Office M365 AiTM Phishing Kit: OTX Pulse Analysis & Detection Pack
OTX pulses reveal Larva-24009 phishing delivering QuasarRAT via malicious LNKs, and Knight Office AiTM kit stealing M365 session tokens. High urgency.
Mirage Kitten APT Deploys NodeRabbit & PollCat Cross-Platform RATs: OTX Pulse Analysis — Detection & Hunt Pack
Mirage Kitten APT shifts to Node.js/JavaScript RATs (NodeRabbit, PollCat) targeting finance and aerospace via LinkedIn lures. HIGH urgency — hunt now.
ValleyRAT Backdoor Disguised as QN Wallpaper Adware: Void Arachne DLL Sideloading Campaign — OTX Detection Pack
Void Arachne spreads ValleyRAT backdoor via fake QN Wallpaper adware using DLL sideloading. Targets China/India. Keylogging, clipboard theft, C2 active. HIGH urgency.
Blind Eagle GitHub Loader (AsyncRAT/DcRat/XWorm) + 'Mini Shai-Hulud' npm Supply Chain Attack: OTX Pulse Analysis — Enterprise Detection Pack
OTX pulses expose APT-C-36 (Blind Eagle) GitHub-staged RAT loaders targeting Colombian government, and a 10-version npm supply chain compromise via abused GitHub Actions. Hunt now.
QScan + Fast Labyrinth 'Quartermaster' Infrastructure: China-Nexus Cyber Espionage Enablement Network — OTX Pulse Analysis & Detection Pack
OTX pulse exposes a China-nexus 'quartermaster' infrastructure model (QScan, Fast Labyrinth, QTRouter) enabling espionage against US/UK critical infrastructure. Hunt now.
The Gentlemen RaaS + China-Nexus 'Quartermaster' Espionage Infrastructure: OTX Pulse Analysis — Enterprise Detection Pack
OTX pulses track The Gentlemen dual-extortion RaaS hitting Windows/Linux/ESXi and a China-nexus quartermaster proxy network targeting US/UK critical infrastructure. High urgency.
XenoRAT LNK Campaigns, pepesoft.exe Supply-Chain Implant & Aurora Ransomware Leak: OTX Pulse Analysis — Enterprise Detection Pack
OTX pulses expose Kimsuky XenoRAT LNK phishing, malicious NuGet tools dropping pepesoft.exe host surveillance, and a leaked Aurora ransomware affiliate toolkit. Hunt now.
DEV#POPPER npm RAT, Flying Eagle Android Botnet & APT28 Moobot Resurgence: OTX Pulse Analysis — Multi-Platform Detection Pack
OTX pulses reveal npm supply-chain RAT (DEV#POPPER), a 170-server Android RAT ecosystem targeting banking in China/Thailand, and APT28-linked Moobot botnet activity post-2024 takedown. High urgency.
Dark Caracal GoCaracal Framework + Tortoiseshell TWOSTROKE Backdoor: Dual APT Campaign OTX Analysis — Enterprise Detection Pack
Two APT campaigns active: Dark Caracal deploying GoCaracal modular spyware across Latin America telecom, and Iranian Tortoiseshell targeting defense/aerospace with TWOSTROKE backdoor and SSH tunneling. Immediate C2 blocking required.
AMOS Stealer + XMRig macOS ClickFix Crimekit: EtherHiding C2 on Polygon Blockchain — OTX Detection Pack
macOS ClickFix crimekit uses fake CAPTCHA AppleScript lures to drop AMOS stealer + XMRig miner, hiding C2 in Polygon smart contracts. High urgency for Mac fleets.
HookBot & ERMAC Source Leak: Exposed Android Banking Trojan Panels Enable Mass Operator Proliferation — OTX Detection Pack
ERMAC/HookBot builder + backend leaked with default creds intact. Financial sector targeted via overlay attacks. 19 live C2 indicators — hunt now.
Vanilla Tempest ClickFix Cluster: Supper Malware + DLL Sideloading via MSI & NodeJS — OTX Detection Pack
Vanilla Tempest ClickFix cluster delivering Supper malware via MSI sideloading & NodeJS. C2 dead drops, DLL sideload IOCs + Sigma/KQL detection rules. High urgency.
Cyber Av3ngers IOCONTROL + MALPDB Campaign: Nation-State PLC Exploitation Against U.S. Water & Energy Infrastructure — OTX Detection Pack
IRGC-linked Cyber Av3ngers is actively exploiting internet-exposed PLCs across U.S. water and energy sectors, deploying IOCONTROL malware and abusing valid engineering credentials. Hunt now.
JadeProx PlugX/TriBack Campaign, Void Blizzard Zimbra Zero-Click Espionage & Helix SharePoint Extortion: OTX Pulse Analysis — Enterprise Detection Pack
OTX pulses expose China-nexus JadeProx intrusions, Russian Void Blizzard Zimbra zero-click espionage, and Helix vishing-driven SharePoint extortion. Hunt now.
Head Mare PhantomCore via TrueConf Supply-Chain Compromise + STARDUST CHOLLIMA Rust Crate Backdoor: OTX Pulse Analysis — Enterprise Detection Pack
Two live supply-chain campaigns: Head Mare APT trojanizing TrueConf conferencing clients with PhantomCore, and DPRK-linked STARDUST CHOLLIMA backdooring Rust crates on crates.io. Hunt now.
Offside Wallet Theft Factory: 77 Malicious Firefox Extensions Steal Crypto Wallet Seed Phrases via Supabase & Cloudflare Workers C2 — OTX Pulse Detection Pack
OTX pulse exposes 77 Firefox extensions (40 confirmed malicious) stealing crypto wallet recovery phrases and credentials via Supabase switches and Cloudflare Workers C2. HIGH urgency for Web3-facing orgs.
Showing 50 of 279 reports. Archive expands automatically as new intel is generated.
Every APT & Nation-State Report Includes SIGMA & KQL Detection Rules
Every intelligence briefing on this page includes at least one Sigma rule, a Microsoft Sentinel KQL hunt query, and an IOC check script — ready to drop into your SIEM. No paywall. No registration.