APT & Nation-State Intelligence
Advanced Persistent Threat intelligence tracking nation-state actors — Lazarus Group, Sandworm, Volt Typhoon, and others. Campaign TTPs, targeted sectors, and SIGMA/KQL detection rules.
APT & Nation-State — Archive & Latest
Blind Eagle (APT-C-36) Evolving Toolkit: AsyncRAT, njRAT & LimeRAT Campaign Targeting Colombian Finance — OTX Detection Pack
Blind Eagle (APT-C-36) is targeting Colombian finance with an evolved toolkit: AsyncRAT, njRAT, LimeRAT, RunPE AutoIt loader, JS AES obfuscation, DuckDNS C2. Hunt now.
HelloNet APT Campaign: ViPNet Supply Chain Compromise Deploys HelloInjector/HelloBackdoor Against Russian Critical Infrastructure — OTX Detection Pack
Active APT campaign abuses ViPNet update system via DLL sideloading to deploy 5-stage Rust-based tooling against Russian government, energy, and aerospace orgs. Hunt now.
GoSerpent RAT + HelloNet ViPNet Supply-Chain Campaign: OTX Pulse Analysis — State-Sponsored Intrusion Detection Pack
Two state-linked campaigns hit government networks: GoSerpent RAT targets SE Asia diplomatic entities; HelloNet hijacks ViPNet updates in Russia. CRITICAL — hunt now.
Starland RAT + WLDR PowerShell Implant: UAT-11795 ClickFix Campaign — OTX Pulse Analysis & Enterprise Detection Pack
UAT-11795 deploys novel Starland RAT and WLDR C2 implant via ClickFix lures and trojanized installers. US/EU users targeted for credential and crypto theft. Hunt now.
BandCamPro 'Patriot Bait' Campaign: AI-Deployed C2 Botnet via Google Gemini CLI — OTX Pulse Analysis & Healthcare Detection Pack
Russian-speaking actor 'bandcampro' used Google Gemini CLI to build and migrate a C2 botnet in six minutes, compromising dental clinic systems across the US and Canada. High urgency.
Mustang Panda CoolClient Kernel Rootkit, TA416 EU Espionage & AI-Built 'Patriot Bait' Botnet: OTX Pulse Analysis — Enterprise Detection Pack
HoneyMyte/Mustang Panda deploys CoolClient with a signed kernel rootkit; TA416 resumes EU espionage; an AI-assisted botnet hit US/CA healthcare. High urgency.
Multi-Stage Phishing Redirection Chains: Framer & Cloudflare Workers Abuse with HTML Smuggling — OTX Pulse Detection Pack
OTX pulse exposes multi-stage phishing chains abusing Framer, Cloudflare Workers, and Blob API HTML smuggling to deliver credential theft pages. Enterprise detection pack included.
LabubaRAT Rust Implant + Multi-Stage Phishing Relay Infrastructure: OTX Pulse Analysis — Enterprise Detection Pack
OTX pulses expose LabubaRAT (Rust RAT spoofing NVIDIA software) and multi-stage phishing chains abusing Cloudflare Workers & Framer. Urgent hunt guidance inside.
Cl0p LEMURLOOT MFT Zero-Days, Armored Likho Still Toolkit Rust Espionage + Multi-Stage Phishing Relay: OTX Pulse Detection Pack
OTX: Cl0p MFT zero-days, Armored Likho Still Toolkit Rust espionage, multi-stage phishing; hunt C2, Rust droppers, Cloudflare/Framer redirection.
Midnight Blizzard CaptiveCrunch + UNC6671 Vishing Extortion Wave: OTX Pulse Analysis — Credential & OAuth Attack Detection Pack
APT29 hijacks hotel captive portals for M365 credential theft while ShinyHunters and UNC6671 escalate OAuth abuse and vishing extortion against SaaS. Block IOCs now.
Aeternum Blockchain C2, Midnight Blizzard 'CaptiveCrunch' M365 Credential Theft, and GoldDigger Android Banking Trojan: OTX Pulse Analysis — Enterprise Detection Pack
OTX pulses reveal Polygon blockchain C2 botnets, APT29 hotel captive-portal M365 credential theft, and GoldDigger Android banking trojan targeting finance. High urgency — detect now.
Evilginx AiTM, Midnight Blizzard CaptiveCrunch, APT37 RokRAT: OTX Detection Pack
OTX pulses expose AiTM phishing crews, APT29 hotel captive-portal M365 theft, and APT37 RokRAT spear-phishing; prioritize credential reset, DNS blocking, hunts.
Powercat Infostealer Campaign: Fake Game Cheats Deploying Java Loader for Discord Session Hijacking & Crypto Theft — OTX Detection Pack
Powercat malware campaign uses fake Roblox/Minecraft/GTA V cheats to deliver a multi-stage infostealer targeting Discord sessions and crypto wallets. URGENT: hunt now.
ShadowPad, PlugX & DestroyRAT: TAG-179 Dual-Nexus Espionage Against Pakistani Law Enforcement — OTX Pulse Detection Pack
TAG-179 campaign unites suspected China-nexus and India-nexus actors compromising Balochistan Police networks. ShadowPad, PlugX, Cobalt Strike & RAT IOCs — hunt now.
SilverFox, Mustang Panda & Amaranth-Dragon Converge on Indonesian BFSI: ValleyRAT, LOTUSLITE, and Amaranth Loader Campaign Analysis — OTX Detection Pack
OTX pulse reveals eight APT clusters targeting Indonesian banking and fintech with ValleyRAT, LOTUSLITE, and Amaranth Loader. ICARUS ransomware and underground data sales escalate risk. High urgency.
Rare Werewolf 'Invoice to AnyDesk' Spear-Phishing Campaign: OTX Pulse Analysis — Russian Aerospace Targeting Detection Pack
OTX pulse exposes Rare Werewolf spear-phishing against Russian aerospace orgs — password-protected archives, AnyDesk RAT abuse, scheduled-task persistence, SMTP exfiltration. Hunt now.
Vidar Stealer, Overlord RAT & MacSync: Cross-Platform Credential Theft Campaign — OTX Pulse Detection Pack
OTX pulses expose coordinated stealer campaigns: Vidar+XMRig via malvertising, Overlord RAT via fake Zoom on macOS, and MacSync via ClickFix fake CAPTCHA. High urgency for SOC teams.
Larva-26005 Xctdoor Backdoor, UAT-7810 LapDogs ORB Expansion & Fake CAPTCHA TDS: OTX Pulse Analysis — Enterprise Detection Pack
OTX pulses expose North Korea-linked Xctdoor backdoor ops, UAT-7810's LapDogs ORB malware family, and a 12,700-PDF fake CAPTCHA traffic distribution network. High urgency.
The Gentlemen's EtherRAT & Shai-Hulud npm Supply Chain: OTX Pulse Analysis — Enterprise Detection Pack
Active threats: The Gentlemen deploying Ethereum C2 EtherRAT and Shai-Hulud hijacking npm packages. Detection engineering inside.
China-Nexus Spray-and-Check Campaign: GOCS, SNOWLIGHT, Neo-reGeorg Infrastructure — OTX Pulse Analysis
China-nexus actors exploiting CVE-2025-24813 deploy GOCS/SNOWLIGHT in global spray-and-check. Immediate blocking required.
UAT-11795 ClickFix Campaign & Mirage Kitten NightLedger: Dual-Front RAT/Backdoor Analysis
UAT-11795 leverages ClickFix for Starland RAT; Mirage Kitten targets MEA with NightLedger backdoor. Critical detection engineering required.
Larva-24009 (HeptaX) Phishing Campaign: QuasarRAT & UltraVNC Deployment — Healthcare Sector Threat Analysis
Larva-24009 targeting healthcare with LNK phishing, deploying QuasarRAT and UltraVNC via obfuscated PowerShell. Urgent detection required.
Procurement-Themed AiTM Phishing: FlowerStorm & EvilProxy Campaign — OTX Pulse Analysis
Active AiTM phishing campaign targeting Education/Govt using procurement lures and EvilProxy to bypass MFA. Block domains immediately.
Interlock/Rhysida Ransomware Ecosystem & Global Procurement AiTM Phishing: OTX Pulse Analysis
Hive0163 InterlockRAT/NodeSnake activity & AiTM procurement phishing targeting Gov/Edu. Immediate IOC blocking required.
Phantom Stealer, Ousaban Banking Trojan, and TAG-182 MarkiRAT: OTX Pulse Analysis
OTX Pulse Analysis: Phantom Stealer steals crypto, Ousaban targets Iberian banks, and TAG-182 uses MarkiRAT for surveillance. Urgent IOC blocking required.
Flying Eagle RAT, The Gentlemen RaaS, and BlueShell APT: Multi-Vector Threat Analysis
Active RaaS (The Gentlemen), APT (BlackTech/BlueShell), and mobile banking fraud (Flying Eagle) detected. High urgency for APAC sectors.
Mirage Kitten Campaign: NightLedger Backdoor & ArcBridge Toolset Analysis
APT group Mirage Kitten targets Middle East & Africa aerospace/defense sectors using NightLedger backdoor and custom malware. Critical urgency.
Kimsuky & Void Arachne Surge: KimJongRAT, XenoRAT & DcRAT Campaigns Targeting Asian Infrastructure
Kimsuky & Void Arachne APTs active with KimJongRAT/XenoRAT/DcRAT. Targeting Japan, SK, India via phishing & GitHub abuse. Urgent.
Y2K Operators: Millenium RAT v4 (C++) Telegram C2 Campaign — OTX Pulse Analysis
Y2K Operators distribute rewritten C++ Millenium RAT v4 via MaaS; abuses Telegram API for C2. High urgency detection guidance.
Prinz Eugen Ransomware: ROOTBOY APT Campaign & Go-based Encryptor — OTX Pulse Analysis
New ROOTBOY Go-ransomware 'Prinz Eugen' targets Finance/Gov via RMM abuse. High urgency. IOCs inside.
Void Blizzard Zimbra Exploitation + Tycoon2FA Phishing Trends: OTX Pulse Analysis — Enterprise Detection Pack
Void Blizzard exploits CVE-2025-66376 targeting Ukraine; Tycoon2FA phishing shifts to QR codes. Urgency: High.
Woodgnat Mistic Backdoor & Shai-Hulud NPM Supply Chain Attack: OTX Pulse Analysis
Woodgnat deploys Mistic backdoor & ModeloRAT; Shai-Hulud compromises NPM packages for GitHub token theft. Critical enterprise risk.
FortiBleed, TAG-195 MaaS, & TA458 RoundPress: OTX Pulse Analysis — Enterprise Detection Pack
FortiBleed VPN harvesting, TAG-195 modular MaaS, and TA458 webmail zero-days targeting Gov/Def sectors. Urgency: High.
JadeProx APT: TriBack Loader & Helix Extortion — OTX Pulse Analysis & Detection Pack
JadeProx targets SE Asia with TriBack Loader/PlugX; Helix uses vishing/MFA abuse for extortion. Urgent IOCs and Sigma rules provided.
Dolphin X Stealer & Kontraktnik AI-Driven Infostealer Campaign — Enterprise Detection Pack
New Dolphin X stealer targets 300+ apps & SSH keys. Kontraktnik uses AI profiling. Critical for DevOps & Cloud teams.
Icarus Threat Group: Klue Supply Chain Attack & OAuth Token Theft — Detection Engineering
Active OAuth token theft via Klue supply chain. Icarus targeting CRM data. Critical urgency: immediate token rotation required.
Project CAV3RN Framework & AiTM Phishing Campaign: OTX Pulse Analysis — Enterprise Detection Pack
Active AiTM phishing targeting finance/gov sectors & CHRYSENE's CAV3RN espionage framework targeting Israel. HIGH urgency.
Operation STANDOFF: GitHub Redirect C2 & Multi-Loader Campaign (Raccoon, RedLine, Glupteba)
Russian-speaking campaign distributing Raccoon/RedLine via GitHub redirects. Urgent: Block TimeWeb IPs & hunt for SmokeLoader persistence.
APT-C-36 AsyncRAT Toolkit Evolution & O-UNC-066 Entra Passkey Vishing: OTX Pulse Analysis
Blind Eagle targets LatAm finance with AutoIT RATs; O-UNC-066 launches vishing campaigns against Microsoft Entra passkeys. High urgency.
Operation Poisson: Havoc C2 & RustDesk Fileless Campaign — OTX Pulse Analysis
French actor 'Poisson' uses Havoc C2, RustDesk, and Python keyloggers against automotive sector. Urgent IOC hunting required.
OkoBot Framework with TookPS + Rilide Injector: Multi-Stage Cryptojacking Infrastructure — OTX Pulse Analysis
OkoBot malware framework targeting crypto wallets via TookPS PowerShell and Rilide browser injectors. Active against Brazil, Canada, Mexico. HIGH URGENCY.
ClickFix & OkoBot: AI-Generated Typosquatting and Crypto Theft Targeting LATAM — OTX Pulse Analysis
Active ClickFix campaigns targeting Brazilian finance and crypto users with SmartRAT and OkoBot via AI-generated typosquatting domains. High Urgency.
GoSerpent APT & GlassWASM Supply Chain: OTX Pulse Analysis — Enterprise Detection Pack
OTX Pulse: GoSerpent targets SE Asia gov, GlassWASM abuses VS Code/Solana, OkoBot hits crypto wallets. Critical detection rules included.
OkoBot Crypto-Stealer & UNC6508 Espionage: OTX Pulse Analysis — Detection Engineering Pack
OTX pulses reveal OkoBot crypto theft, UNC6508 medical espionage, and LLM jailbreaking. Urgent detection required.
NuGet Supply Chain Attack & LLM Jailbreaking: O-UNC-038 Phishing — Enterprise Detection Pack
Malicious NuGet game cheats, LLM jailbreak exploits, and O-UNC-038 recruitment phishing targeting enterprise SaaS credentials.
Jalisco PhaaS & LabubaRAT: AI-Powered Threat Landscape Analysis
Active AI-driven phishing campaigns (Jalisco/OmegaLord) and Rust-based RATs (LabubaRAT) targeting enterprise credentials.
Operation ShadowRecruit: SheetAgent RAT & ControlR Abuse Targeting Indian Government
APT campaign targeting Indian job seekers using SheetAgent RAT, ControlR, and Google Sheets C2 via fake recruitment ads.
Operation Capsule Vault: APT37 RokRAT v2 Phishing Campaign — OTX Pulse Analysis
APT37 targets research/gov via spear-phishing delivering malicious ISOs embedding RokRAT EMBED_PAYLOAD_v2. High urgency.
Void Blizzard O365 Espionage & SniperDz PhaaS: OTX Pulse Analysis — Enterprise Detection Pack
Russia-aligned Void Blizzard targets US sectors via O365 session theft; SniperDz PhaaS attacks MENA with browser hijacking. Urgent.
ShadowPad, SpectralViper & NightForge: Geopolitical Espionage Surge in APAC — OTX Pulse Analysis
APAC nations under siege: TAG-179, APT32, and Khmer Shadow target Pakistan, Vietnam, and Cambodia using ShadowPad, SpectralViper, and NightForge loaders.
Showing 50 of 224 reports. Archive expands automatically as new intel is generated.
Every APT & Nation-StateReport Includes SIGMA & KQL Detection Rules
Every intelligence briefing on this page includes at least one Sigma rule, a Microsoft Sentinel KQL hunt query, and an IOC check script — ready to drop into your SIEM. No paywall. No registration.