Dark Side Intelligence Category

APT & Nation-State Intelligence

Advanced Persistent Threat intelligence tracking nation-state actors — Lazarus Group, Sandworm, Volt Typhoon, and others. Campaign TTPs, targeted sectors, and SIGMA/KQL detection rules.

252 reports availableRefreshed every 5 minutes

APT & Nation-State — Archive & Latest

50 reports loaded
APT & Nation-State

Overlord RAT Fake Zoom macOS Chain + UNC6671 Vishing Extortion: OTX Pulse Detection Pack

Fake Zoom installers drop Overlord/FlexibleFerret on macOS while UNC6671 vishing hits Okta/passkey SSO; urgent identity and endpoint hunt.

Sep 6, 2026
Read →
APT & Nation-State

MacSync Stealer ClickFix Campaign: Fake CAPTCHA Terminal Commands Deploy Crypto-Draining Mach-O Payloads — OTX Pulse Analysis & Detection Pack

MacSync stealer uses ClickFix fake CAPTCHA lures to trick macOS users into running Terminal commands, deploying Go Mach-O payloads that drain crypto wallets and harvest credentials.

Sep 5, 2026
Read →
APT & Nation-State

TA416 Mustang Panda EU Espionage: PlugX/Korplug + TONESHELL/PUBLOAD OTX Detection Pack

TA416/Mustang Panda resumes EU government espionage with PlugX/Korplug, TONESHELL and PUBLOAD; hunt web bugs, Turnstile-gated C2 now.

Sep 4, 2026
Read →
APT & Nation-State

The Gentlemen Ransomware — TukTuk C2 v2.0 & GentleKiller BYOVD EDR Neutralization: OTX Detection Pack

The Gentlemen's TukTuk C2 v2.0 exposed with GentleKiller/EDRKiller BYOVD tooling targeting US defense, healthcare, tech & aerospace. Critical urgency.

Sep 3, 2026
Read →
APT & Nation-State

Woodgnat 'Node.js Resurgence' Campaign: ClickFix → ModeloRAT + EtherHiding C2 — OTX Detection Engineering Pack

Woodgnat actors abuse signed node.exe via ClickFix lures to deploy ModeloRAT, EtherRAT & AsukaStealer against US gov/tech/finance. High urgency — detect now.

Sep 3, 2026
Read →
APT & Nation-State

Teams Helpdesk Impersonation + Node.js MSI Implant: Human-Operated Intrusion Chain — OTX Pulse Analysis & Detection Pack

Threat actors impersonating IT helpdesk via Microsoft Teams are deploying MSI loaders and Node.js implants for enterprise-wide access. Urgent: hunt now.

Sep 3, 2026
Read →
APT & Nation-State

Knight Office AiTM Phishing Kit: M365 Session Token Theft Campaign — OTX Pulse Analysis & Detection Pack

CRITICAL: New 'Knight Office' AiTM phishing kit harvests Microsoft 365 session tokens via DocuSign lures, Monday.com redirects, and .vu C2 domains. Enterprise detection pack inside.

Sep 2, 2026
Read →
APT & Nation-State

Larva-24009 (HeptaX) QuasarRAT LNK Campaign + Knight Office M365 AiTM Phishing Kit: OTX Pulse Analysis & Detection Pack

OTX pulses reveal Larva-24009 phishing delivering QuasarRAT via malicious LNKs, and Knight Office AiTM kit stealing M365 session tokens. High urgency.

Sep 2, 2026
Read →
APT & Nation-State

Mirage Kitten APT Deploys NodeRabbit & PollCat Cross-Platform RATs: OTX Pulse Analysis — Detection & Hunt Pack

Mirage Kitten APT shifts to Node.js/JavaScript RATs (NodeRabbit, PollCat) targeting finance and aerospace via LinkedIn lures. HIGH urgency — hunt now.

Sep 1, 2026
Read →
APT & Nation-State

ValleyRAT Backdoor Disguised as QN Wallpaper Adware: Void Arachne DLL Sideloading Campaign — OTX Detection Pack

Void Arachne spreads ValleyRAT backdoor via fake QN Wallpaper adware using DLL sideloading. Targets China/India. Keylogging, clipboard theft, C2 active. HIGH urgency.

Aug 31, 2026
Read →
APT & Nation-State

Blind Eagle GitHub Loader (AsyncRAT/DcRat/XWorm) + 'Mini Shai-Hulud' npm Supply Chain Attack: OTX Pulse Analysis — Enterprise Detection Pack

OTX pulses expose APT-C-36 (Blind Eagle) GitHub-staged RAT loaders targeting Colombian government, and a 10-version npm supply chain compromise via abused GitHub Actions. Hunt now.

Aug 31, 2026
Read →
APT & Nation-State

QScan + Fast Labyrinth 'Quartermaster' Infrastructure: China-Nexus Cyber Espionage Enablement Network — OTX Pulse Analysis & Detection Pack

OTX pulse exposes a China-nexus 'quartermaster' infrastructure model (QScan, Fast Labyrinth, QTRouter) enabling espionage against US/UK critical infrastructure. Hunt now.

Aug 29, 2026
Read →
APT & Nation-State

The Gentlemen RaaS + China-Nexus 'Quartermaster' Espionage Infrastructure: OTX Pulse Analysis — Enterprise Detection Pack

OTX pulses track The Gentlemen dual-extortion RaaS hitting Windows/Linux/ESXi and a China-nexus quartermaster proxy network targeting US/UK critical infrastructure. High urgency.

Aug 29, 2026
Read →
APT & Nation-State

XenoRAT LNK Campaigns, pepesoft.exe Supply-Chain Implant & Aurora Ransomware Leak: OTX Pulse Analysis — Enterprise Detection Pack

OTX pulses expose Kimsuky XenoRAT LNK phishing, malicious NuGet tools dropping pepesoft.exe host surveillance, and a leaked Aurora ransomware affiliate toolkit. Hunt now.

Aug 28, 2026
Read →
APT & Nation-State

DEV#POPPER npm RAT, Flying Eagle Android Botnet & APT28 Moobot Resurgence: OTX Pulse Analysis — Multi-Platform Detection Pack

OTX pulses reveal npm supply-chain RAT (DEV#POPPER), a 170-server Android RAT ecosystem targeting banking in China/Thailand, and APT28-linked Moobot botnet activity post-2024 takedown. High urgency.

Aug 28, 2026
Read →
APT & Nation-State

Dark Caracal GoCaracal Framework + Tortoiseshell TWOSTROKE Backdoor: Dual APT Campaign OTX Analysis — Enterprise Detection Pack

Two APT campaigns active: Dark Caracal deploying GoCaracal modular spyware across Latin America telecom, and Iranian Tortoiseshell targeting defense/aerospace with TWOSTROKE backdoor and SSH tunneling. Immediate C2 blocking required.

Aug 26, 2026
Read →
APT & Nation-State

AMOS Stealer + XMRig macOS ClickFix Crimekit: EtherHiding C2 on Polygon Blockchain — OTX Detection Pack

macOS ClickFix crimekit uses fake CAPTCHA AppleScript lures to drop AMOS stealer + XMRig miner, hiding C2 in Polygon smart contracts. High urgency for Mac fleets.

Aug 26, 2026
Read →
APT & Nation-State

HookBot & ERMAC Source Leak: Exposed Android Banking Trojan Panels Enable Mass Operator Proliferation — OTX Detection Pack

ERMAC/HookBot builder + backend leaked with default creds intact. Financial sector targeted via overlay attacks. 19 live C2 indicators — hunt now.

Aug 25, 2026
Read →
APT & Nation-State

Vanilla Tempest ClickFix Cluster: Supper Malware + DLL Sideloading via MSI & NodeJS — OTX Detection Pack

Vanilla Tempest ClickFix cluster delivering Supper malware via MSI sideloading & NodeJS. C2 dead drops, DLL sideload IOCs + Sigma/KQL detection rules. High urgency.

Aug 25, 2026
Read →
APT & Nation-State

Cyber Av3ngers IOCONTROL + MALPDB Campaign: Nation-State PLC Exploitation Against U.S. Water & Energy Infrastructure — OTX Detection Pack

IRGC-linked Cyber Av3ngers is actively exploiting internet-exposed PLCs across U.S. water and energy sectors, deploying IOCONTROL malware and abusing valid engineering credentials. Hunt now.

Aug 23, 2026
Read →
APT & Nation-State

JadeProx PlugX/TriBack Campaign, Void Blizzard Zimbra Zero-Click Espionage & Helix SharePoint Extortion: OTX Pulse Analysis — Enterprise Detection Pack

OTX pulses expose China-nexus JadeProx intrusions, Russian Void Blizzard Zimbra zero-click espionage, and Helix vishing-driven SharePoint extortion. Hunt now.

Aug 22, 2026
Read →
APT & Nation-State

Head Mare PhantomCore via TrueConf Supply-Chain Compromise + STARDUST CHOLLIMA Rust Crate Backdoor: OTX Pulse Analysis — Enterprise Detection Pack

Two live supply-chain campaigns: Head Mare APT trojanizing TrueConf conferencing clients with PhantomCore, and DPRK-linked STARDUST CHOLLIMA backdooring Rust crates on crates.io. Hunt now.

Aug 21, 2026
Read →
APT & Nation-State

Offside Wallet Theft Factory: 77 Malicious Firefox Extensions Steal Crypto Wallet Seed Phrases via Supabase & Cloudflare Workers C2 — OTX Pulse Detection Pack

OTX pulse exposes 77 Firefox extensions (40 confirmed malicious) stealing crypto wallet recovery phrases and credentials via Supabase switches and Cloudflare Workers C2. HIGH urgency for Web3-facing orgs.

Aug 20, 2026
Read →
APT & Nation-State

Operation STANDOFF + Offside Wallet Theft Factory: Raccoon/RedLine Stealer Ecosystem & Malicious Firefox Extension Campaign — OTX Detection Pack

OTX pulses expose a Russian-speaking pay-per-install stealer/proxy-botnet operation (Raccoon, RedLine, Amadey, SmokeLoader, Glupteba) and 77 Firefox extensions stealing crypto wallets. Hunt now.

Aug 20, 2026
Read →
APT & Nation-State

ClickFix Fileless PowerShell, ENCFORGE AI Ransomware, and Balonx Spyroid PhaaS: OTX Enterprise Detection Pack

OTX: ClickFix fileless PowerShell, JADEPUFFER ENCFORGE AI ransomware via CVE-2025-3248, Balonx PhaaS Spyroid hitting Mexican banks. High urgency.

Aug 20, 2026
Read →
APT & Nation-State

Mirage2FA AiTM PhaaS + CopyCop/Storm-1516 Influence Infrastructure: OTX Pulse Detection Pack

OTX: Mirage2FA AiTM PhaaS hijacks M365 sessions across US sectors; CopyCop/Storm-1516 spins fake media to derail Armenia AI investment. Block IOCs, reset sessions.

Aug 19, 2026
Read →
APT & Nation-State

Octagon Android Banking Botnet + PurpleDelta DPRK Insider Fraud: OTX Pulse Analysis — Mobile MaaS & Identity Deception Detection Pack

New Octagon Android MaaS bot targets crypto wallets and banking apps via accessibility abuse; PurpleDelta DPRK IT workers infiltrated 1,100+ companies with AI personas. High urgency.

Aug 18, 2026
Read →
APT & Nation-State

Projextor + TamperedChef: Electron-Based Trojanized Productivity Apps Distributed via SEO Poisoning — OTX Detection Pack

OTX pulse exposes Projextor campaign weaponizing Electron-based PDF/meal-planner apps via impersonation sites. Working UIs hide desktop capture and JS execution. Hunt now.

Aug 18, 2026
Read →
APT & Nation-State

Blind Eagle (APT-C-36) Evolving Toolkit: AsyncRAT, njRAT & LimeRAT Campaign Targeting Colombian Finance — OTX Detection Pack

Blind Eagle (APT-C-36) is targeting Colombian finance with an evolved toolkit: AsyncRAT, njRAT, LimeRAT, RunPE AutoIt loader, JS AES obfuscation, DuckDNS C2. Hunt now.

Aug 17, 2026
Read →
APT & Nation-State

HelloNet APT Campaign: ViPNet Supply Chain Compromise Deploys HelloInjector/HelloBackdoor Against Russian Critical Infrastructure — OTX Detection Pack

Active APT campaign abuses ViPNet update system via DLL sideloading to deploy 5-stage Rust-based tooling against Russian government, energy, and aerospace orgs. Hunt now.

Aug 15, 2026
Read →
APT & Nation-State

GoSerpent RAT + HelloNet ViPNet Supply-Chain Campaign: OTX Pulse Analysis — State-Sponsored Intrusion Detection Pack

Two state-linked campaigns hit government networks: GoSerpent RAT targets SE Asia diplomatic entities; HelloNet hijacks ViPNet updates in Russia. CRITICAL — hunt now.

Aug 15, 2026
Read →
APT & Nation-State

Starland RAT + WLDR PowerShell Implant: UAT-11795 ClickFix Campaign — OTX Pulse Analysis & Enterprise Detection Pack

UAT-11795 deploys novel Starland RAT and WLDR C2 implant via ClickFix lures and trojanized installers. US/EU users targeted for credential and crypto theft. Hunt now.

Aug 15, 2026
Read →
APT & Nation-State

BandCamPro 'Patriot Bait' Campaign: AI-Deployed C2 Botnet via Google Gemini CLI — OTX Pulse Analysis & Healthcare Detection Pack

Russian-speaking actor 'bandcampro' used Google Gemini CLI to build and migrate a C2 botnet in six minutes, compromising dental clinic systems across the US and Canada. High urgency.

Aug 14, 2026
Read →
APT & Nation-State

Mustang Panda CoolClient Kernel Rootkit, TA416 EU Espionage & AI-Built 'Patriot Bait' Botnet: OTX Pulse Analysis — Enterprise Detection Pack

HoneyMyte/Mustang Panda deploys CoolClient with a signed kernel rootkit; TA416 resumes EU espionage; an AI-assisted botnet hit US/CA healthcare. High urgency.

Aug 14, 2026
Read →
APT & Nation-State

Multi-Stage Phishing Redirection Chains: Framer & Cloudflare Workers Abuse with HTML Smuggling — OTX Pulse Detection Pack

OTX pulse exposes multi-stage phishing chains abusing Framer, Cloudflare Workers, and Blob API HTML smuggling to deliver credential theft pages. Enterprise detection pack included.

Aug 13, 2026
Read →
APT & Nation-State

LabubaRAT Rust Implant + Multi-Stage Phishing Relay Infrastructure: OTX Pulse Analysis — Enterprise Detection Pack

OTX pulses expose LabubaRAT (Rust RAT spoofing NVIDIA software) and multi-stage phishing chains abusing Cloudflare Workers & Framer. Urgent hunt guidance inside.

Aug 13, 2026
Read →
APT & Nation-State

Cl0p LEMURLOOT MFT Zero-Days, Armored Likho Still Toolkit Rust Espionage + Multi-Stage Phishing Relay: OTX Pulse Detection Pack

OTX: Cl0p MFT zero-days, Armored Likho Still Toolkit Rust espionage, multi-stage phishing; hunt C2, Rust droppers, Cloudflare/Framer redirection.

Aug 13, 2026
Read →
APT & Nation-State

Midnight Blizzard CaptiveCrunch + UNC6671 Vishing Extortion Wave: OTX Pulse Analysis — Credential & OAuth Attack Detection Pack

APT29 hijacks hotel captive portals for M365 credential theft while ShinyHunters and UNC6671 escalate OAuth abuse and vishing extortion against SaaS. Block IOCs now.

Aug 12, 2026
Read →
APT & Nation-State

Aeternum Blockchain C2, Midnight Blizzard 'CaptiveCrunch' M365 Credential Theft, and GoldDigger Android Banking Trojan: OTX Pulse Analysis — Enterprise Detection Pack

OTX pulses reveal Polygon blockchain C2 botnets, APT29 hotel captive-portal M365 credential theft, and GoldDigger Android banking trojan targeting finance. High urgency — detect now.

Aug 12, 2026
Read →
APT & Nation-State

Evilginx AiTM, Midnight Blizzard CaptiveCrunch, APT37 RokRAT: OTX Detection Pack

OTX pulses expose AiTM phishing crews, APT29 hotel captive-portal M365 theft, and APT37 RokRAT spear-phishing; prioritize credential reset, DNS blocking, hunts.

Aug 12, 2026
Read →
APT & Nation-State

Powercat Infostealer Campaign: Fake Game Cheats Deploying Java Loader for Discord Session Hijacking & Crypto Theft — OTX Detection Pack

Powercat malware campaign uses fake Roblox/Minecraft/GTA V cheats to deliver a multi-stage infostealer targeting Discord sessions and crypto wallets. URGENT: hunt now.

Aug 10, 2026
Read →
APT & Nation-State

ShadowPad, PlugX & DestroyRAT: TAG-179 Dual-Nexus Espionage Against Pakistani Law Enforcement — OTX Pulse Detection Pack

TAG-179 campaign unites suspected China-nexus and India-nexus actors compromising Balochistan Police networks. ShadowPad, PlugX, Cobalt Strike & RAT IOCs — hunt now.

Aug 8, 2026
Read →
APT & Nation-State

SilverFox, Mustang Panda & Amaranth-Dragon Converge on Indonesian BFSI: ValleyRAT, LOTUSLITE, and Amaranth Loader Campaign Analysis — OTX Detection Pack

OTX pulse reveals eight APT clusters targeting Indonesian banking and fintech with ValleyRAT, LOTUSLITE, and Amaranth Loader. ICARUS ransomware and underground data sales escalate risk. High urgency.

Aug 8, 2026
Read →
APT & Nation-State

Rare Werewolf 'Invoice to AnyDesk' Spear-Phishing Campaign: OTX Pulse Analysis — Russian Aerospace Targeting Detection Pack

OTX pulse exposes Rare Werewolf spear-phishing against Russian aerospace orgs — password-protected archives, AnyDesk RAT abuse, scheduled-task persistence, SMTP exfiltration. Hunt now.

Aug 8, 2026
Read →
APT & Nation-State

Vidar Stealer, Overlord RAT & MacSync: Cross-Platform Credential Theft Campaign — OTX Pulse Detection Pack

OTX pulses expose coordinated stealer campaigns: Vidar+XMRig via malvertising, Overlord RAT via fake Zoom on macOS, and MacSync via ClickFix fake CAPTCHA. High urgency for SOC teams.

Aug 7, 2026
Read →
APT & Nation-State

Larva-26005 Xctdoor Backdoor, UAT-7810 LapDogs ORB Expansion & Fake CAPTCHA TDS: OTX Pulse Analysis — Enterprise Detection Pack

OTX pulses expose North Korea-linked Xctdoor backdoor ops, UAT-7810's LapDogs ORB malware family, and a 12,700-PDF fake CAPTCHA traffic distribution network. High urgency.

Aug 6, 2026
Read →
APT & Nation-State

The Gentlemen's EtherRAT & Shai-Hulud npm Supply Chain: OTX Pulse Analysis — Enterprise Detection Pack

Active threats: The Gentlemen deploying Ethereum C2 EtherRAT and Shai-Hulud hijacking npm packages. Detection engineering inside.

Aug 5, 2026
Read →
APT & Nation-State

China-Nexus Spray-and-Check Campaign: GOCS, SNOWLIGHT, Neo-reGeorg Infrastructure — OTX Pulse Analysis

China-nexus actors exploiting CVE-2025-24813 deploy GOCS/SNOWLIGHT in global spray-and-check. Immediate blocking required.

Aug 4, 2026
Read →
APT & Nation-State

UAT-11795 ClickFix Campaign & Mirage Kitten NightLedger: Dual-Front RAT/Backdoor Analysis

UAT-11795 leverages ClickFix for Starland RAT; Mirage Kitten targets MEA with NightLedger backdoor. Critical detection engineering required.

Aug 4, 2026
Read →
APT & Nation-State

Larva-24009 (HeptaX) Phishing Campaign: QuasarRAT & UltraVNC Deployment — Healthcare Sector Threat Analysis

Larva-24009 targeting healthcare with LNK phishing, deploying QuasarRAT and UltraVNC via obfuscated PowerShell. Urgent detection required.

Aug 4, 2026
Read →

Showing 50 of 252 reports. Archive expands automatically as new intel is generated.

Free Detection Rules Included

Every APT & Nation-StateReport Includes SIGMA & KQL Detection Rules

Every intelligence briefing on this page includes at least one Sigma rule, a Microsoft Sentinel KQL hunt query, and an IOC check script — ready to drop into your SIEM. No paywall. No registration.