APT & Nation-State Intelligence
Advanced Persistent Threat intelligence tracking nation-state actors — Lazarus Group, Sandworm, Volt Typhoon, and others. Campaign TTPs, targeted sectors, and SIGMA/KQL detection rules.
APT & Nation-State — Archive & Latest
Overlord RAT Fake Zoom macOS Chain + UNC6671 Vishing Extortion: OTX Pulse Detection Pack
Fake Zoom installers drop Overlord/FlexibleFerret on macOS while UNC6671 vishing hits Okta/passkey SSO; urgent identity and endpoint hunt.
MacSync Stealer ClickFix Campaign: Fake CAPTCHA Terminal Commands Deploy Crypto-Draining Mach-O Payloads — OTX Pulse Analysis & Detection Pack
MacSync stealer uses ClickFix fake CAPTCHA lures to trick macOS users into running Terminal commands, deploying Go Mach-O payloads that drain crypto wallets and harvest credentials.
TA416 Mustang Panda EU Espionage: PlugX/Korplug + TONESHELL/PUBLOAD OTX Detection Pack
TA416/Mustang Panda resumes EU government espionage with PlugX/Korplug, TONESHELL and PUBLOAD; hunt web bugs, Turnstile-gated C2 now.
The Gentlemen Ransomware — TukTuk C2 v2.0 & GentleKiller BYOVD EDR Neutralization: OTX Detection Pack
The Gentlemen's TukTuk C2 v2.0 exposed with GentleKiller/EDRKiller BYOVD tooling targeting US defense, healthcare, tech & aerospace. Critical urgency.
Woodgnat 'Node.js Resurgence' Campaign: ClickFix → ModeloRAT + EtherHiding C2 — OTX Detection Engineering Pack
Woodgnat actors abuse signed node.exe via ClickFix lures to deploy ModeloRAT, EtherRAT & AsukaStealer against US gov/tech/finance. High urgency — detect now.
Teams Helpdesk Impersonation + Node.js MSI Implant: Human-Operated Intrusion Chain — OTX Pulse Analysis & Detection Pack
Threat actors impersonating IT helpdesk via Microsoft Teams are deploying MSI loaders and Node.js implants for enterprise-wide access. Urgent: hunt now.
Knight Office AiTM Phishing Kit: M365 Session Token Theft Campaign — OTX Pulse Analysis & Detection Pack
CRITICAL: New 'Knight Office' AiTM phishing kit harvests Microsoft 365 session tokens via DocuSign lures, Monday.com redirects, and .vu C2 domains. Enterprise detection pack inside.
Larva-24009 (HeptaX) QuasarRAT LNK Campaign + Knight Office M365 AiTM Phishing Kit: OTX Pulse Analysis & Detection Pack
OTX pulses reveal Larva-24009 phishing delivering QuasarRAT via malicious LNKs, and Knight Office AiTM kit stealing M365 session tokens. High urgency.
Mirage Kitten APT Deploys NodeRabbit & PollCat Cross-Platform RATs: OTX Pulse Analysis — Detection & Hunt Pack
Mirage Kitten APT shifts to Node.js/JavaScript RATs (NodeRabbit, PollCat) targeting finance and aerospace via LinkedIn lures. HIGH urgency — hunt now.
ValleyRAT Backdoor Disguised as QN Wallpaper Adware: Void Arachne DLL Sideloading Campaign — OTX Detection Pack
Void Arachne spreads ValleyRAT backdoor via fake QN Wallpaper adware using DLL sideloading. Targets China/India. Keylogging, clipboard theft, C2 active. HIGH urgency.
Blind Eagle GitHub Loader (AsyncRAT/DcRat/XWorm) + 'Mini Shai-Hulud' npm Supply Chain Attack: OTX Pulse Analysis — Enterprise Detection Pack
OTX pulses expose APT-C-36 (Blind Eagle) GitHub-staged RAT loaders targeting Colombian government, and a 10-version npm supply chain compromise via abused GitHub Actions. Hunt now.
QScan + Fast Labyrinth 'Quartermaster' Infrastructure: China-Nexus Cyber Espionage Enablement Network — OTX Pulse Analysis & Detection Pack
OTX pulse exposes a China-nexus 'quartermaster' infrastructure model (QScan, Fast Labyrinth, QTRouter) enabling espionage against US/UK critical infrastructure. Hunt now.
The Gentlemen RaaS + China-Nexus 'Quartermaster' Espionage Infrastructure: OTX Pulse Analysis — Enterprise Detection Pack
OTX pulses track The Gentlemen dual-extortion RaaS hitting Windows/Linux/ESXi and a China-nexus quartermaster proxy network targeting US/UK critical infrastructure. High urgency.
XenoRAT LNK Campaigns, pepesoft.exe Supply-Chain Implant & Aurora Ransomware Leak: OTX Pulse Analysis — Enterprise Detection Pack
OTX pulses expose Kimsuky XenoRAT LNK phishing, malicious NuGet tools dropping pepesoft.exe host surveillance, and a leaked Aurora ransomware affiliate toolkit. Hunt now.
DEV#POPPER npm RAT, Flying Eagle Android Botnet & APT28 Moobot Resurgence: OTX Pulse Analysis — Multi-Platform Detection Pack
OTX pulses reveal npm supply-chain RAT (DEV#POPPER), a 170-server Android RAT ecosystem targeting banking in China/Thailand, and APT28-linked Moobot botnet activity post-2024 takedown. High urgency.
Dark Caracal GoCaracal Framework + Tortoiseshell TWOSTROKE Backdoor: Dual APT Campaign OTX Analysis — Enterprise Detection Pack
Two APT campaigns active: Dark Caracal deploying GoCaracal modular spyware across Latin America telecom, and Iranian Tortoiseshell targeting defense/aerospace with TWOSTROKE backdoor and SSH tunneling. Immediate C2 blocking required.
AMOS Stealer + XMRig macOS ClickFix Crimekit: EtherHiding C2 on Polygon Blockchain — OTX Detection Pack
macOS ClickFix crimekit uses fake CAPTCHA AppleScript lures to drop AMOS stealer + XMRig miner, hiding C2 in Polygon smart contracts. High urgency for Mac fleets.
HookBot & ERMAC Source Leak: Exposed Android Banking Trojan Panels Enable Mass Operator Proliferation — OTX Detection Pack
ERMAC/HookBot builder + backend leaked with default creds intact. Financial sector targeted via overlay attacks. 19 live C2 indicators — hunt now.
Vanilla Tempest ClickFix Cluster: Supper Malware + DLL Sideloading via MSI & NodeJS — OTX Detection Pack
Vanilla Tempest ClickFix cluster delivering Supper malware via MSI sideloading & NodeJS. C2 dead drops, DLL sideload IOCs + Sigma/KQL detection rules. High urgency.
Cyber Av3ngers IOCONTROL + MALPDB Campaign: Nation-State PLC Exploitation Against U.S. Water & Energy Infrastructure — OTX Detection Pack
IRGC-linked Cyber Av3ngers is actively exploiting internet-exposed PLCs across U.S. water and energy sectors, deploying IOCONTROL malware and abusing valid engineering credentials. Hunt now.
JadeProx PlugX/TriBack Campaign, Void Blizzard Zimbra Zero-Click Espionage & Helix SharePoint Extortion: OTX Pulse Analysis — Enterprise Detection Pack
OTX pulses expose China-nexus JadeProx intrusions, Russian Void Blizzard Zimbra zero-click espionage, and Helix vishing-driven SharePoint extortion. Hunt now.
Head Mare PhantomCore via TrueConf Supply-Chain Compromise + STARDUST CHOLLIMA Rust Crate Backdoor: OTX Pulse Analysis — Enterprise Detection Pack
Two live supply-chain campaigns: Head Mare APT trojanizing TrueConf conferencing clients with PhantomCore, and DPRK-linked STARDUST CHOLLIMA backdooring Rust crates on crates.io. Hunt now.
Offside Wallet Theft Factory: 77 Malicious Firefox Extensions Steal Crypto Wallet Seed Phrases via Supabase & Cloudflare Workers C2 — OTX Pulse Detection Pack
OTX pulse exposes 77 Firefox extensions (40 confirmed malicious) stealing crypto wallet recovery phrases and credentials via Supabase switches and Cloudflare Workers C2. HIGH urgency for Web3-facing orgs.
Operation STANDOFF + Offside Wallet Theft Factory: Raccoon/RedLine Stealer Ecosystem & Malicious Firefox Extension Campaign — OTX Detection Pack
OTX pulses expose a Russian-speaking pay-per-install stealer/proxy-botnet operation (Raccoon, RedLine, Amadey, SmokeLoader, Glupteba) and 77 Firefox extensions stealing crypto wallets. Hunt now.
ClickFix Fileless PowerShell, ENCFORGE AI Ransomware, and Balonx Spyroid PhaaS: OTX Enterprise Detection Pack
OTX: ClickFix fileless PowerShell, JADEPUFFER ENCFORGE AI ransomware via CVE-2025-3248, Balonx PhaaS Spyroid hitting Mexican banks. High urgency.
Mirage2FA AiTM PhaaS + CopyCop/Storm-1516 Influence Infrastructure: OTX Pulse Detection Pack
OTX: Mirage2FA AiTM PhaaS hijacks M365 sessions across US sectors; CopyCop/Storm-1516 spins fake media to derail Armenia AI investment. Block IOCs, reset sessions.
Octagon Android Banking Botnet + PurpleDelta DPRK Insider Fraud: OTX Pulse Analysis — Mobile MaaS & Identity Deception Detection Pack
New Octagon Android MaaS bot targets crypto wallets and banking apps via accessibility abuse; PurpleDelta DPRK IT workers infiltrated 1,100+ companies with AI personas. High urgency.
Projextor + TamperedChef: Electron-Based Trojanized Productivity Apps Distributed via SEO Poisoning — OTX Detection Pack
OTX pulse exposes Projextor campaign weaponizing Electron-based PDF/meal-planner apps via impersonation sites. Working UIs hide desktop capture and JS execution. Hunt now.
Blind Eagle (APT-C-36) Evolving Toolkit: AsyncRAT, njRAT & LimeRAT Campaign Targeting Colombian Finance — OTX Detection Pack
Blind Eagle (APT-C-36) is targeting Colombian finance with an evolved toolkit: AsyncRAT, njRAT, LimeRAT, RunPE AutoIt loader, JS AES obfuscation, DuckDNS C2. Hunt now.
HelloNet APT Campaign: ViPNet Supply Chain Compromise Deploys HelloInjector/HelloBackdoor Against Russian Critical Infrastructure — OTX Detection Pack
Active APT campaign abuses ViPNet update system via DLL sideloading to deploy 5-stage Rust-based tooling against Russian government, energy, and aerospace orgs. Hunt now.
GoSerpent RAT + HelloNet ViPNet Supply-Chain Campaign: OTX Pulse Analysis — State-Sponsored Intrusion Detection Pack
Two state-linked campaigns hit government networks: GoSerpent RAT targets SE Asia diplomatic entities; HelloNet hijacks ViPNet updates in Russia. CRITICAL — hunt now.
Starland RAT + WLDR PowerShell Implant: UAT-11795 ClickFix Campaign — OTX Pulse Analysis & Enterprise Detection Pack
UAT-11795 deploys novel Starland RAT and WLDR C2 implant via ClickFix lures and trojanized installers. US/EU users targeted for credential and crypto theft. Hunt now.
BandCamPro 'Patriot Bait' Campaign: AI-Deployed C2 Botnet via Google Gemini CLI — OTX Pulse Analysis & Healthcare Detection Pack
Russian-speaking actor 'bandcampro' used Google Gemini CLI to build and migrate a C2 botnet in six minutes, compromising dental clinic systems across the US and Canada. High urgency.
Mustang Panda CoolClient Kernel Rootkit, TA416 EU Espionage & AI-Built 'Patriot Bait' Botnet: OTX Pulse Analysis — Enterprise Detection Pack
HoneyMyte/Mustang Panda deploys CoolClient with a signed kernel rootkit; TA416 resumes EU espionage; an AI-assisted botnet hit US/CA healthcare. High urgency.
Multi-Stage Phishing Redirection Chains: Framer & Cloudflare Workers Abuse with HTML Smuggling — OTX Pulse Detection Pack
OTX pulse exposes multi-stage phishing chains abusing Framer, Cloudflare Workers, and Blob API HTML smuggling to deliver credential theft pages. Enterprise detection pack included.
LabubaRAT Rust Implant + Multi-Stage Phishing Relay Infrastructure: OTX Pulse Analysis — Enterprise Detection Pack
OTX pulses expose LabubaRAT (Rust RAT spoofing NVIDIA software) and multi-stage phishing chains abusing Cloudflare Workers & Framer. Urgent hunt guidance inside.
Cl0p LEMURLOOT MFT Zero-Days, Armored Likho Still Toolkit Rust Espionage + Multi-Stage Phishing Relay: OTX Pulse Detection Pack
OTX: Cl0p MFT zero-days, Armored Likho Still Toolkit Rust espionage, multi-stage phishing; hunt C2, Rust droppers, Cloudflare/Framer redirection.
Midnight Blizzard CaptiveCrunch + UNC6671 Vishing Extortion Wave: OTX Pulse Analysis — Credential & OAuth Attack Detection Pack
APT29 hijacks hotel captive portals for M365 credential theft while ShinyHunters and UNC6671 escalate OAuth abuse and vishing extortion against SaaS. Block IOCs now.
Aeternum Blockchain C2, Midnight Blizzard 'CaptiveCrunch' M365 Credential Theft, and GoldDigger Android Banking Trojan: OTX Pulse Analysis — Enterprise Detection Pack
OTX pulses reveal Polygon blockchain C2 botnets, APT29 hotel captive-portal M365 credential theft, and GoldDigger Android banking trojan targeting finance. High urgency — detect now.
Evilginx AiTM, Midnight Blizzard CaptiveCrunch, APT37 RokRAT: OTX Detection Pack
OTX pulses expose AiTM phishing crews, APT29 hotel captive-portal M365 theft, and APT37 RokRAT spear-phishing; prioritize credential reset, DNS blocking, hunts.
Powercat Infostealer Campaign: Fake Game Cheats Deploying Java Loader for Discord Session Hijacking & Crypto Theft — OTX Detection Pack
Powercat malware campaign uses fake Roblox/Minecraft/GTA V cheats to deliver a multi-stage infostealer targeting Discord sessions and crypto wallets. URGENT: hunt now.
ShadowPad, PlugX & DestroyRAT: TAG-179 Dual-Nexus Espionage Against Pakistani Law Enforcement — OTX Pulse Detection Pack
TAG-179 campaign unites suspected China-nexus and India-nexus actors compromising Balochistan Police networks. ShadowPad, PlugX, Cobalt Strike & RAT IOCs — hunt now.
SilverFox, Mustang Panda & Amaranth-Dragon Converge on Indonesian BFSI: ValleyRAT, LOTUSLITE, and Amaranth Loader Campaign Analysis — OTX Detection Pack
OTX pulse reveals eight APT clusters targeting Indonesian banking and fintech with ValleyRAT, LOTUSLITE, and Amaranth Loader. ICARUS ransomware and underground data sales escalate risk. High urgency.
Rare Werewolf 'Invoice to AnyDesk' Spear-Phishing Campaign: OTX Pulse Analysis — Russian Aerospace Targeting Detection Pack
OTX pulse exposes Rare Werewolf spear-phishing against Russian aerospace orgs — password-protected archives, AnyDesk RAT abuse, scheduled-task persistence, SMTP exfiltration. Hunt now.
Vidar Stealer, Overlord RAT & MacSync: Cross-Platform Credential Theft Campaign — OTX Pulse Detection Pack
OTX pulses expose coordinated stealer campaigns: Vidar+XMRig via malvertising, Overlord RAT via fake Zoom on macOS, and MacSync via ClickFix fake CAPTCHA. High urgency for SOC teams.
Larva-26005 Xctdoor Backdoor, UAT-7810 LapDogs ORB Expansion & Fake CAPTCHA TDS: OTX Pulse Analysis — Enterprise Detection Pack
OTX pulses expose North Korea-linked Xctdoor backdoor ops, UAT-7810's LapDogs ORB malware family, and a 12,700-PDF fake CAPTCHA traffic distribution network. High urgency.
The Gentlemen's EtherRAT & Shai-Hulud npm Supply Chain: OTX Pulse Analysis — Enterprise Detection Pack
Active threats: The Gentlemen deploying Ethereum C2 EtherRAT and Shai-Hulud hijacking npm packages. Detection engineering inside.
China-Nexus Spray-and-Check Campaign: GOCS, SNOWLIGHT, Neo-reGeorg Infrastructure — OTX Pulse Analysis
China-nexus actors exploiting CVE-2025-24813 deploy GOCS/SNOWLIGHT in global spray-and-check. Immediate blocking required.
UAT-11795 ClickFix Campaign & Mirage Kitten NightLedger: Dual-Front RAT/Backdoor Analysis
UAT-11795 leverages ClickFix for Starland RAT; Mirage Kitten targets MEA with NightLedger backdoor. Critical detection engineering required.
Larva-24009 (HeptaX) Phishing Campaign: QuasarRAT & UltraVNC Deployment — Healthcare Sector Threat Analysis
Larva-24009 targeting healthcare with LNK phishing, deploying QuasarRAT and UltraVNC via obfuscated PowerShell. Urgent detection required.
Showing 50 of 252 reports. Archive expands automatically as new intel is generated.
Every APT & Nation-StateReport Includes SIGMA & KQL Detection Rules
Every intelligence briefing on this page includes at least one Sigma rule, a Microsoft Sentinel KQL hunt query, and an IOC check script — ready to drop into your SIEM. No paywall. No registration.