Dark Side Intelligence Category

APT & Nation-State Intelligence

Advanced Persistent Threat intelligence tracking nation-state actors — Lazarus Group, Sandworm, Volt Typhoon, and others. Campaign TTPs, targeted sectors, and SIGMA/KQL detection rules.

198 reports availableRefreshed every 5 minutes

APT & Nation-State — Archive & Latest

50 reports loaded
APT & Nation-State

Mirage Kitten Campaign: NightLedger Backdoor & ArcBridge Toolset Analysis

APT group Mirage Kitten targets Middle East & Africa aerospace/defense sectors using NightLedger backdoor and custom malware. Critical urgency.

Jul 28, 2026
Read →
APT & Nation-State

Kimsuky & Void Arachne Surge: KimJongRAT, XenoRAT & DcRAT Campaigns Targeting Asian Infrastructure

Kimsuky & Void Arachne APTs active with KimJongRAT/XenoRAT/DcRAT. Targeting Japan, SK, India via phishing & GitHub abuse. Urgent.

Jul 26, 2026
Read →
APT & Nation-State

Y2K Operators: Millenium RAT v4 (C++) Telegram C2 Campaign — OTX Pulse Analysis

Y2K Operators distribute rewritten C++ Millenium RAT v4 via MaaS; abuses Telegram API for C2. High urgency detection guidance.

Jul 25, 2026
Read →
APT & Nation-State

Prinz Eugen Ransomware: ROOTBOY APT Campaign & Go-based Encryptor — OTX Pulse Analysis

New ROOTBOY Go-ransomware 'Prinz Eugen' targets Finance/Gov via RMM abuse. High urgency. IOCs inside.

Jul 25, 2026
Read →
APT & Nation-State

Void Blizzard Zimbra Exploitation + Tycoon2FA Phishing Trends: OTX Pulse Analysis — Enterprise Detection Pack

Void Blizzard exploits CVE-2025-66376 targeting Ukraine; Tycoon2FA phishing shifts to QR codes. Urgency: High.

Jul 24, 2026
Read →
APT & Nation-State

Woodgnat Mistic Backdoor & Shai-Hulud NPM Supply Chain Attack: OTX Pulse Analysis

Woodgnat deploys Mistic backdoor & ModeloRAT; Shai-Hulud compromises NPM packages for GitHub token theft. Critical enterprise risk.

Jul 24, 2026
Read →
APT & Nation-State

FortiBleed, TAG-195 MaaS, & TA458 RoundPress: OTX Pulse Analysis — Enterprise Detection Pack

FortiBleed VPN harvesting, TAG-195 modular MaaS, and TA458 webmail zero-days targeting Gov/Def sectors. Urgency: High.

Jul 23, 2026
Read →
APT & Nation-State

JadeProx APT: TriBack Loader & Helix Extortion — OTX Pulse Analysis & Detection Pack

JadeProx targets SE Asia with TriBack Loader/PlugX; Helix uses vishing/MFA abuse for extortion. Urgent IOCs and Sigma rules provided.

Jul 23, 2026
Read →
APT & Nation-State

Dolphin X Stealer & Kontraktnik AI-Driven Infostealer Campaign — Enterprise Detection Pack

New Dolphin X stealer targets 300+ apps & SSH keys. Kontraktnik uses AI profiling. Critical for DevOps & Cloud teams.

Jul 22, 2026
Read →
APT & Nation-State

Icarus Threat Group: Klue Supply Chain Attack & OAuth Token Theft — Detection Engineering

Active OAuth token theft via Klue supply chain. Icarus targeting CRM data. Critical urgency: immediate token rotation required.

Jul 22, 2026
Read →
APT & Nation-State

Project CAV3RN Framework & AiTM Phishing Campaign: OTX Pulse Analysis — Enterprise Detection Pack

Active AiTM phishing targeting finance/gov sectors & CHRYSENE's CAV3RN espionage framework targeting Israel. HIGH urgency.

Jul 22, 2026
Read →
APT & Nation-State

Operation STANDOFF: GitHub Redirect C2 & Multi-Loader Campaign (Raccoon, RedLine, Glupteba)

Russian-speaking campaign distributing Raccoon/RedLine via GitHub redirects. Urgent: Block TimeWeb IPs & hunt for SmokeLoader persistence.

Jul 21, 2026
Read →
APT & Nation-State

APT-C-36 AsyncRAT Toolkit Evolution & O-UNC-066 Entra Passkey Vishing: OTX Pulse Analysis

Blind Eagle targets LatAm finance with AutoIT RATs; O-UNC-066 launches vishing campaigns against Microsoft Entra passkeys. High urgency.

Jul 20, 2026
Read →
APT & Nation-State

Operation Poisson: Havoc C2 & RustDesk Fileless Campaign — OTX Pulse Analysis

French actor 'Poisson' uses Havoc C2, RustDesk, and Python keyloggers against automotive sector. Urgent IOC hunting required.

Jul 19, 2026
Read →
APT & Nation-State

OkoBot Framework with TookPS + Rilide Injector: Multi-Stage Cryptojacking Infrastructure — OTX Pulse Analysis

OkoBot malware framework targeting crypto wallets via TookPS PowerShell and Rilide browser injectors. Active against Brazil, Canada, Mexico. HIGH URGENCY.

Jul 17, 2026
Read →
APT & Nation-State

ClickFix & OkoBot: AI-Generated Typosquatting and Crypto Theft Targeting LATAM — OTX Pulse Analysis

Active ClickFix campaigns targeting Brazilian finance and crypto users with SmartRAT and OkoBot via AI-generated typosquatting domains. High Urgency.

Jul 17, 2026
Read →
APT & Nation-State

GoSerpent APT & GlassWASM Supply Chain: OTX Pulse Analysis — Enterprise Detection Pack

OTX Pulse: GoSerpent targets SE Asia gov, GlassWASM abuses VS Code/Solana, OkoBot hits crypto wallets. Critical detection rules included.

Jul 17, 2026
Read →
APT & Nation-State

OkoBot Crypto-Stealer & UNC6508 Espionage: OTX Pulse Analysis — Detection Engineering Pack

OTX pulses reveal OkoBot crypto theft, UNC6508 medical espionage, and LLM jailbreaking. Urgent detection required.

Jul 15, 2026
Read →
APT & Nation-State

NuGet Supply Chain Attack & LLM Jailbreaking: O-UNC-038 Phishing — Enterprise Detection Pack

Malicious NuGet game cheats, LLM jailbreak exploits, and O-UNC-038 recruitment phishing targeting enterprise SaaS credentials.

Jul 15, 2026
Read →
APT & Nation-State

Jalisco PhaaS & LabubaRAT: AI-Powered Threat Landscape Analysis

Active AI-driven phishing campaigns (Jalisco/OmegaLord) and Rust-based RATs (LabubaRAT) targeting enterprise credentials.

Jul 15, 2026
Read →
APT & Nation-State

Operation ShadowRecruit: SheetAgent RAT & ControlR Abuse Targeting Indian Government

APT campaign targeting Indian job seekers using SheetAgent RAT, ControlR, and Google Sheets C2 via fake recruitment ads.

Jul 14, 2026
Read →
APT & Nation-State

Operation Capsule Vault: APT37 RokRAT v2 Phishing Campaign — OTX Pulse Analysis

APT37 targets research/gov via spear-phishing delivering malicious ISOs embedding RokRAT EMBED_PAYLOAD_v2. High urgency.

Jul 13, 2026
Read →
APT & Nation-State

Void Blizzard O365 Espionage & SniperDz PhaaS: OTX Pulse Analysis — Enterprise Detection Pack

Russia-aligned Void Blizzard targets US sectors via O365 session theft; SniperDz PhaaS attacks MENA with browser hijacking. Urgent.

Jul 11, 2026
Read →
APT & Nation-State

ShadowPad, SpectralViper & NightForge: Geopolitical Espionage Surge in APAC — OTX Pulse Analysis

APAC nations under siege: TAG-179, APT32, and Khmer Shadow target Pakistan, Vietnam, and Cambodia using ShadowPad, SpectralViper, and NightForge loaders.

Jul 11, 2026
Read →
APT & Nation-State

Multi-Actor APT Campaigns Targeting Banking & Infrastructure: ValleyRAT, Havoc, and Supply Chain Attacks — Detection & Response Brief

APT groups targeting banking sector with ValleyRAT & Havoc frameworks. Active exploitation of CVE-2025-8088 & npm supply chain compromise. URGENT response required.

Jul 10, 2026
Read →
APT & Nation-State

SilabRAT MaaS & CitrixBleed 2: DragonForce Ransomware & NPM Supply Chain Analysis — Enterprise Detection Pack

OTX Pulse Alert: Active SilabRAT campaigns, DragonForce ransomware exploiting CVE-2025-5777, and malicious NPM SDKs targeting crypto wallets.

Jul 10, 2026
Read →
APT & Nation-State

HarborWatch Agent RAT: ClickFix via Fake Amazon Alerts — OTX Pulse Analysis

HarborWatch Agent RAT distributed via ClickFix attacks using fake Amazon alerts. High urgency for enterprise sectors.

Jul 9, 2026
Read →
APT & Nation-State

X3D MINER & Rare Werewolf: Vidar Stealer, XMRig, and AnyDesk Campaigns — OTX Pulse Analysis

Active campaigns delivering Vidar Stealer, XMRig, and AnyDesk via malvertising and sophisticated phishing targeting US & Russian orgs.

Jul 9, 2026
Read →
APT & Nation-State

GIFTEDCROOK, Overlord & BRICKSTORM: OTX Pulse Analysis — Multi-Front APT Campaigns & Detection Pack

Russian, North Korean, and Chinese APTs target Ukraine, US Devs, and MSPs via WinRAR flaws, GitHub phishing, and edge device compromise.

Jul 8, 2026
Read →
APT & Nation-State

Salat Stealer, UNK_MassTraction & Cavern Manticore: OTX Pulse Analysis — Multi-Vector APT Campaigns

Three active campaigns: Salat Stealer infostealer, UNK_MassTraction exploiting Roundcube in universities, and Iran-linked Cavern Manticore targeting Israel. High urgency.

Jul 7, 2026
Read →
APT & Nation-State

OP-512 China-Linked Espionage + UNC3753 Targeted Campaigns: GhostKit, PlugX, Cobalt Strike, BazarLoader, TrickBot - OTX Pulse Analysis — Enterprise Detection Pack

China-linked OP-512 targets IIS with GhostKit; UNC3753 attacks US law firms with BazarLoader/TrickBot. HIGH PRIORITY threat intel.

Jul 5, 2026
Read →
APT & Nation-State

MarkiRAT Surveillance Operations + Pink Vishing Campaign + Global Smishing Network: OTX Pulse Analysis — Enterprise Detection Pack

Iran's TAG-182 using MarkiRAT; Pink gang with vishing; massive smishing op. High urgency for global enterprises.

Jul 4, 2026
Read →
APT & Nation-State

SessionGate, RemusStealer, PCPJack & APT37 Supply Chain: OTX Pulse Analysis — Enterprise Detection Pack

OTX detects large-scale open-source impersonation, cloud SMTP relays, and APT37 supply chain attacks targeting Yanbian.

Jul 3, 2026
Read →
APT & Nation-State

Bumblebee Loader, The Gentlemen RaaS, and Ousaban: Multi-Vector OTX Pulse Analysis

Active campaigns delivering Akira via SEO poisoning, The Gentlemen RaaS exploiting VPNs, and Ousaban targeting Iberian banks.

Jul 2, 2026
Read →
APT & Nation-State

Bumblebee Loader, The Gentlemen RaaS, and Ousaban: OTX Pulse Analysis — SEO Poisoning and Geofenced Banking Trojans

High-threat activity: SEO poisoning delivers Akira via Bumblebee; The Gentlemen RaaS exploits VPNs; Ousaban targets Iberia with geofenced phishing.

Jul 2, 2026
Read →
APT & Nation-State

Bumblebee/Akira RaaS, The Gentlemen Backdoors, and Ousaban Banking Trojan: OTX Pulse Analysis — Enterprise Detection Pack

Severe RaaS and banking trojan campaigns detected via SEO poisoning and phishing. Urgency: High.

Jul 2, 2026
Read →
APT & Nation-State

Bumblebee Loader, The Gentlemen RaaS, and JINX-0164: OTX Pulse Analysis — Supply Chain & SEO Poisoning Wave

SEO poisoning, supply chain attacks, and RaaS identified via Bumblebee, Akira, and JINX-0164. Critical urgency for crypto and enterprise sectors.

Jul 1, 2026
Read →
APT & Nation-State

Multi-Vector RaaS and Supply Chain Attacks: Bumblebee, The Gentlemen, and JINX-0164 OTX Pulse Analysis

Urgent detection guidance for SEO poisoning, RaaS expansion via SharkLoader, and crypto supply chain attacks targeting dev infrastructure.

Jun 30, 2026
Read →
APT & Nation-State

Triple Threat: Bumblebee→Akira SEO Poisoning, The Gentlemen RaaS Expansion, and JINX-0164 Crypto Supply Chain Attacks — OTX Pulse Analysis & Detection Engineering

Three active OTX campaigns detected: Bumblebee/Akira SEO poisoning, Gentlemen RaaS targeting 6 sectors, and JINX-0164 crypto supply chain attacks. High urgency.

Jun 30, 2026
Read →
APT & Nation-State

Bumblebee→Akira SEO Poisoning, The Gentlemen RaaS Surge & JINX-0164 Crypto Supply Chain Attacks: OTX Pulse Intelligence Briefing

Three active campaigns detected: Bumblebee→Akira via SEO poisoning, The Gentlemen RaaS top-10 threat, JINX-0164 targeting crypto developers. Critical urgency.

Jun 30, 2026
Read →
APT & Nation-State

Woodgnat Access Broker & JINX-0164 macOS Campaigns: Mistic, ModeloRAT, AUDIOFIX — OTX Detection Pack

OTX pulses reveal active campaigns: Woodgnat (Mistic/ModeloRAT) targeting EdTech/Insurance, JINX-0164 (AUDIOFIX) hitting Crypto devs, and Kimsuky (KimJongRAT) via GitHub.

Jun 29, 2026
Read →
APT & Nation-State

Woodgnat, JINX-0164, and Kimsuky Campaigns: OTX Pulse Analysis — Mistic, AUDIOFIX, and KimJongRAT Detection Pack

Active threats: Woodgnat IAB deploys Mistic/ModeloRAT for ransomware; JINX-0164 targets crypto via LinkedIn; Kimsuky evolves KimJongRAT via GitHub.

Jun 29, 2026
Read →
APT & Nation-State

Woodgnat IAB & Kimsuky Campaigns: Mistic Backdoor, JINX-0164 macOS RATs, and LOTS Abuse Analysis

Critical threats: Woodgnat's Mistic backdoor, JINX-0164's crypto-targeting macOS RATs, and Kimsuky's GitHub abuse detected. High urgency.

Jun 29, 2026
Read →
APT & Nation-State

Woodgnat, JINX-0164 & Kimsuky: Multi-Front RAT Offensive (Mistic, AUDIOFIX, KimJongRAT)

OTX Pulse Analysis: Woodgnat, JINX-0164, and Kimsuky deploy Mistic, AUDIOFIX, and KimJongRAT via sideloading, supply chain, and GitHub abuse.

Jun 28, 2026
Read →
APT & Nation-State

Woodgnat, JINX-0164, and Kimsuky Campaigns: Mistic, AUDIOFIX, and KimJongRAT Analysis

OTX analysis reveals IAB Woodgnat and APTs Kimsuky/JINX-0164 deploying Mistic, AUDIOFIX, and KimJongRAT via sideloading and GitHub.

Jun 27, 2026
Read →
APT & Nation-State

Woodgnat Mistic Backdoor, JINX-0164 Crypto Supply Chain, Kimsuky KimJongRAT: OTX Pulse Analysis

OTX detects Woodgnat Mistic backdoor, JINX-0164 targeting crypto devs via macOS/Python, and Kimsuky's evolved KimJongRAT. Urgency: High.

Jun 27, 2026
Read →
APT & Nation-State

Mistic Backdoor, KimJongRAT, and Besomar-Themed Supply Chain Attacks: OTX Pulse Analysis

Active campaigns: Woodgnat's Mistic backdoor, Kimsuky's KimJongRAT, and GhostShell's supply chain attack on UAVs. High urgency.

Jun 26, 2026
Read →
APT & Nation-State

Woodgnat, Kimsuky & GhostShell: Mistic Backdoor, KimJongRAT & UAV Supply Chain Attack — OTX Pulse Analysis

Urgent: Woodgnat, Kimsuky, and GhostShell target sectors with Mistic backdoor, KimJongRAT, and Vidar via supply chain compromise.

Jun 26, 2026
Read →
APT & Nation-State

Woodgnat IAB Operations & GhostShell UAV Attacks: Mistic Backdoor and Vidar Stealer Analysis

Woodgnat IAB deploys Mistic/ModeloRAT for ransomware; GhostShell targets Ukraine UAV supply chain with Vidar.

Jun 25, 2026
Read →
APT & Nation-State

Woodgnat Access Broker & GhostShell Supply Chain: Mistic Backdoor, Vidar Stealer, and Middle East C2 Infrastructure

Active Woodgnat access brokering, GhostShell targeting Ukraine's UAV sector, and massive Middle East C2 expansion detected via OTX.

Jun 24, 2026
Read →

Showing 50 of 198 reports. Archive expands automatically as new intel is generated.

Free Detection Rules Included

Every APT & Nation-StateReport Includes SIGMA & KQL Detection Rules

Every intelligence briefing on this page includes at least one Sigma rule, a Microsoft Sentinel KQL hunt query, and an IOC check script — ready to drop into your SIEM. No paywall. No registration.