Dark Side Intelligence Category

APT & Nation-State Intelligence

Advanced Persistent Threat intelligence tracking nation-state actors — Lazarus Group, Sandworm, Volt Typhoon, and others. Campaign TTPs, targeted sectors, and SIGMA/KQL detection rules.

279 reports available•Refreshed every 5 minutes

APT & Nation-State — Archive & Latest

50 reports loaded
APT & Nation-State

Moobot/Mirai Botnet Resurgence: Open Directory Exposure of 'StresD Pro+' DDoS-as-a-Service Panel — OTX Pulse Analysis & Detection Pack

OTX pulse reveals exposed Moobot source code and active 'StresD Pro+' DDoS panel post-2024 takedown. IoT botnet ops tied to China-linked infrastructure. High urgency.

Sep 26, 2026
Read →
APT & Nation-State

Salt Typhoon / Fire Ant TACACS+ Pre-Auth RCE (CVE-2026-48842): OTX Pulse Analysis — Telecom Infrastructure Detection Pack

OTX flags critical pre-auth RCE in TACACS+ (CVE-2026-48842) tied to Salt Typhoon/Fire Ant telecom espionage. Pre-authentication exploitation of network AAA. URGENT.

Sep 26, 2026
Read →
APT & Nation-State

ClickFix Clipboard Poisoning via third-party.com, Galago Ransomware Emergence, and TACACS+ Pre-Auth RCE: OTX Pulse Analysis — Enterprise Detection Pack

ClickFix lures hijack placeholder domain third-party.com; Galago ransomware hits Icelandic healthcare; critical pre-auth RCE in TACACS+ protocol. Hunt now.

Sep 25, 2026
Read →
APT & Nation-State

HookBot Android Banking Trojan Leak, ClickFix Clipboard Poisoning & Konni VelvetCake LNK Campaign: OTX Pulse Analysis — Enterprise Detection Pack

OTX pulses expose leaked HookBot/ERMAC panels with default creds, ClickFix lures on third-party[.]com, and Konni's VelvetCake LNK campaign targeting Ukraine. Hunt now.

Sep 24, 2026
Read →
APT & Nation-State

PavinLoader Multi-Stage Campaign: ClickFix, Fake Captchas & EtherHiding Blockchain C2 — OTX Pulse Analysis with Enterprise Detection Pack

PavinLoader .NET loader distributing Amatera Stealer & HijackLoader via ClickFix/fake captcha lures, using MSBuild abuse and EtherHiding blockchain C2. High urgency.

Sep 24, 2026
Read →
APT & Nation-State

DPRK Hangro State VPN Infrastructure Exposed: Silibank Mail Relays & Rogue Certificate Hierarchy — OTX Detection Pack

OTX pulse exposes North Korea's Hangro state VPN/mail infrastructure spanning Pyongyang, Russian Far East & Chinese netblocks. Rogue certs, mail relays identified. Hunt now.

Sep 23, 2026
Read →
APT & Nation-State

ClickFix Fake CAPTCHA Chains, UTA0565 Chrome/Windows 0-Days & Red Heron Kapibala: OTX Pulse Analysis — Enterprise Detection Pack

CRITICAL: Bulletproof-hosted ClickFix malware chains, Chinese APT zero-day phishing (UTA0565), and Red Heron WordPress exploitation hitting governments globally.

Sep 23, 2026
Read →
APT & Nation-State

INC Ransomware Double-Extortion Campaign + DPRK Hangro VPN Infrastructure: OTX Pulse Detection Pack — IAB Handoffs, BYOVD & SoftEther C2

OTX pulses expose INC ransomware's 17-day IAB-to-affiliate attack chain across 175 endpoints and North Korea's Hangro VPN/mail infrastructure on Russian Far East servers. Hunt now.

Sep 22, 2026
Read →
APT & Nation-State

Operation DreamJob Resurfaces: Lazarus LightlessCan, NickelLoader and BLINDINGCAN Trojanized Coding Challenges — OTX Detection Pack

Lazarus Operation DreamJob spearphishing targets aerospace via fake Meta recruiter coding tests; hunt LightlessCan, NickelLoader, BLINDINGCAN IOCs now.

Sep 21, 2026
Read →
APT & Nation-State

Head Mare APT Exploits TrueConf Video Conferencing Servers to Deliver PhantomCore Malware: OTX Pulse Analysis — Supply Chain Detection Pack

Head Mare APT exploited two TrueConf server vulnerabilities to push trojanized client installers and PhantomCore/PhantomGraph malware to conference participants. Patch and hunt now.

Sep 20, 2026
Read →
APT & Nation-State

Mirage2FA PhaaS Session Hijacking + BlackCore Influence-for-Hire: OTX Pulse Analysis — Enterprise Detection Pack

Mirage2FA PhaaS steals Microsoft 365 sessions via AiTM attacks (4K+ US victims); BlackCore runs global influence-for-hire ops. Detection pack inside.

Sep 19, 2026
Read →
APT & Nation-State

Offside Wallet Theft Factory, Mirage2FA AiTM, and PurpleDelta DPRK Employment Fraud: OTX Enterprise Detection Pack

OTX: 77 malicious Firefox extensions, Mirage2FA AiTM M365 session theft, and PurpleDelta DPRK job-fraud personas. Enterprise identity/browser risk is high.

Sep 18, 2026
Read →
APT & Nation-State

EtherHiding Blockchain C2, BlackHatSect0r/DXQRTXX Go C2, Balonx Spyroid PhaaS: OTX Enterprise Detection Pack

OTX pulses expose EtherHiding blockchain C2, BlackHatSect0r/DXQRTXX Go C2 credential harvesting and Balonx Spyroid PhaaS hitting banks; hunt now.

Sep 18, 2026
Read →
APT & Nation-State

LabubaRAT, EtherHiding Blockchain C2 & PolinRider Supply Chain Campaign: OTX Pulse Analysis — Enterprise Detection Pack

OTX pulses expose a Rust RAT spoofing NVIDIA software, a Polygon blockchain C2 campaign, and a Packagist supply-chain infostealer. Enterprise detection pack inside.

Sep 18, 2026
Read →
APT & Nation-State

Octagon Android MaaS + APT36 Operation RapidRust + Mirage2FA AiTM Kit: OTX Pulse Analysis — Mobile Banking Fraud, GitHub C2 Backdoors, and M365 Session Hijacking Detection Pack

OTX pulses expose AndroidKitKat's Octagon banking bot, APT36's Rust backdoors hitting India/Afghanistan defense, and Mirage2FA AiTM phishing with 4K+ US victims. High urgency.

Sep 17, 2026
Read →
APT & Nation-State

VectraRAT MaaS Platform, Noodle RAT Espionage Kit & APT36 Operation RapidRust: OTX Pulse Analysis — Multi-Family Detection Pack

OTX pulses expose VectraRAT MaaS rentals, Chinese-nexus Noodle RAT espionage, and APT36's Rust-based RapidRust campaign targeting government, defense, and finance. High urgency.

Sep 17, 2026
Read →
APT & Nation-State

NightEagle APT (APT-Q-95) GhostContainer Exchange Backdoor + PeckBirdy Casino Infrastructure: OTX Pulse Analysis — Enterprise Detection Pack

NightEagle APT expands GhostContainer Exchange backdoor ops to Russian enterprises via compromised VPN creds; PeckBirdy gambling infrastructure masks espionage. High urgency.

Sep 16, 2026
Read →
APT & Nation-State

GrelosGTM Google Tag Manager Skimmer: Magento Checkout JS Sniffer + WebSocket Exfil Detection Pack

GrelosGTM abuses Google Tag Manager to skim Magento checkout data via JS sniffers/WebSocket exfil; retail in US/EU at risk—hunt and block now.

Sep 15, 2026
Read →
APT & Nation-State

JeetBot Malicious Browser Extension Campaign: Twitch OAuth Token Theft via Russian Proxy Infrastructure — OTX Detection Pack

Malicious 'Twitch Enhanced Viewer | JeetBot' extension exfiltrated OAuth session tokens from 30K+ users to Russian proxies. URGENT: audit extensions, revoke tokens now.

Sep 14, 2026
Read →
APT & Nation-State

Cl0p LEMURLOOT MFT Exploitation + Jewelbug REF7707 Antino Backdoor: OTX Pulse Analysis — Enterprise Detection Pack

OTX pulses detail Cl0p's zero-day MFT ransomware campaigns and Jewelbug/REF7707 dual espionage-fraud ops via Antino backdoor and XG-Web. Govt, defense, telecom at risk. Act now.

Sep 12, 2026
Read →
APT & Nation-State

Midnight Blizzard CaptiveCrunch + LegionLoader ClickFix + Melofee Linux Implant: OTX Pulse Analysis — Enterprise Detection Pack

OTX pulses expose APT29 hotel Wi-Fi M365 credential theft, LegionLoader ClickFix distribution, and Melofee Linux rootkit variants. Immediate hunting advised.

Sep 11, 2026
Read →
APT & Nation-State

GRIMWEDGE Chrome 0-Day Chain, Vwork Work-Profile Evasion & PREY-0058 MFA-Bypass Extortion: OTX Pulse Analysis — Enterprise Detection Pack

Chinese actors chain Chrome/Windows 0-days against NGOs; GoldFactory weaponizes Shelter fork; PREY-0058 runs vishing + AiTM MFA bypass against M365. Hunt now.

Sep 10, 2026
Read →
APT & Nation-State

Aeternum Blockchain C2 Botnet + XWorm/ZingoStealer Loader Chain: OTX Pulse Analysis — Polygon Smart Contract Detection Pack

AlienVault OTX flags Aeternum, a C++ loader using Polygon smart contracts for C2, dropping XWorm, ZingoStealer and XMRig. Immutable blockchain C2 defeats takedowns — hunt RPC egress now.

Sep 9, 2026
Read →
APT & Nation-State

APT37 Ted Backdoor + CL-CRI-1171 PPI Nexus: OTX Pulse Detection Pack — Trojanized Linux Daemons, HAProxy Implants, SEO Poisoning

OTX pulses expose DPRK APT37 Linux trojanized binaries in South Korean media/auto plus CL-CRI-1171 PPI malware hitting gamers, government and energy.

Sep 9, 2026
Read →
APT & Nation-State

BlueMoon Chrome/Windows 0-Day Chain, ClearFake WebDAV Infection & Virtualized Vidar Stealer: OTX Pulse Analysis — Enterprise Detection Pack

OTX pulses reveal APT31/TA412 deploying BlueMoon Chrome+Windows 0-days, ClearFake's WebDAV chain dropping Amatera stealer, and a VM-obfuscated Vidar variant. Enterprise defenders must act now.

Sep 9, 2026
Read →
APT & Nation-State

Kimsuky 'Operation GitPower' Evolves: AI-Generated Decoys, GitHub PAT C2, and LNK-Based PowerShell Loaders — OTX Detection Pack

Kimsuky's Operation GitPower campaign deploys 13 malicious LNK variants using GitHub PATs for C2 and AI-generated decoys. Finance and government targets at risk. Hunt now.

Sep 7, 2026
Read →
APT & Nation-State

BengalSEO MayaBot SEO Poisoning Operation: OTX Pulse Analysis — Enterprise Detection Pack for Search Engine Poisoning & Tech Support Scam Infrastructure

BengalSEO (Rajasthan, India) SEO poisoning operation distributing MayaBot and tech support scam lures since 2015. 524 IOCs published. Block domains, hunt endpoints now.

Sep 7, 2026
Read →
APT & Nation-State

Overlord RAT Fake Zoom macOS Chain + UNC6671 Vishing Extortion: OTX Pulse Detection Pack

Fake Zoom installers drop Overlord/FlexibleFerret on macOS while UNC6671 vishing hits Okta/passkey SSO; urgent identity and endpoint hunt.

Sep 6, 2026
Read →
APT & Nation-State

MacSync Stealer ClickFix Campaign: Fake CAPTCHA Terminal Commands Deploy Crypto-Draining Mach-O Payloads — OTX Pulse Analysis & Detection Pack

MacSync stealer uses ClickFix fake CAPTCHA lures to trick macOS users into running Terminal commands, deploying Go Mach-O payloads that drain crypto wallets and harvest credentials.

Sep 5, 2026
Read →
APT & Nation-State

TA416 Mustang Panda EU Espionage: PlugX/Korplug + TONESHELL/PUBLOAD OTX Detection Pack

TA416/Mustang Panda resumes EU government espionage with PlugX/Korplug, TONESHELL and PUBLOAD; hunt web bugs, Turnstile-gated C2 now.

Sep 4, 2026
Read →
APT & Nation-State

The Gentlemen Ransomware — TukTuk C2 v2.0 & GentleKiller BYOVD EDR Neutralization: OTX Detection Pack

The Gentlemen's TukTuk C2 v2.0 exposed with GentleKiller/EDRKiller BYOVD tooling targeting US defense, healthcare, tech & aerospace. Critical urgency.

Sep 3, 2026
Read →
APT & Nation-State

Woodgnat 'Node.js Resurgence' Campaign: ClickFix → ModeloRAT + EtherHiding C2 — OTX Detection Engineering Pack

Woodgnat actors abuse signed node.exe via ClickFix lures to deploy ModeloRAT, EtherRAT & AsukaStealer against US gov/tech/finance. High urgency — detect now.

Sep 3, 2026
Read →
APT & Nation-State

Teams Helpdesk Impersonation + Node.js MSI Implant: Human-Operated Intrusion Chain — OTX Pulse Analysis & Detection Pack

Threat actors impersonating IT helpdesk via Microsoft Teams are deploying MSI loaders and Node.js implants for enterprise-wide access. Urgent: hunt now.

Sep 3, 2026
Read →
APT & Nation-State

Knight Office AiTM Phishing Kit: M365 Session Token Theft Campaign — OTX Pulse Analysis & Detection Pack

CRITICAL: New 'Knight Office' AiTM phishing kit harvests Microsoft 365 session tokens via DocuSign lures, Monday.com redirects, and .vu C2 domains. Enterprise detection pack inside.

Sep 2, 2026
Read →
APT & Nation-State

Larva-24009 (HeptaX) QuasarRAT LNK Campaign + Knight Office M365 AiTM Phishing Kit: OTX Pulse Analysis & Detection Pack

OTX pulses reveal Larva-24009 phishing delivering QuasarRAT via malicious LNKs, and Knight Office AiTM kit stealing M365 session tokens. High urgency.

Sep 2, 2026
Read →
APT & Nation-State

Mirage Kitten APT Deploys NodeRabbit & PollCat Cross-Platform RATs: OTX Pulse Analysis — Detection & Hunt Pack

Mirage Kitten APT shifts to Node.js/JavaScript RATs (NodeRabbit, PollCat) targeting finance and aerospace via LinkedIn lures. HIGH urgency — hunt now.

Sep 1, 2026
Read →
APT & Nation-State

ValleyRAT Backdoor Disguised as QN Wallpaper Adware: Void Arachne DLL Sideloading Campaign — OTX Detection Pack

Void Arachne spreads ValleyRAT backdoor via fake QN Wallpaper adware using DLL sideloading. Targets China/India. Keylogging, clipboard theft, C2 active. HIGH urgency.

Aug 31, 2026
Read →
APT & Nation-State

Blind Eagle GitHub Loader (AsyncRAT/DcRat/XWorm) + 'Mini Shai-Hulud' npm Supply Chain Attack: OTX Pulse Analysis — Enterprise Detection Pack

OTX pulses expose APT-C-36 (Blind Eagle) GitHub-staged RAT loaders targeting Colombian government, and a 10-version npm supply chain compromise via abused GitHub Actions. Hunt now.

Aug 31, 2026
Read →
APT & Nation-State

QScan + Fast Labyrinth 'Quartermaster' Infrastructure: China-Nexus Cyber Espionage Enablement Network — OTX Pulse Analysis & Detection Pack

OTX pulse exposes a China-nexus 'quartermaster' infrastructure model (QScan, Fast Labyrinth, QTRouter) enabling espionage against US/UK critical infrastructure. Hunt now.

Aug 29, 2026
Read →
APT & Nation-State

The Gentlemen RaaS + China-Nexus 'Quartermaster' Espionage Infrastructure: OTX Pulse Analysis — Enterprise Detection Pack

OTX pulses track The Gentlemen dual-extortion RaaS hitting Windows/Linux/ESXi and a China-nexus quartermaster proxy network targeting US/UK critical infrastructure. High urgency.

Aug 29, 2026
Read →
APT & Nation-State

XenoRAT LNK Campaigns, pepesoft.exe Supply-Chain Implant & Aurora Ransomware Leak: OTX Pulse Analysis — Enterprise Detection Pack

OTX pulses expose Kimsuky XenoRAT LNK phishing, malicious NuGet tools dropping pepesoft.exe host surveillance, and a leaked Aurora ransomware affiliate toolkit. Hunt now.

Aug 28, 2026
Read →
APT & Nation-State

DEV#POPPER npm RAT, Flying Eagle Android Botnet & APT28 Moobot Resurgence: OTX Pulse Analysis — Multi-Platform Detection Pack

OTX pulses reveal npm supply-chain RAT (DEV#POPPER), a 170-server Android RAT ecosystem targeting banking in China/Thailand, and APT28-linked Moobot botnet activity post-2024 takedown. High urgency.

Aug 28, 2026
Read →
APT & Nation-State

Dark Caracal GoCaracal Framework + Tortoiseshell TWOSTROKE Backdoor: Dual APT Campaign OTX Analysis — Enterprise Detection Pack

Two APT campaigns active: Dark Caracal deploying GoCaracal modular spyware across Latin America telecom, and Iranian Tortoiseshell targeting defense/aerospace with TWOSTROKE backdoor and SSH tunneling. Immediate C2 blocking required.

Aug 26, 2026
Read →
APT & Nation-State

AMOS Stealer + XMRig macOS ClickFix Crimekit: EtherHiding C2 on Polygon Blockchain — OTX Detection Pack

macOS ClickFix crimekit uses fake CAPTCHA AppleScript lures to drop AMOS stealer + XMRig miner, hiding C2 in Polygon smart contracts. High urgency for Mac fleets.

Aug 26, 2026
Read →
APT & Nation-State

HookBot & ERMAC Source Leak: Exposed Android Banking Trojan Panels Enable Mass Operator Proliferation — OTX Detection Pack

ERMAC/HookBot builder + backend leaked with default creds intact. Financial sector targeted via overlay attacks. 19 live C2 indicators — hunt now.

Aug 25, 2026
Read →
APT & Nation-State

Vanilla Tempest ClickFix Cluster: Supper Malware + DLL Sideloading via MSI & NodeJS — OTX Detection Pack

Vanilla Tempest ClickFix cluster delivering Supper malware via MSI sideloading & NodeJS. C2 dead drops, DLL sideload IOCs + Sigma/KQL detection rules. High urgency.

Aug 25, 2026
Read →
APT & Nation-State

Cyber Av3ngers IOCONTROL + MALPDB Campaign: Nation-State PLC Exploitation Against U.S. Water & Energy Infrastructure — OTX Detection Pack

IRGC-linked Cyber Av3ngers is actively exploiting internet-exposed PLCs across U.S. water and energy sectors, deploying IOCONTROL malware and abusing valid engineering credentials. Hunt now.

Aug 23, 2026
Read →
APT & Nation-State

JadeProx PlugX/TriBack Campaign, Void Blizzard Zimbra Zero-Click Espionage & Helix SharePoint Extortion: OTX Pulse Analysis — Enterprise Detection Pack

OTX pulses expose China-nexus JadeProx intrusions, Russian Void Blizzard Zimbra zero-click espionage, and Helix vishing-driven SharePoint extortion. Hunt now.

Aug 22, 2026
Read →
APT & Nation-State

Head Mare PhantomCore via TrueConf Supply-Chain Compromise + STARDUST CHOLLIMA Rust Crate Backdoor: OTX Pulse Analysis — Enterprise Detection Pack

Two live supply-chain campaigns: Head Mare APT trojanizing TrueConf conferencing clients with PhantomCore, and DPRK-linked STARDUST CHOLLIMA backdooring Rust crates on crates.io. Hunt now.

Aug 21, 2026
Read →
APT & Nation-State

Offside Wallet Theft Factory: 77 Malicious Firefox Extensions Steal Crypto Wallet Seed Phrases via Supabase & Cloudflare Workers C2 — OTX Pulse Detection Pack

OTX pulse exposes 77 Firefox extensions (40 confirmed malicious) stealing crypto wallet recovery phrases and credentials via Supabase switches and Cloudflare Workers C2. HIGH urgency for Web3-facing orgs.

Aug 20, 2026
Read →

Showing 50 of 279 reports. Archive expands automatically as new intel is generated.

Free Detection Rules Included

Every APT & Nation-State Report Includes SIGMA & KQL Detection Rules

Every intelligence briefing on this page includes at least one Sigma rule, a Microsoft Sentinel KQL hunt query, and an IOC check script — ready to drop into your SIEM. No paywall. No registration.