Skip to main content

Threat Intelligence

Threat actor activity and indicators

Rows of equipment and monitors line the walls of a network operations center, with technicians working in the background.

Novel Chinese Spy Group Infiltrates Critical Networks in Poland, Asia

A recent investigation by TrendAI has uncovered a concerning China-linked espionage campaign, with a novel spy group infiltrating over a dozen critical networks across Poland and Asia, leaving behind a lingering threat that's experts' biggest worry. The threat group, tracked as Shadow-Earth-053, has been actively compromising networks since December 2024.

Analyst 207
Law enforcement officials gather outside a government building with daylight streaming through tall windows.

US Charges Scattered Spider Hacker with Extortion, Cyber Intrusion

A 19-year-old hacker, known online as "Bouquet," has been arrested in Finland and charged in the US with extortion and cyber intrusion as a key player in the notorious Scattered Spider hacking collective. The dual US and Estonian citizen was caught at Helsinki airport while trying to flee to Japan.

Analyst 207
People work on computers in a dimly lit internet cafe or office surrounded by networking equipment.

Threat Actors Formalize Operational Security Playbook

Cybercrime players are now treating operational security as a sophisticated game-changer, and it's time for you to level up your security strategy beyond just using VPNs. A battle-tested three-tier infrastructure model has emerged, separating exposure, execution, and monetization to safeguard high-stakes operations.

Analyst 207
Person walks into a courtroom with a blurred government seal in the background.

China Hacker Extradited Over Silk Typhoon Cyber Attacks

In a major breakthrough, 34-year-old Chinese national Xu Zewei has been extradited to the US to face charges for his alleged role in the massive Silk Typhoon cyber attacks that hit over 12,700 US organizations. Xu appeared in a Houston federal court over the weekend, facing serious charges including wire fraud, unauthorized computer access, and identity theft.

Analyst 207
Formal government setting with podium and judicial backdrop, lit by daylight and abstract shapes.

US Charges Chinese National in Silk Typhoon Cyber Attacks

A Chinese national, Xu Zewei, has been extradited to the US from Italy to face charges for his alleged role in the notorious HAFNIUM cyber attacks, a vast intrusion campaign that compromised over 12,700 US organizations. Xu's arrival in US court marks a significant step in holding him accountable for his actions.

Analyst 207
US Department of Justice officials gather in a government building to address a cyberespionage case.

US Charges Chinese Hacker in Cyberespionage Case

The US Department of Justice has extradited Chinese national Xu Zewei from Italy to face charges of conducting cyberespionage operations on behalf of China's intelligence services, targeting victims including COVID-19 researchers. Xu's alleged hacking activities, directed by China's Ministry of State Security, spanned over a year, from February 2020 to June 2021.

Analyst 207
Busy airport terminal in Central or South America with laptop on luggage cart.

TGR-STA-1030 Intensifies Espionage Push in Central, South America

The threat group TGR-STA-1030 is ramping up its espionage efforts in Central and South America, with sustained and widespread activity observed across multiple countries since February. This persistent campaign has recently intensified, with a heavy focus on regions within Central and South America.

Analyst 207
Modern lab setting with computer workstation and subtle industrial background.

US Warns of Coordinated AI Model Extraction Campaigns by Foreign Adversaries

The US government has sounded the alarm on a critical threat: foreign adversaries are launching coordinated, large-scale campaigns to steal American AI capabilities, specifically targeting the distillation of advanced US AI models into smaller, lighter-weight versions. To combat this, the White House is directing federal agencies to collaborate with the private sector to develop best practices for protection.

Analyst 207
Cluttered server room with stacked routers, cables, and wires in dim light.

China Builds Covert Hacker Networks with Compromised Routers

China-nexus cyber actors have dramatically changed their game, ditching solo operations for massive networks of hacked devices - and it's a threat you need to know about. A joint advisory from top cyber agencies worldwide warns of this new tactic, urging vigilance in the face of large-scale cyber attacks.

Analyst 207
A router on a rack in a network closet with multiple cables connected.

China-Linked Hackers Exploit Global Infrastructure in Covert Network Attacks

Be on high alert: China-linked hackers are secretly building global covert networks using compromised routers and devices, putting anyone who's a target at risk of devastating cyber attacks and data theft. This sinister plot, revealed by a joint advisory from 16 government agencies worldwide, has far-reaching implications for organizations and individuals alike.

Analyst 207
Interconnected devices in a dimly lit server room with daylight visible through tall windows.

UK Warns of Chinese Hackers' Proxy Network Tactics to Evade Detection

The UK's National Cyber Security Centre has warned that Chinese hacking groups are using a sophisticated network of proxies to evade detection, with multiple covert networks constantly being updated and used by multiple threat actors. This alarming shift in tactics has prompted a coordinated warning from the NCSC-UK and nine international partners.

Analyst 207
Modern office setting with subtle digital communication hints.

China-Linked APT Group Exploits Legitimate Services for Covert Ops

ESET researchers have uncovered a treasure trove of clues, analyzing 6,044 Slack messages and 3,005 Discord messages that reveal the covert operations of a China-linked APT group, dubbed GopherWhisper, which has been active since at least 2023. The recovered logs provide a rare glimpse into the group's tactics, thanks to hardcoded credentials in Go-based backdoors that gave investigators access to the group's command and control channels.

Analyst 207
Threat intelligence analyst's workstation with multiple screens displaying data visualizations and system monitoring tools.

AI-Driven Cyberthreats Expose Need for Advanced Threat Intelligence

In today's hyper-fast cyber threat landscape, operating at machine speed is no longer a choice - it's a necessity, as expert Tom Kellermann warns, highlighting the urgent need for advanced threat intelligence to combat AI-driven attacks.

Analyst 207
Security analyst working at desk with multiple screens displaying code and scans, surrounded by notes and coffee cups.

CISOs Face New Era of AI-Driven Threats

The old security measures are no longer enough - a 'passed' audit only tells you where you've been, not where you are now, in a threat landscape rapidly changed by AI-driven attacks. Advanced AI tools can now discover and exploit weaknesses at unprecedented speeds and scales, outpacing traditional security methods.

Analyst 207
Cluttered server room with laptops, smartphones, and tangled cables, hint of a global map in the background.

Researchers Expose ProxySmart Software Behind Global SIM Farms

Meet ProxySmart, a sneaky software powering "SIM Farm as a Service" operations worldwide, with a massive footprint of 94 phone farms across 17 countries and 19 US states. Its creators, a Belarus-based vendor, have made it easy for operators to run mobile proxy infrastructure at commercial scale.

Analyst 207
Young British man in his mid-twenties sits somberly in a formal setting surrounded by law enforcement officials.

Scotland Hacker Pleads Guilty in Scattered Spider Cybercrime Case

Meet Tyler Robert Buchanan, the 24-year-old mastermind behind the notorious Scattered Spider cybercrime gang, who has pleaded guilty to federal charges of conspiracy and identity theft. With a potential 22-year prison sentence looming, Buchanan's guilty plea marks a major win for law enforcement in the fight against cybercrime.

Analyst 207
Shadowy figure in a hoodie surrounded by devices in a dimly lit office space with blurred coworkers in the background.

AI-Driven Threats Target Hybrid Workplaces with New Sophistication

As the modern workplace becomes increasingly decentralized, organizations face a daunting challenge: protecting their dispersed workforce from sophisticated threats powered by artificial intelligence. Fresh thinking is needed to secure hybrid work environments from these emerging AI-driven threats.

Analyst 207
Helpdesk worker surrounded by screens with a masked figure lurking in shadows.

Microsoft Teams Targeted in Rising Helpdesk Impersonation Attacks

Microsoft is sounding the alarm on a growing threat: hackers are exploiting Microsoft Teams' external collaboration features to impersonate helpdesk teams and gain access to enterprise networks. They're using the platform's own tools to move undetected, posing a major challenge for defenders.

Analyst 207
A lone figure in a hoodie sits in shadows, face obscured, intensely focused on a laptop displaying lines of code amidst…

Iran-Backed Hackers Intensify US Infrastructure Cyberattacks

Pro-Iran hackers are stepping up their game, targeting US infrastructure with increasing frequency, as seen in the recent breach of the Los Angeles Metro. The federal government is sounding the alarm, warning that critical systems remain vulnerable to these escalating cyberattacks.

Analyst 207
Person in hoodie sits before laptop with eerie glow, surrounded by cables, with cityscape and Iranian flag in background.

Iran's Cyber Threat Landscape Intensifies

Iran's cyber threat landscape is escalating, with phishing, hacktivist operations, and criminal activity converging to create a complex risk picture. A recent Unit 42 threat brief offers valuable insights and practical guidance to help defenders stay ahead of these emerging threats.

Analyst 207
Severed laptop cord wrapped around a globe with scattered papers and a smartphone near a cracked windowpane overlooking a…

US Seizes Control of North Korea's Fake Remote Worker Scam Network

Imagine a network of seemingly ordinary remote workers secretly infiltrating over 100 companies - only to discover they were all part of a massive scam run by North Korea. Two Americans have been jailed for helping the rogue nation pull off this daring cyber deception.

Analyst 207
Dark cityscape with a lone figure before a cracked, eerie blue digital wall and a shattered smartphone on wet pavement.

Zero-Day Exploits Multiply as Hacker Creativity Surges

Feeling overwhelmed by the endless stream of cybersecurity threats? Every Thursday morning, you're faced with a daunting question: how to stay informed without getting bogged down by a never-ending parade of old and new threats.

Analyst 207
Dark cityscape with shattered phone and laptop displaying code amidst ominous shadows.

Iranian Operative Behind L.A. Metro Cyberattack

New intelligence suggests a pro-Iranian operative is behind the L.A. Metro cyberattack, shifting the focus from the disruption caused to the motivations and strategic intentions of the attacker. This development elevates the incident from a local service outage to a complex geopolitical issue.

Analyst 207
Dark command center with screens displaying ominous code, a lone hooded figure in shadows amidst cables and wires.

US and UK Cyber Leaders Scramble to Contain Claude Mythos Threat

As a new AI tool, Claude Mythos, raises red flags with its potential to aid hacking, US and UK cyber leaders are scrambling to contain the threat and reassess their cybersecurity strategies. This emerging concern marks a new front in AI and cybersecurity, where commercially available models are now viewed as a potential operational risk.

Analyst 207