APT Activity

State-aligned and financially motivated intrusion sets, their tooling, and the infrastructure they operate — summarized from vendor and government reporting.

Other conventional threat types

Showing 1–17 of 17 threats, newest first

ownCloudCISA-KEVCVE-2023-49105pre-authenticationwebdavchina-nexuscritical-infrastructurenuclear-sectordata-theft

A critical pre-authentication vulnerability in ownCloud (CVE-2023-49105, CVSS 9.8) was actively exploited by a suspected Chinese-speaking threat actor to breach a nuclear research institute in the Philippines and exfiltrate sensitive records. CISA has added the flaw to its Known Exploited Vulnerabilities catalog, confirming active in-the-wild exploitation and prompting mandated remediation for federal agencies.

Updated Aug 30, 2026 · CVSS 9.8

IranIRGCnation-stateespionagebackdoorSSH-tunnelingNimbus ManticoreAPT

Nimbus Manticore, an Iranian state-sponsored APT group affiliated with the IRGC, has expanded its toolset with a new TWOSTROKE-like backdoor and an SSH tunneling utility, according to Group-IB research. The group is characterized as one of the most active Iranian threat actors in 2026, conducting cyber espionage operations using newly discovered infrastructure and malware.

Updated Aug 27, 2026

chinastate-sponsoredcritical-infrastructurenetwork-reconnaissancerouter-exploitationbotnetfbi-disruptionQTFY

The U.S. DoJ and FBI disrupted infrastructure operated by China-linked threat actor QTFY, tied to Nanjing Xinjiuwei Network Technology Company, which used two custom hacking platforms—QScan and QTRouter—to target U.S. critical infrastructure and sensitive networks. The takedown highlights ongoing state-sponsored efforts to compromise network edge devices for espionage and data theft purposes.

Updated Aug 27, 2026

iransanctionscritical-infrastructurestate-sponsoredtreasurygeopolitical

The U.S. Department of the Treasury has imposed new sanctions on Iranian cyber actors linked to breaches of critical infrastructure, as part of a broader economic pressure campaign against Iran. This is a policy and enforcement action rather than a newly disclosed technical vulnerability, though it signals continued Iranian state-sponsored targeting of critical infrastructure sectors.

Updated Aug 26, 2026

phishingoauth-abusecredential-theftsocial-engineeringrussiastate-sponsoredaccount-takeoverwhatsappgoogle-oauth

Three suspected Russian cyber espionage clusters (UNC6293, UNC7005, UNC5976) are abusing legitimate Google OAuth flows and WhatsApp device-linking features to hijack accounts of individuals in academia, aerospace/defense, government, and think tanks across Europe and the U.S. These campaigns rely on persistent, adaptive social engineering rather than exploiting software vulnerabilities, making them difficult to detect with traditional malware defenses.

Updated Aug 21, 2026

espionageAPTRATCentral Asiagovernmentnation-state

SilkParasite is a newly identified cyber espionage operation targeting government bodies in Central Asia, first observed in late 2025. The campaign leverages seven distinct RAT families, five of which are previously undocumented, indicating a well-resourced threat actor with custom malware development capabilities.

Updated Aug 20, 2026

spywaremercenary-spywaremobile-securityiosnation-statesurveillancetargeted-attack

Apple has issued new 'Threat Notification' alerts warning select iPhone users that they have been targeted by mercenary spyware attacks. These notifications, part of Apple's ongoing threat intelligence program, indicate highly targeted, sophisticated attacks typically associated with commercial spyware vendors like NSO Group or Intellexa rather than broad-based malware campaigns.

Updated Aug 14, 2026

SandwormAPTRussiatrojanized-softwareVPNsocial-engineeringjob-lurecredential-theftIT-professionalsagent-relevant

The Russian state-linked threat group Sandworm is targeting system administrators and IT professionals with fake job offers designed to lure victims into installing a trojanized WireGuard VPN client. The campaign, active since at least May 2026, aims to compromise privileged accounts and gain persistent access to enterprise networks through social engineering and malicious software.

Updated Aug 12, 2026

APT29Midnight BlizzardhospitalityWi-FiMicrosoft 365credential-theftRussianation-stateagent-relevant

Microsoft has attributed a global campaign against hospitality Wi-Fi networks to the Russian state-sponsored actor Midnight Blizzard (APT29). The group uses custom malware deployed via compromised hotel networks to intercept traffic and steal Microsoft 365 credentials from traveling targets, likely diplomats, government officials, and corporate executives. The campaign highlights the ongoing risk of adversary-in-the-middle attacks on untrusted public networks.

Updated Aug 4, 2026

captive-portal-hijackfake-updateRATsurveillance-malwareMidnight-BlizzardStorm-2945hospitalitynation-statecredential-theftagent-relevant

Microsoft has identified a campaign, tracked as CaptiveCrunch, in which threat actors hijack hotel Wi-Fi captive portals to serve fake browser update prompts. Victims who install the fake update are infected with CornFlake, a remote access trojan capable of capturing webcam images, microphone audio, and keystrokes. The activity is attributed to Storm-2945, assessed as an operational sub-cluster of the Russian state-sponsored group Midnight Blizzard (APT29).

Updated Aug 3, 2026

APTChina-nexusCentral-Asiagovernmentespionagemalwarebackdoor

A suspected Chinese-speaking threat actor has been conducting an espionage campaign since January 2025, primarily targeting government organizations in Central Asia and Afghanistan, as well as Syria. The campaign employs two custom malware families, OctLurk and SilkLurk, to establish persistent access for likely intelligence collection purposes.

Updated Aug 1, 2026

espionagemicrosoft-365c2-over-saasgraph-api-abuseliving-off-trusted-servicesdata-exfiltrationagent-relevant

Group-IB has identified an espionage implant dubbed HollowGraph that abuses Microsoft 365 calendar events, dated far in the future (2050), to relay operator instructions and exfiltrate stolen files as event attachments. By routing tasking and data theft through legitimate Microsoft Graph API traffic, the malware blends into normal enterprise activity and evades traditional network-based detection.

Updated Jul 21, 2026

state-sponsoredrussiafsbrouter-hygienesnmp-abusenetwork-devicescritical-infrastructureciscosmart-installcredential-theftproxy-infrastructure

Russian FSB Center 16 (aka Berserk Bear, Energetic Bear, Crouching Yeti, Dragonfly, Ghost Blizzard, Static Tundra) is conducting a long-running, opportunistic global campaign exploiting poorly configured and vulnerable networking devices, primarily routers, using SNMP abuse and known Cisco CVEs. Targeting spans critical infrastructure sectors including communications, energy, financial services, defense industrial base, government, and healthcare. A joint advisory from CISA, NSA, FBI, and 15 international partner agencies urges organizations to harden router/SNMP configurations and disable legacy protocols.

Updated Jul 14, 2026

cyber-espionagegovernmentlaw-enforcementsouth-asiachina-nexusindia-nexusweb-application-compromisedata-breachcritical-infrastructure

Suspected China- and India-aligned APT groups conducted a sustained, multi-year cyber espionage campaign (February 2024 to April 2026) against Pakistani law enforcement organizations, including the Balochistan Police. Attackers compromised servers hosting public-facing web applications used to manage sensitive police and citizen data, including criminal records.

Updated Jul 12, 2026

china-nexusORB-networkrouter-compromiseedge-device-exploitationbotnetstate-sponsored

Chinese state-linked threat actor UAT-7810 is deploying new malware dubbed LONGLEASH to expand an Operational Relay Box (ORB) network, primarily by compromising unpatched internet-facing Ruckus routers. The ORB network is used to anonymize and relay malicious traffic, complicating attribution and enabling downstream intrusion campaigns.

Updated Jul 8, 2026

irannation-statec2-frameworkmoisisraelgovernmentit-sectorcheck-point-research

A threat cluster linked to Iran's Ministry of Intelligence and Security (MOIS) has been observed using a previously undocumented modular command-and-control framework called Cavern (Cav3rn) to target Israeli IT providers and government organizations. Check Point Research attributes the activity to a state-sponsored espionage campaign aimed at establishing persistent access within high-value networks. The framework's modular design suggests ongoing development and long-term operational use by the threat actor.

Updated Jul 7, 2026

APTState-SponsoredCritical Infrastructure

Chinese state-sponsored group maintaining persistent access in US energy, water, and telecom networks using living-off-the-land techniques that blend with normal admin activity.

Updated Jul 3, 2026