The Gentlemen Affiliate Deploys EtherRAT Across Windows Networks Using Ethereum Smart Contract C2 2026-08-05 True True Flying Eagle Android RAT: Leaked Source Code, 170 Active Servers, and a New Platform Called Night Dragon 2026-07-29 True True Thailand's Ministry of Finance Targeted With Hermes AI Agent Running Unattended, Hades Implant Staged 2026-07-24 True True Open Directory Stages NGINX Rift and Ghost CMS Exploits Against Government and Finance Across Eleven Countries 2026-07-21 True True Suspected Chinese Operators Use Claude Code and DeepSeek to Breach Government Systems Across Four Countries 2026-07-16 True True Inside Eastern Europe's C2 Sprawl: 3,900+ Servers, 302 Providers, One Host Doing Half the Work 2026-06-25 True True Chinese-speaking Operators Clone FIFA's World Cup 2026 Ticketing Site To Steal Fan Logins and Card Data 2026-06-18 True True Ababil of Minab Exposed: LA Metro SCADA Backups and Israeli Victim Data Left Open on an Iranian Staging Server 2026-06-16 True True PCPJack Hijacked 230 AWS, GCP, and Azure Servers to Run a Hidden SMTP Relay Network 2026-06-04 True True Exposing a Global Smishing Operation Across 19 Countries: Governments, Postal Services, and Telecoms Targeted 2026-05-28 True True Middle East Malicious Infrastructure Report: 1,350+ C2 Servers Mapped Across 98 Providers 2026-05-22 True True How TeamPCP's Python Toolkit Survives a C2 Takedown: FIRESCALE, GitHub, and the Victim's Own Account 2026-05-15 True True CVE-2025-32975: The Open Directory Behind the KACE SMA Breach and 60+ Downstream Victims 2026-05-13 True True Iranian-Nexus Operation Against Oman's Government: 12 Ministries Hit and 26,000 Citizen Records Exposed 2026-05-06 True True xlabs_v1 DDoS-for-Hire Operation Exposed: How an Operator's Debug Build Unraveled a Commercial Game-Server Botnet 2026-04-30 True True DinDoor Backdoor: Deno Runtime Abuse and 20 Active C2 Servers 2026-04-22 True True Exposing Russian Malicious Infrastructure: 1,250+ C2 Servers Mapped Across 165 Providers 2026-04-16 True True Canis C2 Exposed: Previously Undocumented Cross-Platform Surveillance Framework Targeting Japan 2026-04-09 True True Breaking Down the Axios Supply Chain Attack: Dropper, Cross-Platform RATs, and BlueNoroff/TA444 2026-04-02 True True 33K Exposed LiteLLM Deployments and the C2 Servers Behind TeamPCP's Supply Chain Attack 2026-03-28 True True TheGentlemen Ransomware Toolkit Found on Russian Proton66 Server 2026-03-25 True True Iranian Botnet Exposed via Open Directory: 15-Node Relay Network and Active C2 2026-03-18 True True Exposing Lumma Stealerâs Second-Stage Infrastructure and C2 Servers with ASN and JA4X Pivoting 2026-03-12 True True Operation Roundish: Uncovering an APT28 Roundcube Exploitation Toolkit Targeting Ukraine 2026-03-12 True True Iranian APT Infrastructure in Focus: Mapping State-Aligned Clusters During Geopolitical Escalation 2026-03-05 True True The Complete Guide to Hunting Cobalt Strike - Part 4: Operationalizing C2 Feeds with API Automation 2026-03-04 True True Fake Homebrew Pages Deliver Cuckoo Stealer via ClickFix 2026-02-18 True True Russian-Speaking Threat Actor Abuses Cloudflare & Telegram in Phishing Campaign 2026-02-16 True True South Korean Organizations Targeted by Cobalt Strike âCatâ Delivered by a Rust Beacon 2026-02-16 True True 630K gov.br Subdomains Abused in SEO Poisoning Attack 2026-02-16 True True JSPSpy and âfilebroserâ: A Custom File Management Tool in Webshell Infrastructure 2026-02-16 True True Hunt.io Insights: Gamaredonâs Flux-Like Infrastructure and a Look at Recent ShadowPad Activity 2026-02-16 True True Inside the 2025 Energy Phishing Wave: Chevron, Conoco, PBF, Phillips 66 2026-02-16 True True ClickFix Facebook Session Hijacking Campaign Targets Creators at Scale 2026-02-16 True True KeyPlug Server Exposes Fortinet Exploits & Webshell Activity Targeting a Major Japanese Company 2026-02-16 True True Proactive ClickFix Threat Hunting with Hunt.io 2026-02-16 True True Operation SouthNet: SideWinder Targets South Asia Maritime 2026-02-16 True True Server-Side Phishing: How Credential Theft Campaigns Are Hiding in Plain Sight 2026-02-16 True True Detecting IOX, FRP, Rakshasa, and Stowaway Proxies Using Hunt.io 2026-02-16 True True AsyncRAT Campaigns Uncovered: How Attackers Abuse ScreenConnect and Open Directories 2026-02-16 True True From Munitions to Malware: Joseph Harrison on Threat Detection & Digital Forensics 2026-02-16 True True Exposed BYOB C2 Infrastructure Reveals a Multi-Stage Malware Deployment 2026-02-16 True True Rekoobe Backdoor Discovered in Open Directory, Possibly Targeting TradingView Users 2026-02-16 True True Targeting Innovation: Sliver C2 and Ligolo-ng Used in Operation Aimed at Y Combinator 2026-02-16 True True Shared SSH Keys Expose Phishing Infrastructure Targeting Kuwait 2026-02-16 True True Suspected KEYPLUG Infrastructure: TLS Certificates and GhostWolf Links 2026-02-16 True True Tricks, Treats, and Threats: Cobalt Strike & the Goblin Lurking in Plain Sight 2026-02-16 True True Suspected DPRK Phishing Campaign Targets Naver; Separate Apple Domain Spoofing Cluster Identified 2026-02-16 True True Introducing Code Search on AttackCapture: Uncover Exploit Code, Reverse Shells, C2 Configs, and More 2026-02-16 True True XenoRAT Adopts Excel XLL Files and ConfuserEx as Access Method 2026-02-16 True True