PROBABLYPWNED
TID

Threat Intel Desk

Threat Intelligence

The Threat Intel Desk covers nation-state actors, APT campaigns, and the geopolitics of cyber conflict. Reporting is built from primary sources — CISA advisories, vendor threat research, and government attribution — and reviewed by ProbablyPwned editors before publication.

APT trackingattribution analysisnation-state campaignsthreat actor TTPs

Articles from the Threat Intel Desk(171)

Iran-Linked Handala Claims Breach of California Water Utility
Threat Intelligence4 min read

Iran-Linked Handala Claims Breach of California Water Utility

Handala threat group claims to have compromised California Water Service, publishing 5GB of customer data. Security experts assess the group reached billing systems and GPS servers but likely cannot disrupt water operations.

Threat Intel DeskJun 14, 2026
Phantom Taurus: Chinese APT Deploys NET-STAR Malware Suite
Threat Intelligence4 min read

Phantom Taurus: Chinese APT Deploys NET-STAR Malware Suite

Unit 42 exposes Phantom Taurus, a China-aligned APT targeting governments and telecoms across Africa, the Middle East, and Asia with custom NET-STAR backdoors for IIS servers.

Threat Intel DeskJun 6, 2026
SideCopy Targets Afghanistan's Finance Ministry With XenoRAT
Threat Intelligence4 min read

SideCopy Targets Afghanistan's Finance Ministry With XenoRAT

Operation XENOFISCAL delivers customized XenoRAT to Afghanistan's Ministry of Finance and 34 provincial revenue directorates. The Pakistan-linked APT used Pashto-language lures and bulletproof European hosting.

Threat Intel DeskMay 31, 2026
GREYVIBE APT Uses ChatGPT and Gemini to Target Ukraine
Threat Intelligence4 min read

GREYVIBE APT Uses ChatGPT and Gemini to Target Ukraine

Russian-linked GREYVIBE threat actor deploys AI-generated malware including PhantomRelay and LegionRelay against Ukrainian military and government targets. WithSecure analysis reveals the group's OPSEC failures.

Threat Intel DeskMay 30, 2026
FBI: Extortion Gang Walks Into Law Firms Posing as IT Staff
Threat Intelligence4 min read

FBI: Extortion Gang Walks Into Law Firms Posing as IT Staff

Silent Ransom Group escalates from vishing to physical infiltration. FBI FLASH alert warns 38+ law firms already breached, with operatives plugging USB drives into office computers.

Threat Intel DeskMay 28, 2026
FBI Warns Kali365 PhaaS Steals Microsoft 365 Tokens at Scale
Threat Intelligence4 min read

FBI Warns Kali365 PhaaS Steals Microsoft 365 Tokens at Scale

New phishing-as-a-service platform bypasses MFA via OAuth device code flow. FBI PSA details how Kali365's AI-generated lures and $250/month pricing are enabling widespread credential theft.

Threat Intel DeskMay 24, 2026
DBIR 2026: Vulnerability Exploitation Now the Top Breach Cause
Threat Intelligence4 min read

DBIR 2026: Vulnerability Exploitation Now the Top Breach Cause

Verizon's 2026 Data Breach Investigations Report reveals vulnerability exploitation surpassed credential theft as the leading breach vector for the first time in 19 years. Only 26% of KEV flaws get patched.

Threat Intel DeskMay 20, 2026
Microsoft Dismantles Fox Tempest Malware-Signing Operation
Threat Intelligence3 min read

Microsoft Dismantles Fox Tempest Malware-Signing Operation

Microsoft's Digital Crimes Unit seizes infrastructure behind Fox Tempest, a malware-signing service that helped Rhysida, Akira, and Qilin ransomware gangs disguise malicious code as legitimate software.

Threat Intel DeskMay 20, 2026
Turla's Kazuar Backdoor Evolves Into Modular P2P Botnet
Threat Intelligence4 min read

Turla's Kazuar Backdoor Evolves Into Modular P2P Botnet

Microsoft exposes how Russia's FSB-linked Secret Blizzard transformed Kazuar from a monolithic backdoor into a three-module P2P botnet with advanced anti-detection capabilities.

Threat Intel DeskMay 16, 2026
Google Catches First AI-Generated Zero-Day Exploit in the Wild
Threat Intelligence4 min read

Google Catches First AI-Generated Zero-Day Exploit in the Wild

Google's Threat Intelligence Group identifies a criminal group using an LLM-generated exploit to bypass 2FA in a web admin tool—marking the first confirmed AI-built zero-day in active use.

Threat Intel DeskMay 11, 2026
FEMITBOT Scam Uses Telegram Mini Apps to Push Crypto Fraud
Threat Intelligence4 min read

FEMITBOT Scam Uses Telegram Mini Apps to Push Crypto Fraud

CTM360 exposes FEMITBOT, a large-scale fraud operation abusing Telegram Mini Apps to run crypto scams, impersonate brands like Apple and NVIDIA, and distribute Android malware.

Threat Intel DeskMay 4, 2026
APT28's PRISMEX Malware Targets NATO Supply Chains
Threat Intelligence4 min read

APT28's PRISMEX Malware Targets NATO Supply Chains

Russian military hackers deployed PRISMEX steganography malware against Ukraine and NATO logistics networks, exploiting zero-days CVE-2026-21509 and CVE-2026-21513 weeks before patches.

Threat Intel DeskApr 30, 2026
APT37 Exploits Facebook Friendships to Deploy RokRAT
Threat Intelligence4 min read

APT37 Exploits Facebook Friendships to Deploy RokRAT

North Korean threat actors are befriending targets on Facebook, building trust over weeks, then delivering RokRAT malware through trojanized PDF readers. Military and government officials targeted.

Threat Intel DeskApr 29, 2026
Silk Typhoon Hacker Extradited to U.S. for COVID Vaccine Theft
Threat Intelligence4 min read

Silk Typhoon Hacker Extradited to U.S. for COVID Vaccine Theft

Chinese national Xu Zewei faces nine federal counts after extradition from Italy for alleged role in Silk Typhoon attacks stealing COVID-19 vaccine research from U.S. universities and research institutions.

Threat Intel DeskApr 28, 2026
PhantomCore Exploits TrueConf Flaws to Breach Russian Networks
Threat Intelligence4 min read

PhantomCore Exploits TrueConf Flaws to Breach Russian Networks

Pro-Ukrainian hacktivist group PhantomCore chains three TrueConf vulnerabilities including CVSS 9.8 command injection to infiltrate Russian government and private organizations since September 2025.

Threat Intel DeskApr 27, 2026
UAC-0247 Targets Ukrainian Hospitals With Data-Theft Malware
Threat Intelligence4 min read

UAC-0247 Targets Ukrainian Hospitals With Data-Theft Malware

CERT-UA warns of ongoing campaign hitting Ukrainian clinics and government agencies with AGINGFLY backdoor. Attackers steal browser credentials, WhatsApp data, and deploy cryptominers.

Threat Intel DeskApr 17, 2026
FBI: Cybercrime Losses Hit $20.9B in 2025, Up 26%
Threat Intelligence4 min read

FBI: Cybercrime Losses Hit $20.9B in 2025, Up 26%

FBI IC3 2025 report reveals record $20.9 billion in cybercrime losses. Investment fraud tops $8.6B, cryptocurrency scams reach $11.4B, and ransomware losses surge 259%.

Threat Intel DeskApr 13, 2026
Storm-2755 Steals Canadian Paychecks via SEO Poisoning
Threat Intelligence4 min read

Storm-2755 Steals Canadian Paychecks via SEO Poisoning

Microsoft tracks Storm-2755 'Payroll Pirate' using poisoned search results and AiTM phishing to hijack Canadian employee direct deposits. HR systems compromised.

Threat Intel DeskApr 12, 2026
FBI, CISA Warn Iran Is Attacking US Water and Energy PLCs
Threat Intelligence5 min read

FBI, CISA Warn Iran Is Attacking US Water and Energy PLCs

Joint advisory AA26-097A details Iranian APT targeting Rockwell Allen-Bradley controllers across critical infrastructure. Attacks caused operational disruptions since March 2026.

Threat Intel DeskApr 8, 2026
Iran-Linked Hackers Spray 300+ Israeli M365 Tenants
Threat Intelligence4 min read

Iran-Linked Hackers Spray 300+ Israeli M365 Tenants

Check Point tracks an Iran-nexus campaign targeting Microsoft 365 accounts across 300+ Israeli organizations and 25+ UAE entities. Attackers use Tor exit nodes and Israeli VPNs to evade detection.

Threat Intel DeskApr 7, 2026
Storm-1175 Deploys Medusa Ransomware Within 24 Hours of Access
Threat Intelligence4 min read

Storm-1175 Deploys Medusa Ransomware Within 24 Hours of Access

Microsoft links China-based Storm-1175 to high-velocity Medusa ransomware attacks exploiting zero-day vulnerabilities. Healthcare, education, and finance sectors hit across Australia, UK, and US.

Threat Intel DeskApr 7, 2026
Phantom Taurus Deploys Net-Star Backdoors Across Africa
Threat Intelligence3 min read

Phantom Taurus Deploys Net-Star Backdoors Across Africa

Unit 42 exposes Phantom Taurus, a Chinese APT targeting embassies and foreign ministries with fileless NET-STAR malware. The group resurfaces within hours after discovery.

Threat Intel DeskApr 4, 2026
North Korea Uses GitHub as C2 in South Korea Attacks
Threat Intelligence4 min read

North Korea Uses GitHub as C2 in South Korea Attacks

FortiGuard Labs exposes DPRK campaign using LNK files and GitHub repositories for command-and-control against South Korean targets. 22 evasion techniques identified.

Threat Intel DeskApr 3, 2026
Iranian APT Deploys Fake RedAlert App to Surveil Israeli Users
Threat Intelligence3 min read

Iranian APT Deploys Fake RedAlert App to Surveil Israeli Users

Unit 42 uncovers phishing campaign distributing trojanized Israeli civil defense app. Malicious APK harvests location data, contacts, and messages from Android devices amid regional tensions.

Threat Intel DeskMar 23, 2026
APT28 Uses BEARDSHELL and COVENANT to Spy on Ukraine
Threat Intelligence4 min read

APT28 Uses BEARDSHELL and COVENANT to Spy on Ukraine

Russian GRU-linked APT28 deploys BEARDSHELL and COVENANT implants for long-term surveillance of Ukrainian military personnel. ESET research reveals cloud storage abuse for C2.

Threat Intel DeskMar 10, 2026
FBI Investigating Hack of Wiretap Surveillance System
Threat Intelligence4 min read

FBI Investigating Hack of Wiretap Surveillance System

The FBI confirms a sophisticated cyberattack targeted its internal wiretap and FISA warrant management system. Investigation ongoing with CISA and NSA involvement.

Threat Intel DeskMar 7, 2026
APT28 Linked to MSHTML Zero-Day Exploited Before Patch
Threat Intelligence4 min read

APT28 Linked to MSHTML Zero-Day Exploited Before Patch

Security researchers tie Russia's APT28 to CVE-2026-21513 exploitation using malicious LNK files. The MSHTML zero-day was weaponized weeks before Microsoft's February patch.

Threat Intel DeskMar 3, 2026
UnsolicitedBooker APT Targets Central Asian Telecoms
Threat Intelligence4 min read

UnsolicitedBooker APT Targets Central Asian Telecoms

China-aligned threat group deploys LuciDoor and MarsSnake backdoors against telecom providers in Kyrgyzstan and Tajikistan, expanding from prior Saudi operations.

Threat Intel DeskMar 1, 2026
APT37 Ruby Jumper Campaign Targets Air-Gapped Networks
Threat Intelligence4 min read

APT37 Ruby Jumper Campaign Targets Air-Gapped Networks

North Korean APT37 deploys six new malware tools to breach air-gapped systems using USB drives and cloud C2. Zscaler reveals RESTLEAF, THUMBSBD, and FOOTWINE surveillance capabilities.

Threat Intel DeskFeb 27, 2026
LAPSUS$ Supergroup Paying Women $1,000 Per Vishing Call
Threat Intelligence4 min read

LAPSUS$ Supergroup Paying Women $1,000 Per Vishing Call

Scattered Lapsus$ Hunters offers $500-$1,000 to recruit women for IT help desk social engineering attacks. The supergroup combines LAPSUS$, Scattered Spider, and ShinyHunters tactics.

Threat Intel DeskFeb 26, 2026
MuddyWater Deploys GhostFetch and Telegram-Based Backdoors
Threat Intelligence3 min read

MuddyWater Deploys GhostFetch and Telegram-Based Backdoors

Iranian APT MuddyWater launches Operation Olalampo against MENA organizations, deploying four new malware families including GhostFetch and CHAR, a Rust backdoor controlled via Telegram.

Threat Intel DeskFeb 23, 2026
AI-Assisted Attacker Compromises 600+ FortiGate Firewalls
Threat Intelligence4 min read

AI-Assisted Attacker Compromises 600+ FortiGate Firewalls

Amazon threat intelligence exposes Russian-speaking actor using generative AI to breach 600+ FortiGate devices across 55 countries. Attack used ARXON tool with DeepSeek and Claude.

Threat Intel DeskFeb 22, 2026
Dell Zero-Day Exploited by Chinese Hackers Since 2024
Threat Intelligence5 min read

Dell Zero-Day Exploited by Chinese Hackers Since 2024

Chinese threat group UNC6201 exploited a critical hardcoded credential flaw (CVE-2026-22769) in Dell RecoverPoint for 18 months before disclosure. Patch now.

Threat Intel DeskFeb 18, 2026
China's UNC3886 Breached All Four Singapore Telcos
Threat Intelligence3 min read

China's UNC3886 Breached All Four Singapore Telcos

Singapore confirms China-linked APT compromised M1, Singtel, StarHub, and SIMBA using zero-day exploits and rootkits. 11-month Operation Cyber Guardian response disclosed.

Threat Intel DeskFeb 14, 2026
AI Knowledge Graphs Transform APT Threat Intelligence
Threat Intelligence4 min read

AI Knowledge Graphs Transform APT Threat Intelligence

SANS researchers demonstrate how open-source AI tools extract actionable relationships from unstructured threat reports, mapping GRU and APT28 TTPs in interactive visualizations.

Threat Intel DeskFeb 13, 2026
State Hackers Weaponize Gemini AI Across Attack Lifecycle
Threat Intelligence5 min read

State Hackers Weaponize Gemini AI Across Attack Lifecycle

Google's threat intelligence reveals APT groups from China, Iran, North Korea, and Russia using Gemini for recon, malware development, and phishing. Two AI-powered malware families discovered.

Threat Intel DeskFeb 12, 2026
North Korea Uses Deepfake Zoom Calls in Crypto Heists
Threat Intelligence4 min read

North Korea Uses Deepfake Zoom Calls in Crypto Heists

Google Mandiant exposes UNC1069's use of AI-generated deepfake video, compromised executive accounts, and ClickFix attacks to deploy macOS malware against cryptocurrency firms.

Threat Intel DeskFeb 12, 2026
Germany Warns of Signal Phishing Targeting Officials
Threat Intelligence4 min read

Germany Warns of Signal Phishing Targeting Officials

Germany's BfV and BSI issued a joint advisory warning of state-sponsored phishing campaigns targeting politicians, military officials, and journalists through Signal's device linking feature.

Threat Intel DeskFeb 12, 2026
Broken Phishing URLs Are Bypassing Your Filters
Threat Intelligence5 min read

Broken Phishing URLs Are Bypassing Your Filters

SANS ISC handler Xavier Mertens documents phishing campaigns using malformed URL parameters to evade regex detection, URL normalization, and IOC extraction.

Threat Intel DeskFeb 5, 2026
APT28 Weaponized Office Zero-Day in Three Days Flat
Threat Intelligence3 min read

APT28 Weaponized Office Zero-Day in Three Days Flat

Operation Neusploit saw Russia's APT28 exploit CVE-2026-21509 against 60+ Ukrainian targets within 72 hours of Microsoft's disclosure, delivering MiniDoor and BEARDSHELL backdoors.

Threat Intel DeskFeb 5, 2026
RedKitten Malware Targets Iranian Protest Documenters
Threat Intelligence3 min read

RedKitten Malware Targets Iranian Protest Documenters

French researchers uncover SloppyMIO, an AI-assisted malware campaign using fabricated victim lists to target individuals documenting human rights abuses during Iranian protests.

Threat Intel DeskJan 31, 2026
Google Dismantles IPIDEA Proxy Network Used by 550+ APTs
Threat Intelligence4 min read

Google Dismantles IPIDEA Proxy Network Used by 550+ APTs

Google Threat Intelligence Group disrupts one of the world's largest residential proxy networks, cutting off infrastructure used by nation-state actors from China, Russia, Iran, and North Korea.

Threat Intel DeskJan 31, 2026
Phishers Hide Behind Google Slides Publish Feature
Threat Intelligence5 min read

Phishers Hide Behind Google Slides Publish Feature

Attackers exploit Google Presentations' publish mode to host phishing pages that bypass Google's own security warnings, targeting Vivaldi Webmail users.

Threat Intel DeskJan 30, 2026
Chinese APT Used VMware ESXi Zero-Days to Escape VMs
Threat Intelligence4 min read

Chinese APT Used VMware ESXi Zero-Days to Escape VMs

Huntress researchers discover 'MAESTRO' toolkit exploiting three VMware vulnerabilities. Attackers chained SonicWall VPN access with hypervisor escape to deploy persistent backdoors.

Threat Intel DeskJan 13, 2026
CISA Closes 10 Emergency Directives in Historic Shift
Threat Intelligence4 min read

CISA Closes 10 Emergency Directives in Historic Shift

The agency retired directives spanning SolarWinds to Microsoft Exchange in the largest bulk closure ever. KEV catalog now handles most vulnerability mandates.

Threat Intel DeskJan 11, 2026
Ransomware Groups to Watch in 2025-2026
Threat Intelligence5 min read

Ransomware Groups to Watch in 2025-2026

Qilin has hit 1,000+ victims. Everest targets critical infrastructure. Here's what security teams need to know about today's most active ransomware operations.

Threat Intel DeskJan 10, 2026
North Korea's Cyber Army: A Lazarus Group Profile
Threat Intelligence5 min read

North Korea's Cyber Army: A Lazarus Group Profile

DPRK hackers stole $2B in cryptocurrency in 2025 alone. Understanding Lazarus Group's operations helps defend against state-sponsored financial theft.

Threat Intel DeskJan 10, 2026
UK Commits £210M to Mandatory Public Sector Cybersecurity
Threat Intelligence4 min read

UK Commits £210M to Mandatory Public Sector Cybersecurity

New Government Cyber Action Plan creates centralized security unit, dedicated cyber profession, and mandatory requirements for all departments. Legacy systems get top priority.

Threat Intel DeskJan 7, 2026
Finland Arrests Ship Crew Over Baltic Cable Sabotage
Threat Intelligence4 min read

Finland Arrests Ship Crew Over Baltic Cable Sabotage

Two crew members detained after cargo vessel's anchor allegedly severed Finland-Estonia telecommunications cable in suspected hybrid warfare operation.

Threat Intel DeskJan 4, 2026