BT
Privacy ToolboxJournalProjectsResumeBookmarks
Feed
Privacy Toolbox
Journal
Projects
Resume
Bookmarks
Intel
Threat Actors
Privacy Threats
Dashboard
CVEs
Tags
Intel
Threat ActorsPrivacy ThreatsDashboardCVEsTags

Intel

  • Feed
  • Threat Actors
  • Privacy Threats
  • Dashboard
  • Privacy Toolbox
  • CVEs

Personal

  • Journal
  • Projects

Resources

  • Subscribe
  • Bookmarks
  • Developers
  • Tags
Cybersecurity News & Analysis
github
defconxt
•
© 2026
•
blacktemple.net
  1. Feed
  2. /Tags
  3. /apt

Tag: apt

highNation-State & APT

Nation-State Roundup: Iran's Handala Wiper Campaign Escalates, China Targets Southeast Asian Military

Unit 42 reports increased wiper attacks by Iran-linked Handala Hack group exploiting Microsoft Intune, while a separate China-based espionage operation targets military infrastructure across Southeast Asia. Additional developments include FBI surveillance data increases, Stryker cyberattack recovery uncertainties, and critical WordPress plugin vulnerabilities.

Mar 13, 2026Security Affairs, The Record, Palo Alto Unit 42
nation-stateaptiran
🇺🇸Apple
highData Breaches & Incidents

Iran's MuddyWater Targets US Firms, macOS Stealer Campaign, and HIBP Surge

Iran's MuddyWater hackers deployed new Dindoor backdoor against US companies while cybercriminals used fake CleanMyMac sites to distribute macOS stealer malware. Meanwhile, Have I Been Pwned processed five major breaches in two days, highlighting an acceleration in data compromise incidents.

Mar 10, 2026Hackread, Troy Hunt
muddywateraptmacos
🇮🇷MuddyWater
highNation-State & APT

Iranian APT Groups Intensify Cyber Operations Against U.S. and Middle East Infrastructure

Check Point researchers observed Iran-linked actors targeting IP cameras across Israel and Gulf states for military intelligence, while Broadcom's Symantec team uncovered MuddyWater deploying the new Dindoor backdoor against U.S. banks, airports, and nonprofits.

Mar 7, 2026Security Affairs
iranmuddywaterapt
🇮🇷MuddyWater
highNation-State & APT

Nation-State Roundup: Iran-Nexus APT Targets Iraq Officials, Phobos Admin Pleads Guilty, Multi-Year Campaign Exposed

Iranian threat actors are actively targeting Iraqi government officials with previously unknown malware families, while law enforcement secured a guilty plea from a Phobos ransomware administrator. Separately, researchers uncovered a multi-year campaign targeting high-value sectors that went undetected for years.

Mar 6, 2026Security Affairs, Palo Alto Unit 42
aptiraniraq
🏴Phobos
highMalware & Threats

Threat Landscape Roundup: Zero-Day Surge, State Actor Campaigns, and Multi-Million Dollar Fraud Operations

Google's threat intelligence reveals 90 zero-day vulnerabilities were actively exploited in 2025, with nearly half targeting enterprise infrastructure. Concurrently, state-sponsored groups continue targeting telecommunications providers while cybercriminals execute multi-million dollar fraud schemes through business email compromise and cryptocurrency theft.

Mar 6, 2026BleepingComputer, Cisco Talos, Malwarebytes Labs, SecureList (Kaspersky)
zero-dayaptmalware
🇺🇸Google
mediumNation-State & APT

Russian APT Deploys New Ukraine-Targeting Malware as Law Enforcement Disrupts Global Cybercrime Operations

Russian threat actors launched a new espionage campaign against Ukraine using two undocumented malware strains. Meanwhile, international law enforcement scored major wins with takedowns of the Leakbase cybercrime forum and indictments against 62 individuals tied to the Prince Group scam operation.

Mar 5, 2026Security Affairs, The Record
russiaukraineapt
highVulnerabilities & Exploits

Multi-Platform RATs, AI-Driven Attacks, and Certificate Abuse: Weekly Vulnerability Roundup

Multiple sophisticated attack campaigns emerged this week, including cross-platform RATs distributed via fake Laravel packages, APT41-linked Silver Dragon targeting governments, and AI-assisted attacks hitting FortiGate devices across 55 countries. Certificate abuse and social engineering tactics continue enabling persistent enterprise access.

Mar 4, 2026The Hacker News, Microsoft Security, SANS ISC, MSRC Security Updates
malwareaptsupply-chain
🇨🇳APT41
🇺🇸Google
highVulnerabilities & Exploits

Active Android Exploit, Government-Targeted Campaigns, and OAuth Abuse Highlight March Threat Landscape

Google disclosed active exploitation of a Qualcomm Android vulnerability while Microsoft warned of OAuth redirect campaigns targeting government entities. Meanwhile, SloppyLemming APT actors launched dual malware chains against Pakistan and Bangladesh governments.

Mar 3, 2026The Hacker News, Ars Technica Security, SANS ISC, MSRC Security Updates
androidoauthgovernment-targeting
🇺🇸Google🇺🇸Oracle Data Cloud🇺🇸Apple
criticalMalware & Threats

Critical Infrastructure Vulnerabilities and Evolving Attack Vectors: Weekly Threat Roundup

This week brought critical remote code execution vulnerabilities in Juniper PTX routers and Trend Micro Apex One, alongside sophisticated social engineering campaigns abusing Google APIs and trusted video conferencing brands. Ransomware payment rates have dropped to historic lows despite increased attack volume.

Feb 27, 2026BleepingComputer, Graham Cluley, Cisco Talos, Malwarebytes Labs
vulnerabilitiesransomwaredata-breach
🇺🇸Google
criticalVulnerabilities & Exploits

Critical Infrastructure Under Fire: Cisco Zero-Day Exploited Since 2023, Google Disrupts China APT

A critical Cisco SD-WAN authentication bypass vulnerability has been exploited in the wild since 2023, while Google disrupted a China-linked APT that breached 53 organizations across 42 countries. Supply chain attacks continue with malicious NuGet packages impersonating Stripe libraries and vulnerabilities in AI coding assistants enabling remote code execution.

Feb 26, 2026The Hacker News, SANS ISC, MSRC Security Updates
zero-dayciscosd-wan
🏴Lapsus$
🇺🇸Google
highMalware & Threats

Threat Intelligence Digest: Chinese APT Campaign, Critical Router RCE, and Agent Tesla Resurgence

This week saw a Chinese APT campaign breach dozens of telecom firms and government agencies using novel SaaS API evasion techniques. Critical vulnerabilities emerged in Zyxel routers enabling unauthenticated RCE, while Agent Tesla campaigns evolved with advanced multi-stage delivery mechanisms.

Feb 26, 2026BleepingComputer, Graham Cluley, Malwarebytes Labs, Fortinet
aptmalwaredata-breach
🇺🇸Meta Platforms🇦🇪Telegram🇺🇸Google
highVulnerabilities & Exploits

Supply Chain Worms and State-Sponsored Malware: Weekend Threat Roundup

Active npm supply chain worm harvests crypto keys and CI secrets while Iranian APT MuddyWater deploys new malware targeting MENA organizations in coordinated campaign.

Feb 23, 2026The Hacker News, SANS ISC
supply-chainnpmmalware
🇮🇷MuddyWater🇷🇺Sandworm