Deep Analysis
Long-form analysis of significant threat actors, campaigns, and incidents. Written for those who need to understand the full picture — not just the headlines.
Akira Ransomware: The VPN-First Playbook Behind a $244 Million Operation
Akira has become one of the most prolific ransomware operations of 2025-26 by sticking to a disciplined playbook: compromised VPN credentials, ESXi encryptors, and a short negotiation window. Here's how the group operates, who it targets, and what defenders can do about it.
Lurking Lizard: How a China-Linked Cybercrime Group Built a Global Residential Proxy Network Through Fake Software
Infoblox and The Hacker News disclosed in July 2026 that Lurking Lizard, a China-based financially motivated threat group, operates an industrial-scale residential proxy business sustained by trojaned installers for legitimate software. The network has processed hundreds of millions of proxy requests and is actively rented to criminal and espionage-linked operators.
Storm-2755: Inside the Malware-Free Payroll Fraud Group Redirecting Canadian Salaries to Attacker Accounts
Microsoft disclosed Storm-2755 in April 2026 — a financially motivated threat actor conducting adversary-in-the-middle phishing campaigns against Canadian employees to redirect payroll deposits to attacker-controlled bank accounts. The group operates without traditional malware, using stolen session tokens to bypass MFA and modify direct deposit settings in HR portals.
DPRK IT Worker Networks: North Korea's Industrial-Scale Employment Fraud Operation
North Korea is running an industrial-scale programme in which thousands of operatives pose as freelance software developers and remote employees to generate revenue, conduct espionage, and extort companies they infiltrate. Tracked as UNC5267 and Nickel Tapestry, this threat has graduated from a revenue scheme to a direct enterprise security risk.
UAT-7810 and LapDogs: Inside China's Malware Factory for Covert Relay Infrastructure
Cisco Talos has published detailed research on UAT-7810's LapDogs campaign: a China-nexus operation building Operational Relay Box networks through compromised SOHO routers. New malware families LONGLEASH, DOGLEASH, and JARLEASH reveal how far this infrastructure-as-a-service model has matured.
Weaver Ant: The China-Nexus APT That Lived Inside a Telecom for Four Years
Sygnia's exposure of Weaver Ant reveals a China-aligned threat actor that maintained persistent access inside an Asian telecommunications provider for more than four years, using an AES-encrypted China Chopper variant, a novel in-memory web shell, and an ORB network built from compromised telco routers.
Cadet Blizzard: GRU Unit 29155 and the Sabotage Doctrine
Cadet Blizzard — GRU Unit 29155's cyber arm — is the group behind WhisperGate, a wiper that preceded Russia's full-scale Ukraine invasion. Since the September 2024 DOJ indictment publicly named its officers, a clearer picture has emerged of a unit that combines destructive cyber operations with physical sabotage across NATO member states.
Anubis Ransomware: The RaaS Platform Weaponising Healthcare Regulators Against Its Own Victims
Anubis is a Go-based ransomware-as-a-service operation that emerged in late 2024 and has rapidly focused on healthcare organisations, deploying a novel pressure tactic: threatening to notify data protection regulators and HIPAA enforcement bodies unless victims pay. This deep dive covers Anubis's affiliate model, technical profile, targeting patterns, and the regulatory weaponisation that distinguishes its extortion approach.
Cicada3301: The Rust-Based RaaS That Emerged From the ALPHV Collapse
Cicada3301, tracked by Palo Alto Unit 42 as Repellent Scorpius, emerged in mid-2024 as a technically sophisticated ransomware-as-a-service operation bearing strong similarities to the ALPHV/BlackCat platform. This deep dive examines the evidence for an ALPHV connection, the technical profile of the Rust-based encryptor, targeting patterns, and what the group's structure tells us about resilience in the ransomware ecosystem.
RansomHub: The RaaS Platform That Inherited the Ransomware Ecosystem
RansomHub launched in February 2024 as a direct beneficiary of two simultaneous law enforcement disruptions — the FBI's LockBit takedown and the ALPHV/BlackCat collapse — and in less than a year became the most prolific ransomware group by victim count. This deep dive covers how RansomHub built its dominance, the multi-platform technical architecture, the affiliate model that makes it resilient to law enforcement pressure, and what defenders should prioritise.
Qilin: The Ransomware Group Behind the NHS Synnovis Attack and the Chrome Credential Theft Innovation
Qilin emerged in 2022 as Agenda ransomware and has evolved through a complete Rust rewrite, a defining attack on NHS blood supply services in 2024, a novel Chrome browser credential theft technique, and a 2026 VPN exploitation campaign hitting four major vendors simultaneously. This deep dive covers the full operational and technical profile.
Pioneer Kitten: How Iran's IRGC Became an Access Broker for Ransomware Gangs
Pioneer Kitten — tracked as Fox Kitten, Lemon Sandstorm, and UNC757 — is an Iranian state-sponsored group that exploits network perimeter devices to establish persistent access, then sells that access to criminal ransomware affiliates. This deep dive examines the group's dual mandate, tradecraft, and what a compromise looks like in practice.
RomCom / Storm-0978: Russia's Hybrid Espionage-Criminal Threat Actor
RomCom — tracked by Microsoft as Storm-0978, by Unit 42 as Tropical Scorpius, by Mandiant as UNC2596 — is a Russian threat actor that operates across the line between state-sponsored espionage and organised cybercrime. The group exploited two chained zero-days to target NATO governments in 2023, runs Underground ransomware operations for revenue, and has maintained continuous campaigns against Ukrainian government and European defence targets through 2026.
Mustang Panda (Twill Typhoon): China's Most Prolific Espionage APT
Mustang Panda is one of the most operationally active Chinese APT groups, running continuous espionage operations since at least 2012. Known for PlugX, DLL sideloading, and a rapidly evolving implant arsenal, the group has compromised government ministries, NGOs, telecoms, and religious organisations across Southeast Asia, Europe, and beyond.
INC Ransomware: Rust Encryptors, Veeam Credential Theft, and 830 Victims
INC Ransom has quietly become one of the most prolific ransomware operations of 2025-2026, combining purpose-rebuilt Rust encryptors, a modified Veeam DPAPI credential dumper, and deliberate use of living-off-the-land techniques to evade detection. With over 830 confirmed victims across healthcare, legal, and manufacturing, this group deserves closer examination than it typically receives.
APT42: Iran's Elite Social Engineering Unit Targeting Western Officials and Research
APT42 is Iran's most operationally sophisticated espionage actor — an IRGC-IO-sponsored group that has compromised US presidential campaigns, nuclear researchers, journalists, and Western diplomats through highly targeted social engineering rather than technical exploitation.
FulcrumSec: Deep Dive into the Data Extortion Group Exploiting Developer Credential Sprawl
FulcrumSec emerged in October 2025 running pure data extortion with no ransomware component. Confirmed victims include Avnet (1.3TB), youX (300GB), and Novo Nordisk (1.3TB, $25M demand). Their initial access technique — GitHub PATs exposed in client-side JavaScript — is simple, scalable, and rapidly becoming a template for other extortion groups. This deep dive covers their attack chain, operational history, tooling characteristics, and defensive countermeasures.
GopherWhisper: China-Aligned APT Using Cloud Messaging C2 Against Mongolian Government
GopherWhisper is a China-aligned threat actor discovered by ESET in January 2025 and publicly disclosed in April 2026. The group operates Go-based implants that use Slack, Discord, Microsoft 365 Outlook, and legitimate file-sharing services as command-and-control channels, almost entirely avoiding traditional C2 infrastructure. Their campaigns have persistently targeted the Mongolian government.
Secret Blizzard: Inside Russia's Most Patient Cyber Espionage Operation
A deep dive into Secret Blizzard (Turla), the FSB-linked APT that has sustained global intelligence collection for over two decades — hijacking criminal infrastructure, deploying ISP-level interception against foreign embassies, and evolving the Kazuar backdoor into a resilient P2P botnet.
APT41 / Winnti / Double Dragon: China's Dual-Mandate Cyber Threat Group
APT41 operates simultaneously as a state-directed espionage actor targeting strategic industries for Beijing and a financially motivated cybercriminal enterprise — a combination unique among Chinese threat groups. A 2026 ELF cloud credential backdoor with zero VirusTotal detections is the latest evidence of the group's continued operational sophistication.
Gamaredon in 2026: Russia's Most Persistent APT Upgrades to a Modular Framework and Exploits WinRAR for Initial Access
Gamaredon (Primitive Bear, Aqua Blizzard) — Russia's FSB-linked APT targeting Ukraine since 2014 — has deployed a newly modularised malware framework in 2026, using HTML smuggling and CVE-2025-8088 WinRAR exploitation for initial access. Sekoia's June 2026 analysis reveals a four-stage VBScript loader chain, Telegram-based dead drop resolvers, and five distinct payload families covering every phase of the kill chain.
APT28: Russia's GRU Hacking Unit and the Twenty-Year Campaign Against Western Democracy
APT28 — Fancy Bear, Forest Blizzard, GRU Unit 26165 — is Russia's Military Intelligence cyber arm and the most prolific nation-state attacker targeting Western governments, militaries, and democratic institutions. This deep dive covers their operational history, tradecraft, tooling, and current targeting priorities.
Cl0p: The Group That Turned File Transfer Vulnerabilities Into a Mass Exploitation Business
Cl0p is a financially motivated cybercriminal group that has systematically identified and mass-exploited zero-day vulnerabilities in enterprise file transfer software, compromising thousands of organisations globally. Their MOVEit campaign in 2023 was the largest data theft operation in the history of ransomware. This deep dive covers their operational model, technical approach, and what comes next.
LockBit: The Ransomware Operation That Survived Its Own Takedown
LockBit is the world's most prolific ransomware-as-a-service operation, responsible for more confirmed attacks than any other RaaS group. Despite Operation Cronos seizing its infrastructure and unmasking its administrator in 2024, the affiliate network remains active. This deep dive covers LockBit's operational model, technical capabilities, and what the post-Cronos resurgence means for defenders.
Midnight Blizzard: A Complete Profile of Russia's SVR Espionage Apparatus
APT29 — Cozy Bear, Midnight Blizzard — is Russia's SVR-aligned intelligence collection machine, responsible for SolarWinds, the 2024 Microsoft corporate email compromise, and ongoing targeting of European governments, diplomatic missions, and defence industrial base organisations. This deep dive covers their full operational history, tradecraft, tooling, and what defenders need to be doing now.
MuddyWater: Iran's MOIS Cyber Arm and the Blurred Line Between Espionage and Disruption
MuddyWater — Seedworm, Static Kitten, Earth Vetala — is Iran's Ministry of Intelligence and Security cyber unit conducting sustained espionage across the Middle East, Europe, and Asia, increasingly deploying ransomware as a false flag to complicate attribution and provide cover for intelligence collection.
UNC1549: Iran's Persistent Aerospace and Defence Espionage Operation
UNC1549 — tracked as Screening Serpens and Nimbus Manticore by different intelligence vendors — is an IRGC-affiliated Iranian APT conducting sustained espionage against aerospace, defence, and telecommunications targets. Their recent expansion to European targeting, adoption of Azure and cloud C2 infrastructure, and novel AppDomainManager injection technique make them a growing concern beyond their traditional Middle East focus.
Harvester APT: South Asia Espionage Expands to Linux With Graph API Command-and-Control
The Harvester threat group — active since at least 2021 against government and telecommunications targets in South Asia — has extended its capabilities to Linux with a new GoGra backdoor variant that routes command-and-control traffic through Microsoft Outlook via the Graph API. The evolution reflects a broader shift toward cloud-service-based C2 that defeats traditional perimeter monitoring.
Silk Typhoon: China's IT Supply Chain Pivot and the Downstream Threat to Every Sector
Silk Typhoon — the Chinese state actor behind the 2021 Exchange ProxyLogon campaign and the 2024 US Treasury breach — has fundamentally changed how it operates. A deep dive into the group's shift to IT supply chain targeting and what it means for every organisation that relies on a managed service provider.
Lazarus Group / TraderTraitor: North Korea's Premier Financial Theft Operation
A comprehensive profile of Lazarus Group and its TraderTraitor subcluster -- the North Korean cyber apparatus responsible for over $6 billion in cryptocurrency theft, the largest single financial heist in history, and a growing campaign of developer-targeted supply chain intrusions.
Sandworm: Inside Russia's Most Destructive Cyber Weapon
Sandworm -- GRU Unit 74455 -- is responsible for the most destructive cyberattacks in history: the 2015 and 2016 Ukraine power grid attacks, NotPetya, Olympic Destroyer, and continuous destructive campaigns against Ukraine since 2022. This deep-dive covers their history, capabilities, and why they remain the most dangerous threat actor operating today.
Phantom Taurus: China's Surgical New APT Targeting Governments and Embassies Worldwide
Unit 42 researchers have unmasked Phantom Taurus, a previously undocumented Chinese state-aligned APT deploying the bespoke NET-STAR malware suite against ministries of foreign affairs, embassies, and telecoms across Africa, the Middle East, and Asia.
SHADOW-EARTH-053: Inside China's ShadowPad Espionage Campaign Against Asian Governments and NATO
A detailed examination of SHADOW-EARTH-053, a China-aligned cyberespionage cluster that has compromised government, defence, and critical infrastructure organisations across South, East, and Southeast Asia -- and at least one NATO member state -- since late 2024.
The Gentlemen: From Zero to 340 Victims in Nine Months -- Inside the RaaS Group Rewriting the Ransomware Playbook
Launched in mid-2025 by a disgruntled Qilin affiliate, The Gentlemen ransomware-as-a-service operation reached third place globally in Q1 2026 through pre-stockpiled FortiGate access, a 90% affiliate commission, and a deliberate strategy to target non-US markets that most groups neglect.
UNC3886: The China-Nexus Group That Breached All of Singapore's Major Telecoms
UNC3886, the China-linked APT responsible for zero-day exploitation of Fortinet, VMware, and Juniper systems, breached all four of Singapore's major telecommunications operators in a campaign that triggered the nation's largest ever coordinated cyber defence operation.
AI in the Attack Chain: How Threat Actors Are Using Language Models Operationally
AI-assisted exploitation is no longer theoretical. From automated vulnerability research to AI-generated spear-phishing, the adoption of LLMs across the offensive lifecycle is accelerating. This analysis examines what is confirmed, what is emerging, and what it means for defenders.
Volt Typhoon: The Long Game in Western Critical Infrastructure
A deep analysis of Volt Typhoon's objectives, methods, and targets -- and what the sustained Chinese pre-positioning campaign in Western CNI means for how operators, regulators, and governments need to respond.
Salt Typhoon: How China Compromised the West's Wiretap Infrastructure
The Salt Typhoon campaign against US and European telecommunications carriers was not a data breach in any conventional sense. It was a strategic intelligence operation targeting the systems governments use to conduct lawful surveillance.
Scattered Spider: When Social Engineering Becomes a Professional Discipline
The group behind the MGM Resorts and Caesars Entertainment attacks isn't a nation-state operation or a seasoned criminal enterprise. They're young, English-speaking, and they're better at manipulating people than most security teams are at stopping them.
No analyses match this sector filter.