nation-state cyber threats.
Gated threat reports and active advisories from HiveForce Labs. Tracking the state-sponsored operations targeting your industry, your geography, and your infrastructure.
Featured Report · Part 2 · Most Downloaded
HiveForce Labs releases critical findings on the most significant cyber-kinetic conflict in history. Tactics, techniques, and procedures observed across Iranian state-sponsored operations targeting Western infrastructure.
Download the Report →
🔒 Gated · Form Required
Why This Matters
They're
targeting you now.
Geopolitical conflict has moved into the network layer. Iranian, Russian, Chinese, and North Korean operations are actively probing Western enterprises, with TTPs that bypass traditional vulnerability management. This hub is where HiveForce Labs publishes what we're seeing in the field.
01
Gated, in-depth threat reports for each nation-state actor we actively track.
02
Open threat advisories on specific CVEs, exploits, and campaigns tied to state-sponsored groups.
03
Briefing-list signup for nation-state coverage we're actively researching.
Iran · ACTIVE COVERAGE

Report · Part 2
Updated TTPs, infrastructure mapping, and remediation guidance based on Q1-Q2 2026 incident telemetry.
Download Report →

Report · Part 1
The original HiveForce Labs report on Iranian operations: threat actor profiles, observed TTPs, and target industries.
Download Report →

eBook · Companion Guide
Self-assessment guide for security leaders. Map the Iranian TTPs against your current controls and exposure posture.
Read the eBook →

Free Tool
Get a tailored report on your organization's exposure to active Iranian campaigns. Runs against your scan data, returns in 48 hours.
Request Assessment →
Russia · COMING SOON
TA2026093
APT28, the Russian state-sponsored threat group operating under GRU Military Intelligence Unit 26165, conducted a large-scale DNS hijacking campaign dubbed Operation FrostArmada by compromising small office and home office routers to build distributed credential theft infrastructure.
Read →
China · COMING SOON
TA2025371
ShadyPanda threat actor, a likely China-based cybercriminal group, orchestrated a seven-year browser extension malware operation that compromised more than 4.3 million Chrome and Edge users worldwide.
Read →
North Korea · COMING SOON
TA2025122
A newly uncovered cyber espionage campaign by North Korea-linked Kimsuky (aka Larva-24005) has been active since at least October 2023, targeting South Korea’s software, energy, and financial sectors, as well as global organizations.
Read →
UAE · COMING SOON
TA2025183
Stealth Falcon, a long-active cyber-espionage group, exploited a zero-day vulnerability in Windows (CVE-2025-33053) to target a Turkish defense firm using a malicious file disguised as a PDF.
Read →
Other Actors · COMING SOON
TA2026084
Stealth Falcon, a long-active cyber-espionage group, exploited a zero-day vulnerability in Windows (CVE-2025-33053) to target a Turkish defense firm using a malicious file disguised as a PDF.
Read →
Talk to Hive Pro
Book a Demo →
Looking for general threat research and resources?
Visit the Learning Center →
Platform
Arbis AI
The Hive Pro Platform
Integrations
OT / ICS Security
Compare
vs Rapid7
vs Tenable
vs Qualys
vs Nucleus
Solutions
Attack Surface Mgmt
Multi-Env Scanners
Exposure Assessment
Security Intelligence
Threat Prioritization
Exposure Validation
By Role
CISO
Vulnerability Managers