
| Name | Origin | About | Target Locations | Target Sectors |
| APT27(Emissary Panda, LuckyMouse, Bronze Union, TG-3390, TEMP.Hippo, Budworm, Group 35, ATK 15, Iron Tiger, Earth Smilodon, ZipToken) | China | The malicious campaign targets German commercial organizations where the attackers use the HyperBro remote access trojan to inject backdoors into the victims' network. HyperBro allows hackers to persist on victim networks by acting as an in-memory backdoor with remote administration capabilities. The threat group's goal is to steal sensitive information as well as attempt to target their victim’s customers in supply chain attacks. | Australia, Canada, China, Hong Kong, India, Iran, Israel, Japan, France Middle East, Philippines, Russia, South Korea, Taiwan, Thailand, Tibet, UK, USA, Germany | Retail, Defense, Education, Healthcare, Embassies, Government, Technology, Telecommunications, and Think Tanks |
| MuddyWater (Static Kitten, Seedworm, TEMP.Zagros, Mercury, TA450, Cobalt Ulster, ATK 51, T APT-14, ITG17) | Iran | The Iranian-backed MuddyWater hacking group is conducting a new malicious campaign targeting private organizations and governmental institutions in Turkey. This cyber-espionage group mainly used the PowGoop DLL Loader and Mori Backdoor in the current attack campaign. | Afghanistan, Armenia, Austria, Azerbaijan, Bahrain, Belarus, Egypt, Georgia, India, Iran, Iraq, Israel, Jordan, Kuwait, Laos, Lebanon, Mali, Netherlands, Oman, Pakistan, Russia, Saudi Arabia, Tajikistan, Thailand, Tunisia, Turkey, UAE, | Defense, Education, Energy, Financial, Food and Agriculture, Gaming, Government, Healthcare, High-Tech, IT, Media, NGOs, Oil and Gas, Telecommunications, Transportation. |
| Molerats (Extreme Jackal, Gaza Cybergang, Gaza Hackers Team, TA402, Aluminum Saratoga, ATK 89, TAG-CT5) | Gaza | An APT group Molerats associated with Gaza has launched a new threat campaign using a malware NimbleMamba aimed at Middle Eastern governments, foreign policy think tanks, and even a state-owned airline. | Afghanistan, Algeria, Canada, China, Chile, Denmark, Egypt, Germany, India, Iran, Iraq, Israel, Jordan, Kuwait, Lebanon, Latvia, Libya, Macedonia, Morocco, New Zealand, Oman, Palestine, Qatar, Russia, Saudi Arabia, Serbia, Slovenia, Somalia, South Korea, Syria, Turkey, UAE, UK, USA, Yemen | Aerospace, Defense, Embassies, Energy, Financial, Government, High-Tech, Media, Oil and gas, Telecommunications |
| BlackCats aka ALPHV | Unknown | The Blackcat Ransomware gang also known as ALPHV has targeted around 25 organizations belonging to multiple sectors globally since November 2021. | United States, France, Thailand, Canada, Switzerland, Italy, Hungary, Hong Kong, China, Italian, Philippines, United Kingdom, North America, Germany, Netherlands, Argentina, Spain | Construction and engineering, Retail, Transportation, Commercial Services, Insurance, Machinery, Professional services, Telecommunication, Auto components, and Pharmaceuticals |
| APT28 (Sofacy Fancy Bear, Sednit, Group 74, TG-4127, Pawn Storm, Tsar Team, Strontium, Swallowtail, SIG40, Snakemackerel, Iron Twilight, ATK 5, T-APT-12, ITG05, TAG-0700, Grizzly Steppe) | Russia | The threat actors exfiltrated sensitive data from small and large companies in the U.S. working on defense and intelligence contracts, including missile development, vehicle & aircraft, and software development. | Afghanistan, Armenia, Australia, Azerbaijan, Belarus, Belgium, Brazil, Bulgaria, Canada, Chile, China, Croatia, Cyprus, France, Georgia, Germany, Hungary, India, Iran, Iraq, Japan, Jordan, Kazakhstan, Latvia, Malaysia, Mexico, Mongolia, Montenegro, Netherlands, Norway, Pakistan, Poland, Romania, Slovakia, South Africa, South Korea, Spain, Sweden, Switzerland, Tajikistan, Thailand, Turkey, Uganda, UAE, UK, Ukraine, USA, Uzbekistan | Automotive, Aviation, Chemical, Construction, Defense, Education, Embassies, Engineering, Financial, Government, Healthcare, Industrial, IT, Media, NGOs, Oil and gas, Think Tanks, and Intelligence organizations. |
| UNC2596 | Unknown | Threat actor UNC2596 popularly known for their Ecrime business has targeted more than 50 organizations in 11+ countries. The threat actors increased their initial attack vector by exploiting proxyshell and proxylogon vulnerabilities to deploy Cuba ransomware. | Australia, Belgium, Canada, Germany, India, UK, USA, Austria, Colombia, Jordan, Poland | Construction & Engineering, Education, Manufacturing, Oil & Gas, Transportation, Defense, Energy, Financial, Government, Healthcare, High-Tech, IT, Media, Pharmaceutical, Telecommunications, and MSPs |
| APT10 (Stone Panda, APT 10, menuPass, Red Apollo, CVNX, Potassium, Hogfish, Happyyongzi, Cicada, Bronze Riverside, CTG-5938, ATK 41, TA429, ITG01) | China | Chinese threat actor APT10 conducted a series of large-scale supply chain attacks that exclusively targeted the financial software systems of Taiwanese financial institutions from the end of November 2021 until the middle of February 2022. The actor is well-known for the attacks on Japanese automakers, British managed service providers, US-based aerospace and defense corporations, and South Korean missile defense systems. | Australia, Belgium, Brazil, Canada, China, Finland, France, Germany, Hong Kong, India, Japan, Netherlands, Norway, Philippines, Singapore, South Africa, South Korea, Sweden, Switzerland, Taiwan, Thailand, Turkey, UAE, UK, USA, Vietnam. | Aerospace, Defense, Energy, Financial, Government, Healthcare, High-Tech, IT, Media, Pharmaceutical, Telecommunications, and MSPs. |


| Malware | Description |
| Daxin | Daxin malware is a sophisticated rootkit backdoor with complicated, stealthy command and control (C2) features that allowed remote actors to communicate with secured devices that were not directly connected to the internet. This malware communicates with legitimate services through network tunneling and uses daisy-chain communication that provides it the ability to move internally via hops between several linked computers. The malware appears to be designed for the use against hardened targets, allowing actors to dig deeply into targeted networks and exfiltrate data without raising suspicions. |
| HermeticWiper | Several cybersecurity researchers reported from across the globe and disclosed a highly catastrophic malware known as HermeticWiper which was targeting several organizations in Ukraine. The malware targets the Windows device’s master boot record and manipulates to cause the boot failure. To infiltrate the network, lateral movement, and malware distribution, attackers used tools like Impacket and RemCom as remote access software. A worm HermeticWizard uses WMI and SMB to spread through the network and deploy a wiper to the local computer. Successful exploitation may directly impact the daily operations of any organization and cause the unavailability of critical assets and data. |
| Isaacwiper | IsaacWiper was discovered as a Windows DLL or EXE with no Authenticode signature; the earliest PE compilation timestamp was discovered by a well-known internet security firm on October 19th, 2021, implying that the malware may have been used in previous operations months earlier without being detected. Isaacwiper is now focusing on groups that are immune to Hermeticwiper. |
| T1190 | Exploit Public-Facing Application |
| T1068 | Exploitation for Privilege Escalation |
| T1059 | Command and Scripting Interpreter |
| T1140 | Deobfuscate/Decode Files or Information |
| T1105 | Ingress Tool Transfer |
| T1027 | Obfuscated Files or Information |
| T1566.002 | Spearphishing Link |
| T1204.001 | Malicious Link |
| T1083 | File and Directory Discovery |
| T1082 | System Information Discovery |
