Netcrook

APT Campaigns

201 article(s)

TA446 Unleashes DarkSword: Inside the New Wave of iOS Cyberattacks

🗓 01 Apr 2026 · 👤 AGONY

A dramatic shift in cyber-espionage: TA446 launches DarkSword, a sophisticated exploit kit targeting iOS devices through deceptive phishing and advanced technical exploits. Our investigation reveals the methods, implications, and what’s next for mobile security.

Blackout and Blowback: Inside Iran’s 30-Day Digital Onslaught

🗓 01 Apr 2026 · 👤 AGONY · 🌍 Middle-East

Iran’s 30-day cyberwar saw near-total internet blackout at home but unleashed thousands of attacks abroad, targeting critical infrastructure and exposing new global vulnerabilities. The campaign’s blend of physical and digital assaults has redrawn the rules of cyber conflict.

Handala’s FBI Hack: How Iran’s Cyber Proxies Targeted the Director’s Private Email

🗓 01 Apr 2026 · 👤 AGONY · 🌍 Middle-East

Iran-linked hacktivist group Handala breached the personal Gmail of FBI Director Kash Patel, leaking private emails and photos in a symbolic act of cyberwar. The attack, retaliation for FBI actions against Handala, highlights the personal vulnerabilities of high-profile officials and the evolving tactics of Iranian cyber operations.

Lockheed Martin Targeted: Iranian Hackers Escalate Cyberwar with Data Theft and Death Threats

🗓 27 Mar 2026 · 👤 AGONY · 🌍 Middle-East

Lockheed Martin suffered a dramatic two-stage attack by Iranian-linked hackers in March 2026. Beyond alleged data theft, engineers were doxxed and threatened, marking a dangerous new phase in hybrid cyberwarfare.

APT-Q-27's Screenshot Scam: Web3 Support Teams Targeted in Multi-Stage Malware Attack

🗓 26 Mar 2026 · 👤 AGONY · 🌍 Asia

APT-Q-27 is targeting Web3 support staff with deceptive screenshot links that unleash a sophisticated multi-stage malware chain, culminating in a stealthy memory-resident backdoor. Discover how the attack works and what defenders need to know.

Sandworm’s Stealth RDP Attacks: How APT44 Turns Remote Access Into Espionage Gateways

🗓 25 Mar 2026 · 👤 AGONY · 🌍 Europe

Sandworm (APT44) is hijacking RDP servers with advanced malware, using forged certificates and encrypted tunnels to maintain stealthy, long-term access to high-value networks. Here’s how the campaign works—and what defenders need to know.

TeamPCP’s CanisterWorm: Iran-Targeted Kubernetes Wiper Exposes Global Cloud Risks

🗓 25 Mar 2026 · 👤 AGONY · 🌍 Middle-East

TeamPCP’s CanisterWorm launches targeted destruction against Iranian Kubernetes clusters and persistent backdoors elsewhere. Learn how this sophisticated malware campaign exploits cloud environments and what security teams must do to defend.

Iranian Hacktivists: More Hype Than Harm in Gulf Cyberwar

🗓 25 Mar 2026 · 👤 AGONY · 🌍 Middle-East

Despite a dramatic surge in cyber claims, Iranian hacktivist groups appear to be more focused on psychological disruption than causing real damage to Gulf infrastructure. Our investigation separates fact from fiction in the digital battlefield.

Kamikaze in the Cloud: CanisterWorm’s Iran-Focused Kubernetes Wiper Exposed

🗓 24 Mar 2026 · 👤 AGONY · 🌍 Middle-East

A new variant of TeamPCP’s CanisterWorm selectively destroys Iranian Kubernetes clusters and embeds stealth backdoors elsewhere, marking a dangerous escalation in targeted cyberwarfare.

How Iran’s Surveillance Cameras Became Israel’s Secret Weapon

🗓 24 Mar 2026 · 👤 AGONY · 🌍 Middle-East

Iran’s sweeping surveillance system, intended to control protest and dissent, became a tool for Israeli intelligence after being hacked. The same cameras meant to safeguard the regime were weaponized, contributing to the assassination of Iran’s supreme leader and exposing a new era of AI-driven espionage.

« Prev 3   4   5   6   7   Next »