ProBackend
Advanced Persistent Threats (APTs)

Advanced Persistent Threats (APTs)

Articles on nation-state and highly sophisticated cyber threat groups, including APT28, Kimsuky, MuddyWater, and their tactics, techniques, and infrastructure.

advanced persistent threats apts3 weeks ago6 min

CaptiveCrunch: How Russian APT29 (Midnight Blizzard) Uses AI-Developed Malware to Target Hotel Wi-Fi and Steal Microsoft 365 Accounts

Microsoft links the CaptiveCrunch campaign to Russian threat actor Midnight Blizzard (APT29/Storm-2945). The campaign uses AI-developed malware families—CornFlake and ChocoShell—to compromise hospitality Wi-Fi networks and steal Microsoft 365 credentials through DNS manipulation and ClickFix delivery.

advanced persistent threats aptsAug 3, 20265 min

AI Cybersecurity Threats: How Leaked ShinyHunters Breach Data Fuels $2,000 Sextortion Scams

Opportunistic scammers are scraping leaked email addresses from corporate breaches associated with ShinyHunters to send $2,000 Bitcoin sextortion threats. Analysis of how secondary extortion works and how enterprise security teams must respond to AI cybersecurity threats.

advanced persistent threats aptsAug 3, 20263 min

Model Distillation and Evasion Routes: How AI Cybersecurity Threats Escalate in 2026

An analysis of White House allegations that China's Moonshot AI distilled Anthropic's Fable model using offshore Nvidia GB300 clusters, escalating AI cybersecurity threats in 2026.

advanced persistent threats aptsAug 2, 20265 min

Securing Agentic Infrastructure: Defenses Against Escalating AI Cybersecurity Threats in 2026

Threat intelligence reveals how autonomous DeepSeek exploit chains, rogue agentic workflows, and unisolated operational technology are accelerating AI cybersecurity threats in 2026.

advanced persistent threats aptsAug 2, 20265 min

Stadler Rail Rejects $12.3M Extortion Attempt Amid AI Cybersecurity Threats

Swiss rail manufacturer Stadler Rail refused a $12.3M extortion demand from the Everest ransomware gang after a breach of a shared vendor data platform. Here is how network segmentation and zero-ransom policies defeated the attack.

advanced persistent threats aptsAug 2, 20263 min

AI Cybersecurity Threats 2026: Inside Russia's Shadow Fleet Drone Operations Near NATO Bases

An 18-month low-altitude drone campaign targeted NATO nuclear sharing sites and European airports using Russian shadow fleet vessels as offshore launchpads.

advanced persistent threats aptsAug 1, 20265 min

Adform Script Compromise: What Adtech Hijacks Reveal About AI Cybersecurity Threats in 2026

A stealthy supply-chain attack on adtech provider Adform hijacked tracking scripts to swipe crypto clipboard data, underscoring critical risks in third-party browser execution.

advanced persistent threats aptsAug 1, 20265 min

Browser-Based Evading C2: How Chaos Group's msaRAT Redefines AI Cybersecurity Threats

Chaos ransomware operators have deployed msaRAT, a Rust-based backdoor that hijacks headless Chrome and Edge sessions via Chrome DevTools Protocol. By abusing Cloudflare Workers, Twilio TURN servers, and dual-layer encryption, msaRAT completely hides command-and-control infrastructure within legitimate browser traffic.

advanced persistent threats aptsJul 31, 20265 min

How FBI's Operation Cronos Shattered LockBit Trust Amid Rising AI Cybersecurity Threats

An in-depth analysis of how the FBI's Operation Cronos shattered LockBit by targeting affiliate trust, and what the dismantling of Ransomware-as-a-Service trust models means for AI cybersecurity threats in 2026.

advanced persistent threats aptsJul 30, 20264 min

Trojanized Enterprise Tools and Blockchain C2: AI Cybersecurity Threats in 2026

A technical breakdown of threat actor UAT-11795 deploying Starland RAT, CastleStealer, and the in-memory WLDR agent via trojanized WebEx, Zoom, and developer tools.

advanced persistent threats aptsJul 29, 20266 min

ShinyHunters Claims Ernst & Young Breach: Supply-Chain Flaws in Modern AI Cybersecurity Threats

ShinyHunters extortion gang claims responsibility for the Ernst & Young data breach, alleging a supply-chain attack compromised third-party IT systems. The group threatens data release by July 31, 2026, though EY has not confirmed the claims.

advanced persistent threats aptsJul 26, 20263 min

The Distillation Dilemma: White House Accuses Moonshot AI of IP Theft

Investigating the White House's accusations against Moonshot AI regarding the alleged theft of Anthropic's model intelligence, and the broader implications for AI cybersecurity governance.