Advanced Persistent Threats (APTs)
Articles on nation-state and highly sophisticated cyber threat groups, including APT28, Kimsuky, MuddyWater, and their tactics, techniques, and infrastructure.
AI & Cybersecurity Threats: How CrashStealer Uses macOS Trust to Steal Your Wallets
CrashStealer exploits macOS’s built-in trust in system tools to steal crypto wallets and credentials—using Apple’s own infrastructure against users.
HollowGraph Turns Microsoft 365 Calendars Into a Dead-Drop C2 Channel
A new malware component called HollowGraph hijacks Microsoft 365 calendar events as a covert command-and-control channel, using hybrid RSA-AES encryption and DNS tunneling for credential refresh — a technique that exposes how artificial intelligence cybersecurity threats are evolving toward trusted-infrastructure abuse.
How msaRAT Hides Its C2 Traffic Inside Your Browser — And Why AI Cybersecurity Threats Just Got Harder
The Chaos ransomware gang's new msaRAT backdoor routes all command-and-control traffic through headless Chrome and Edge browsers, making it nearly invisible to traditional network monitoring.
Operation Olympus Blade: How Germany and the U.S. Brought Down the Kratos Phishing Empire
German and U.S. authorities dismantled Kratos, a phishing-as-a-service platform used by 1,800+ criminal customers to run 15,000 campaigns per month across 35 countries. More than 200 servers were seized and the developer arrested in Indonesia under Operation Olympus Blade.
How Russia’s APT28 Weaponized ClickFix to Bypass AI Cybersecurity Defenses
Russia’s APT28 group has evolved ClickFix from a social engineering trick into an API-driven attack that bypasses traditional EDR and AMSI protections — turning human trust into a persistent foothold in Ukrainian critical infrastructure.