A deep-dive into Operation ForumTroll, a high-risk Russia-aligned threat actor conducting espionage, phishing, and influence operations across Eastern Europe.
Category: Blog
PlushDaemon APT: An In-Depth Analysis of a Stealthy China-Aligned Cyber Espionage Group
PlushDaemon is a stealthy, China-aligned advanced persistent threat (APT) group focused on long-term cyber espionage. Active since the early 2010s, the group primarily targets government, defense, research, and technology organizations across Asia using low-noise persistence techniques and modular malware frameworks.
Smishing Triad: A Global Cybercrime Syndicate Targeting Postal and Financial Networks
The Smishing Triad is a high-risk, financially motivated cybercrime syndicate operating smishing-as-a-service campaigns since 2022. By impersonating postal, banking, and public service brands, the group targets consumers globally using SMS lures, OTP theft, and mobile malware.
Silent Chollima: North Korea’s Dual-Track Cyber Weapon
Silent Chollima (APT45), also known as Onyx Sleet, is a North Korea–linked threat actor operating at the intersection of cyber espionage and financially motivated attacks. Active since 2013, the group targets healthcare, defense, critical infrastructure, and cryptocurrency organizations using credential theft, ransomware, and stealthy cloud-based persistence techniques.
OldGremlin: A Stealthy Russian-Speaking Ransomware and Espionage Threat Group Evolving Into a Precision Striking APT
OldGremlin is a high-risk, Russian-speaking threat group operating since 2020 that blends APT-level stealth, long-term reconnaissance, and double-extortion ransomware. Its precision-driven campaigns pose significant risk to global enterprises across multiple sectors.
OilRig: Iran’s Persistent Espionage Arm in Cyberspace
OilRig, also known as APT34 or Helix Kitten, is one of Iran’s most persistent cyber espionage groups. Active since 2014, the group targets energy, defense, and government organizations using spearphishing, cloud credential abuse, and long-term access operations across the Middle East and Europe.
Callisto APT: Russia’s Persistent Espionage Operator
Callisto is a long-running Russia-linked APT group specializing in cyber espionage against NATO, EU, and government organizations. This analysis explores its identity, tactics, cloud-focused operations, and strategic impact.
Crafty Camel APT: Iran’s Expanding Espionage Footprint in the Modern Cyber Battlespace
Crafty Camel is an Iran-aligned advanced persistent threat leveraging spearphishing, cloud credential theft, and identity-centric attacks to conduct long-term cyber espionage. Active since 2017, the group targets government, defense, energy, and telecom organizations across the Middle East, Europe, and the US.
Angry Likho: Inside a Rapidly Growing Espionage Threat Targeting Eastern Europe
Angry Likho is a rapidly evolving pro-Russian cyber espionage group targeting Eastern European governments and defense organizations. This in-depth threat intelligence report analyzes its motivations, TTPs, infrastructure, and campaigns through 2025.
Inside GALLIUM: China’s Expanding Telecom Espionage Apparatus
GALLIUM is a China state-sponsored advanced persistent threat group active since at least 2012, specializing in cyber espionage against telecommunications, government, and critical infrastructure. Recent campaigns across Africa, Southeast Asia, and Europe highlight its use of legitimate tools like SoftEther VPN and modular malware such as ShadowPad and PlugX.