Silent Chollima: North Korea’s Dual-Track Cyber Weapon

Silent Chollima (APT45), also known as Onyx Sleet, is a North Korea–linked threat actor operating at the intersection of cyber espionage and financially motivated attacks. Active since 2013, the group targets healthcare, defense, critical infrastructure, and cryptocurrency organizations using credential theft, ransomware, and stealthy cloud-based persistence techniques.

OilRig: Iran’s Persistent Espionage Arm in Cyberspace

OilRig, also known as APT34 or Helix Kitten, is one of Iran’s most persistent cyber espionage groups. Active since 2014, the group targets energy, defense, and government organizations using spearphishing, cloud credential abuse, and long-term access operations across the Middle East and Europe.

Inside GALLIUM: China’s Expanding Telecom Espionage Apparatus

GALLIUM is a China state-sponsored advanced persistent threat group active since at least 2012, specializing in cyber espionage against telecommunications, government, and critical infrastructure. Recent campaigns across Africa, Southeast Asia, and Europe highlight its use of legitimate tools like SoftEther VPN and modular malware such as ShadowPad and PlugX.