TraderTraitor—also known as Jade Sleet and UNC4899—is one of North Korea’s most aggressive financial APT groups. Responsible for major crypto thefts, including the $1.5B ByBit hack, it targets blockchain developers, exchanges, and fintech firms worldwide.
Category: Blog
Handala: The Rise of a Decentralized Pro-Palestinian Hacktivist Collective
Handala is a pro-Palestinian hacktivist collective active since 2022, conducting defacements, DDoS attacks, and politically motivated data leaks targeting Israeli, U.S., and Western entities during regional conflicts.
Moonlight Tiger (APT-C-09, Patchwork, Dropping Elephant): India’s Silent Espionage Arm in the Digital Battlefield
Moonlight Tiger (APT-C-09) is a long-running India-linked cyber-espionage group conducting spearphishing, modular malware campaigns, and intelligence-gathering operations across South and East Asia. Targeting government, defense, academic, and foreign policy institutions, the group continues to evolve through living-off-the-land techniques, custom backdoors, and cloud-enabled C2 infrastructure.
Inside WageMole: North Korea’s Fusion of Cybercrime and Espionage
WageMole is a North Korean APT active since 2018, operating at the intersection of cyber-espionage and financial theft. The group targets cryptocurrency, fintech, and defense sectors using fake recruiters, supply-chain attacks, and AI-enhanced phishing. Learn how this hybrid threat operates.
Inside Void Manticore: Iran’s Hybrid Hacktivist for Information Warfare
Void Manticore is an Iran-aligned APT group conducting hybrid cyber operations, destructive wiper attacks, and politically motivated leak campaigns targeting Israel, NATO members, NGOs, and critical infrastructure sectors.
Sandworm (APT44): Russia’s Most Destructive Cyber Weapon
Sandworm (APT44) is Russia’s most destructive state-sponsored cyber unit. Known for NotPetya, Industroyer, and AcidPour, the group targets critical infrastructure across Ukraine, NATO states, and Europe, combining cyber sabotage with military objectives.
APT37: North Korea’s Active Cyberespionage Group in 2025
APT37 (Famous Chollima) remains one of North Korea’s most active and adaptive cyberespionage groups. This analysis highlights their 2025 evolution—cloud persistence, AI-driven social engineering, new RAT variants, and global targeting across governments, defense, research, and policy organizations.
Geopolitical Countdown: The Evolution of Cyberspace from Espionage to Destruction and New Strategies for Corporate Resilience
This Geopolitical Countdown analysis reveals how the 2025 cybercrime ecosystem is evolving. From Initial Access Brokers to leaked credentials, MaaS/RaaS platforms, and cloud-targeting exploit kits, this report explores the dark web’s most traded assets and what they mean for enterprise cyber risk.
APT42: Iran’s Shadow Operative in Global Cyberspace
SilverFox APT is rapidly evolving into one of 2025’s most dangerous cyber threat actors. Combining espionage with financial motives, it exploits edge devices, cloud identities, and supply chains to infiltrate governments and enterprises worldwide.
MuddyWater: Iran-Linked Espionage Group Expanding Global Reach
SilverFox APT is rapidly evolving into one of 2025’s most dangerous cyber threat actors. Combining espionage with financial motives, it exploits edge devices, cloud identities, and supply chains to infiltrate governments and enterprises worldwide.