APT19 (Deep Panda) is a China-aligned advanced persistent threat group focused on credential harvesting, phishing campaigns, and long-term espionage operations targeting government, telecom, and technology organizations worldwide.
Category: Blog
BlackTech
BlackTech is a China-aligned APT group specializing in long-term cyber espionage through network infrastructure compromise, targeting telecom, government, and tech sectors.
When AI Fights Back: How Attackers Are Using Agentic AI Against Your Organization
A massive Komiko AI data breach exposed over 1 million users, including OAuth tokens and session data—creating critical account takeover risks. Here’s what happened and how Brandefense detected it early.
UAC-0194: Inside a Rapidly Evolving NTLM-Exploiting Espionage Operation
UAC-0194 is a high-risk, Russian-affiliated threat actor leveraging NTLM vulnerabilities for stealthy credential theft and cyber espionage across Eastern Europe.
What Is Credential Stuffing? Attackers Don’t Crack Passwords, They Buy Them
A massive Komiko AI data breach exposed over 1 million users, including OAuth tokens and session data—creating critical account takeover risks. Here’s what happened and how Brandefense detected it early.
What Is Triple Extortion? The Anatomy of the Encryption + Leakage + DDoS Trio
Triple extortion ransomware is reshaping cyber threats. Discover how attackers operate and how to detect threats before encryption begins.
MFA Doesn’t Protect You — Cookies Give You Away: The Rise of Session Hijacking
Session hijacking allows attackers to bypass MFA by stealing authentication cookies. Discover how it works and how to detect stolen session tokens before exploitation.
Fake Mobile App: How Is Your Clone on the App Store Stealing Your Users?
Fake mobile apps replicate your brand to steal user credentials, financial data, and trust. Discover how attackers build, distribute, and monetize clone apps—and how to stop them early.
UAC-0102: Inside a Covert Espionage Operation Targeting Ukraine and Beyond
UAC-0102 is a stealth-focused cyber espionage group targeting Ukrainian government and infrastructure entities using spearphishing and cloud-based C2 techniques.
Inside the Operations of Crazy Evil: The Rise of a Global Crypto-Focused Cybercrime Network
An in-depth analysis of Crazy Evil, a financially motivated cybercrime group targeting Web3, crypto platforms, and digital identities through advanced social engineering and malware campaigns.