A massive Komiko AI data breach exposed over 1 million users, including OAuth tokens and session data—creating critical account takeover risks. Here’s what happened and how Brandefense detected it early.
Category: Blog
Konni (Vedalia / TA406 / Opal Sleet): North Korea’s Steady Hand in Espionage Operations
Konni is a North Korea-aligned APT group focused on long-term cyber espionage through spearphishing, credential harvesting, and lightweight malware campaigns.
Warlock Group: The Rise of GOLD SALEM (Storm-2603) in 2025’s Ransomware Landscape
Warlock Group (GOLD SALEM / Storm-2603) is an emerging ransomware actor exploiting SharePoint ToolShell vulnerabilities to target global enterprises with double extortion tactics.
DarkHotel (APT-C-06 / ATK52 / DUBNIUM): The Global Espionage Network Behind Elite Cyber Intrusions
DarkHotel is a South Korea-linked APT group known for evolving from hotel Wi-Fi attacks to sophisticated supply chain and cloud-based espionage operations.
Kasablanka: The Emerging North African Cyber Threat Actor
Kasablanka is an emerging cyber threat actor suspected to originate from North Africa. Active since 2021, the group evolved from hacktivism to phishing-driven espionage campaigns targeting governments, energy companies, and media organizations across Europe and the Middle East.
Looking at Your Company Through the Eyes of an Attacker: What Is an Attacker’s-Eye View?
What does your organization look like from the outside? An Attacker’s-Eye View reveals exposed assets, forgotten subdomains, misconfigurations, and threat intelligence signals attackers exploit first.
Turla APT: Russia’s Longstanding Cyber Espionage Powerhouse
Turla is one of the most sophisticated Russian APT groups linked to the FSB. Active since the early 2000s, it conducts long-term cyber espionage campaigns using advanced malware such as Snake, Carbon, and Kazuar against NATO, government, and diplomatic targets.
APT19 (DEEP PANDA): A Persistent China-Aligned Espionage and Credential Theft Actor
APT19 (Deep Panda) is a China-aligned advanced persistent threat group focused on credential harvesting, phishing campaigns, and long-term espionage operations targeting government, telecom, and technology organizations worldwide.
HAFNIUM APT Group (Silk Typhoon): Exploiting the Global Attack Surface for Strategic Espionage
HAFNIUM (Silk Typhoon) is a China-aligned cyber espionage group known for exploiting internet-facing enterprise infrastructure, including the large-scale Microsoft Exchange attacks that impacted organizations worldwide.
Tick APT Group (BRONZE BUTLER): A Long-Running East Asian Cyber Espionage Actor
Tick (Bronze Butler) is a long-running China-aligned APT group known for stealthy cyber espionage campaigns targeting government, defense, and technology sectors in East Asia.