FIN11 is a globally active, financially motivated cybercrime group known for large-scale phishing campaigns, malware distribution, and ransomware ecosystem enablement.
Category: Blog
From Shadow IT to Shadow AI: Clawdbot (Moltbot/Openclaw) and the Rise of Unmanaged Agent Gateways
Shadow AI is emerging as the next evolution of Shadow IT. This analysis reveals how misconfigured Clawdbot agent gateways expose LLM keys, corporate data, and integration tokens—creating a silent but critical attack surface.
APT35: Iran’s Persistent Cyber Espionage Force
APT35, also known as Charming Kitten, is an Iranian state-linked cyber espionage group active since 2011, conducting phishing, credential theft, and influence operations against political, academic, media, and NGO targets worldwide.
APT15 (Ke3Chang / Nylon Typhoon): China-Aligned Cyber Espionage APT
APT15 is a long-running, China-aligned cyber espionage group linked to the MSS, targeting governments, defense organizations, NGOs, and technology sectors globally with sustained operations through 2025.
TA577 (Hive0118): The Evolving Phishing Specialist Behind Modern Malware Campaigns
TA577 (Hive0118) is a financially motivated, Russian-speaking cybercrime group active since 2020, specializing in large-scale phishing, credential theft, and NTLM hash capture, with strong links to ransomware operations such as Black Basta.
VanHelsing: Inside the Rise of a Multi‑Platform RaaS Threat Actor
RomCom, also known as Void Rabisu or Storm-0978, is a Russia-aligned advanced persistent threat active since 2022. The group is known for combining espionage-driven operations with opportunistic financial activity, leveraging zero-day exploits, sophisticated phishing infrastructure, and stealthy malware to target NATO-aligned governments and defense sectors.
WIZARD SPIDER: The Financial Empire Behind Global Ransomware Operations
RomCom, also known as Void Rabisu or Storm-0978, is a Russia-aligned advanced persistent threat active since 2022. The group is known for combining espionage-driven operations with opportunistic financial activity, leveraging zero-day exploits, sophisticated phishing infrastructure, and stealthy malware to target NATO-aligned governments and defense sectors.
APT40
APT40 is a China-aligned advanced persistent threat (APT) group known for long-term cyber espionage campaigns targeting maritime, defense, academic, and government organizations, particularly across the Indo-Pacific region.
RomCom APT
RomCom, also known as Void Rabisu or Storm-0978, is a Russia-aligned advanced persistent threat active since 2022. The group is known for combining espionage-driven operations with opportunistic financial activity, leveraging zero-day exploits, sophisticated phishing infrastructure, and stealthy malware to target NATO-aligned governments and defense sectors.
Inside the Operations of Cactus: The Rise of a Stealth-Focused Ransomware Threat
Cactus is a financially motivated ransomware group leveraging VPN vulnerabilities, encrypted tunneling, and double extortion tactics to target enterprises across the US, UK, and Europe.