Threat Overview In a recent publication by AlienVault dated January 27, 2026, analysts identified a significant evolution in the threat landscape surrounding the HoneyMyte Advanced Persistent Threat (APT) group. The report details how HoneyMyte has upgraded
Continue ReadingAuthor: Tudorel Iancu
Watering Hole Attack Hits EmEditor Users With Data Theft Malware
Threat Overview In late December 2025, security researchers uncovered a sophisticated watering‑hole campaign that targeted users of the popular text editor EmEditor. The adversary compromised the official installer distribution, inserting a multi‑stage malware payload that performs
Continue ReadingSandworm Attack on Poland Power Grid 2025
Threat Overview In late 2025, Poland’s energy system endured what analysts are calling the country’s largest cyberattack in recent memory. The assault, which unfolded during the final week of December, targeted critical power infrastructure and was
Continue ReadingFortiGate Devices Under Attack Unauthorized Configuration Changes via SSO Accounts
Threat Overview In a recent publication dated 2026-01-22, security researchers from AlienVault identified a sophisticated wave of automated malicious activity targeting Fortinet FortiGate firewalls. The attackers exploit Single Sign-On (SSO) mechanisms to gain foothold and then
Continue ReadingPurpleBravo Targeting IT Software Supply Chain
Threat Overview In a recent publication dated 2026-01-21, security researchers from AlienVault have identified a sophisticated threat actor known as PurpleBravo, a North Korean state-sponsored group that has been targeting software developers through deceptive recruitment campaigns.
Continue ReadingCommand Evade Turla Kazuar Loader
Command Evade Turla Kazuar Loader The Turla group, a long‑standing threat actor with a history of sophisticated operations, has recently deployed a new loader that demonstrates advanced evasion techniques. The loader, which we refer to as
Continue ReadingFake Shipping Document Drives New Remcos Attack
Threat Overview On 19 January 2026, AlienVault released a detailed threat report titled 'New Remcos Campaign Distributed Through Fake Shipping Document'. The report describes a phishing operation that delivers a fileless variant of the Remcos RAT,
Continue ReadingNorth American Critical Infrastructure Targeted by Advanced Threat Actor
Threat Overview On 2026-01-16 AlienVault released a new threat report titled Targets critical infrastructure sectors in North America (UAT-8837). The report identifies a China‑nexus advanced persistent threat (APT) actor that has been actively targeting critical infrastructure
Continue ReadingDiscord Clipboard Hijacking Malware Targeting Crypto Communities
Threat Overview On January 15, 2026, AlienVault released a comprehensive threat report titled HUMINT Operations Uncover Cryptojacking Campaign: Discord-Based Distribution of Clipboard Hijacking Malware Targeting Cryptocurrency Communities. The report details a sophisticated operation carried out by
Continue ReadingShadow Reactor Text Only Staging Net Reactor In Memory Remcos RAT Deployments
Shadow Reactor is a sophisticated multi‑stage Windows malware campaign that first surfaced in a threat report published by AlienVault on 13 January 2026. The campaign demonstrates a complex infection chain that relies on obfuscated VBS scripts,
Continue Reading