Active Threats

Explore the latest active threats being deployed by malicious actors as of 2026. Each report may offer attack flows, actionable detection rules, and simulation instructions to help SOC teams stay ahead of evolving adversary techniques.

22 Jul 2026 10:24

Behind the Refund: From GST Phishing to Remcos RAT Through a Multi-Stage .NET Infection Chain

SOC Prime Bias: High

source icon

Seqrite Labs

22 Jul 2026 10:09

Inside TAG-150’s Evolving Tradecraft with DinDoor, DenoRAT, and NightshadeC2

SOC Prime Bias: High

source icon

eSentire

20 Jul 2026 09:25

ACR Stealer: Two Observed Intrusion Chains During Increased Threat Activity

SOC Prime Bias: High

source icon

Microsoft Security Blog

20 Jul 2026 09:18

LABUBARAT: Rust-Based RAT Posing as NVIDIA Software

SOC Prime Bias: High

source icon

Blackpoint Cyber

17 Jul 2026 12:01

SharpViewStateKing and the Anatomy of a Stealthy Implant Framework

SOC Prime Bias: Critical

source icon

Canadian Centre for Cyber Security

16 Jul 2026 17:19

Six Minutes to Compromise: AI-Built C2 Botnet Deployed by Patriot Bait

SOC Prime Bias: High

source icon

Trend Micro

16 Jul 2026 17:05

Primary Compromise Vectors Used by UAC-0145 as of July 2026

SOC Prime Bias: Critical

source icon

cert.gov.ua

16 Jul 2026 16:59

Inside a Threat Hunting Case Study on Scattered Spider

SOC Prime Bias: High

source icon

intel471.com

16 Jul 2026 16:54

LegacyHive: The Windows User Profile Service Bug That Loads Another User’s Registry Hive Nightmare

SOC Prime Bias: Critical

source icon

core-jmp

16 Jul 2026 16:50

Tracking a DoNot (APT-C-35) Intrusion Against Bangladesh Military Personnel

SOC Prime Bias: Critical

source icon

cyderes.com