Active Threats

Explore the latest active threats being deployed by malicious actors as of Q4 2025. Each report may offer attack flows, actionable detection rules, and simulation instructions to help SOC teams stay ahead of evolving adversary techniques.

02 Dec 2025 20:53

DIRTYBULK and Friends: USB Malware Fuelling Coinmining Ops

SOC Prime Bias: Medium

source icon

googlecloudcommunity.com

02 Dec 2025 18:54

Operation Hanoi Thief: Threat Actor Hits Vietnamese IT and Hiring Teams

SOC Prime Bias: Critical

source icon

Information Technology

01 Dec 2025 20:34

AWS GuardDuty Detector Disabled/Suspended – Threat Detection Rule Weekly #11-2025

SOC Prime Bias: Medium

source icon

suKTech24

01 Dec 2025 17:35

Play Ransomware Masquerades as SentinelOne in Grixba Recon Campaign

SOC Prime Bias: High

source icon

fieldeffectsoft

28 Nov 2025 18:53

Shai-Hulud: Widespread npm Supply Chain Attack

SOC Prime Bias: Critical

source icon

about.gitlab.com

27 Nov 2025 19:23

DripLoader Malware: Shellcode Execution and Defense Evasion

SOC Prime Bias: Medium

source icon

coreycburton.com

27 Nov 2025 19:10

Zscaler Threat Hunting Exposes and Reconstructs the Water Gamayun APT Campaign

SOC Prime Bias: Critical

source icon

The Hidden

26 Nov 2025 17:30

Funklocker Ransomware: Detecting and Responding with Wazuh

SOC Prime Bias: High

source icon

Wazuh

26 Nov 2025 17:14

CVE-2025-61757: Oracle Identity Manager Exploit Activity Observed in September

SOC Prime Bias: Critical

source icon

SANS Internet Storm Center

25 Nov 2025 18:38

DarkGate Under the Hood

SOC Prime Bias: Medium

source icon

Sekoia.io