Back to Blog

Threat Intelligence

7 articles on this topic.

Threat Intelligence4 September 2026

A Fake DeFi Startup Exposed How North Korean IT Workers Get Hired

Researchers built a shell company, ran a full hiring pipeline, and let sandboxed 'employees' walk straight into a monitored environment — capturing the tooling behind DPRK employment fraud in granular detail.

dprk-it-workersinsider-threatthreat-intelligence
4 min readRead
Threat Intelligence1 September 2026

Bauman University Leak Exposes Russia's GRU Cyber-Operator Pipeline

A roughly 1.8GB leak from a covert department at Bauman Moscow State Technical University details how the GRU recruits, vets, and routes students into units linked to APT28 and Sandworm.

threat-intelligencegrusandworm
4 min readRead
AI Security27 August 2026

OpenAI Disrupts Cambodia-Based ChatGPT Scam Network — What It Reveals

OpenAI banned accounts tied to a Cambodia-based crime network that used ChatGPT to run romance, crypto, gambling, and impersonation scams simultaneously — and to manage forced-labor recruitment behind the operation.

ai securitysocial engineeringgenai abuse
4 min readRead
AI Security26 August 2026

Unit 42's AI Malware Reality Check: 97% Never Left the Sandbox

Palo Alto Networks' Unit 42 analysed 405 AI-touched malware samples and found almost all of them were proof-of-concept or researcher submissions — but the handful that reached real endpoints show where the trend is actually heading.

ai-securitymalwarethreat-intelligence
5 min readRead
Threat Intelligence19 August 2026

MacSync Stealer: Microsoft Traces macOS Malware Through 30+ Rotating Domains

Microsoft Defender Experts mapped MacSync Stealer's infrastructure not by blocklisting domains, but by fingerprinting the behavior behind them — a lesson for anyone still treating IOC feeds as a detection strategy.

macos-securityinfostealerthreat-intelligence
4 min readRead
Threat Intelligence27 July 2026

Dysphoria Botnet Moves C2 to Ethereum and Solana Name Services

After a March law-enforcement takedown of JackSkid infrastructure, the same IoT-botnet operator rebuilt around blockchain name records and infected-device relays — a design built to survive the next seizure.

iot-securitybotnetblockchain-c2
4 min readRead
Phishing & Fraud26 July 2026

Insurance Phishing Goes Real-Time: Inside the InsureOTP Kit

CTM360 has uncovered a phishing framework that no longer waits to cash in stolen logins — it hijacks insurance accounts live, relaying intercepted OTPs before they expire.

phishingaccount-takeoverotp-interception
4 min readRead