<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:googleplay="http://www.google.com/schemas/play-podcasts/1.0"><channel><title><![CDATA[CyberMaterial: Threats]]></title><description><![CDATA[A threat actor in cybersecurity is any individual, group, or organization that intentionally exploits vulnerabilities, conducts malicious activities, or engages in cyberattacks with the goal of compromising information systems, networks, or data.]]></description><link>https://www.cybermaterial.com/s/threats</link><image><url>https://substackcdn.com/image/fetch/$s_!nNgF!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa6c57d21-5644-4f88-bf07-ea44d2603e80_482x482.png</url><title>CyberMaterial: Threats</title><link>https://www.cybermaterial.com/s/threats</link></image><generator>Substack</generator><lastBuildDate>Fri, 19 Jun 2026 18:12:23 GMT</lastBuildDate><atom:link href="https://www.cybermaterial.com/feed" rel="self" type="application/rss+xml"/><copyright><![CDATA[CyberMaterial]]></copyright><language><![CDATA[en]]></language><webMaster><![CDATA[cybermaterial@substack.com]]></webMaster><itunes:owner><itunes:email><![CDATA[cybermaterial@substack.com]]></itunes:email><itunes:name><![CDATA[CyberMaterial]]></itunes:name></itunes:owner><itunes:author><![CDATA[CyberMaterial]]></itunes:author><googleplay:owner><![CDATA[cybermaterial@substack.com]]></googleplay:owner><googleplay:email><![CDATA[cybermaterial@substack.com]]></googleplay:email><googleplay:author><![CDATA[CyberMaterial]]></googleplay:author><itunes:block><![CDATA[Yes]]></itunes:block><item><title><![CDATA[DarkSpectre]]></title><description><![CDATA[Hidden in Plain Sight: How the DarkSpectre Malware Campaign Weaponized Our Browsers]]></description><link>https://www.cybermaterial.com/p/darkspectre</link><guid isPermaLink="false">https://www.cybermaterial.com/p/darkspectre</guid><dc:creator><![CDATA[CyberMaterial]]></dc:creator><pubDate>Sat, 13 Jun 2026 14:01:16 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!TKpC!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff95215fc-572b-468d-9e28-368155c223ab_1536x1024.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!TKpC!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff95215fc-572b-468d-9e28-368155c223ab_1536x1024.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!TKpC!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff95215fc-572b-468d-9e28-368155c223ab_1536x1024.png 424w, https://substackcdn.com/image/fetch/$s_!TKpC!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff95215fc-572b-468d-9e28-368155c223ab_1536x1024.png 848w, https://substackcdn.com/image/fetch/$s_!TKpC!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff95215fc-572b-468d-9e28-368155c223ab_1536x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!TKpC!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff95215fc-572b-468d-9e28-368155c223ab_1536x1024.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!TKpC!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff95215fc-572b-468d-9e28-368155c223ab_1536x1024.png" width="1456" height="971" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/f95215fc-572b-468d-9e28-368155c223ab_1536x1024.png&quot;,&quot;srcNoWatermark&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/00abb2a1-276a-4172-8fed-f18dbb1c32e8_1536x1024.png&quot;,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:971,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:404389,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.cybermaterial.com/i/201459551?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F00abb2a1-276a-4172-8fed-f18dbb1c32e8_1536x1024.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!TKpC!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff95215fc-572b-468d-9e28-368155c223ab_1536x1024.png 424w, https://substackcdn.com/image/fetch/$s_!TKpC!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff95215fc-572b-468d-9e28-368155c223ab_1536x1024.png 848w, https://substackcdn.com/image/fetch/$s_!TKpC!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff95215fc-572b-468d-9e28-368155c223ab_1536x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!TKpC!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff95215fc-572b-468d-9e28-368155c223ab_1536x1024.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2></h2><p>When we think about cyber threats affecting everyday internet users, our minds usually jump to dramatic scenarios: a panicked click on a sketchy phishing email, or a sudden ransomware screen locking down a hard drive.</p><p>But some of the most insidius cyber operations don&#8217;t rely on flashy malware files at all. Instead, they hitch a ride on the tools we already use and trust.</p><p>Enter <strong>DarkSpectre</strong>&#8212;a highly sophisticated threat actor behind a massive browser extension malware operation that quietly infected an estimated <strong>8.8 million users</strong> worldwide. </p><p>Spanning across Google Chrome, Microsoft Edge, Mozilla Firefox, and Opera, DarkSpectre highlights a dangerous reality: the simple add-ons we use to customize our web experience can easily be turned into powerful cyber weapons.</p><div><hr></div><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.cybermaterial.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">This Substack is reader-supported. To receive new posts and support our  work, consider becoming a free or paid subscriber.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><div><hr></div><p></p><h2>The Perfect Hiding Place: Abusing Browser Trust</h2><p>At its core, DarkSpectre capitalizes on a universal habit: downloading browser extensions for extra convenience. Whether it&#8217;s a custom new-tab page, a video downloader, a translation widget, or a productivity tool, millions of us install these mini-programs without a second thought.</p><p>What makes DarkSpectre uniquely dangerous is its patience and strategic planning. Security researchers at <strong>Koi Security</strong> discovered that the threat actor didn&#8217;t just launch sudden attacks; they maintained dozens of seemingly legitimate extensions for years.</p><h3>The &#8220;Sleeper Agent&#8221; Method</h3><ol><li><p><strong>The Clean Entry:</strong> The extensions were uploaded to official marketplaces with clean, harmless code. They passed automated security reviews, earned positive user ratings, and built up a massive install base.</p></li><li><p><strong>The Delayed Trigger:</strong> Once safely nestled inside millions of browsers, the extensions &#8220;flipped&#8221; to malicious mode. This was done using timed delays or specific server-side triggers.</p></li><li><p><strong>Evading Vetting:</strong> Because the initial behavior looked completely benign, standard marketplace vetting failed to flag them, allowing the malware to operate undetected for years.</p></li></ol><div><hr></div><p><strong>Watch Summary Video Below: &#11015;&#65039;</strong></p>
      <p>
          <a href="https://www.cybermaterial.com/p/darkspectre">
              Read more
          </a>
      </p>
   ]]></content:encoded></item><item><title><![CDATA[SolarMarker / SOVA Malware]]></title><description><![CDATA[SolarMarker (also associated with SOVA) is a sophisticated information-stealing malware designed to harvest credentials, browser data, and sensitive files.]]></description><link>https://www.cybermaterial.com/p/solarmarker-sova-malware</link><guid isPermaLink="false">https://www.cybermaterial.com/p/solarmarker-sova-malware</guid><dc:creator><![CDATA[CyberMaterial]]></dc:creator><pubDate>Sat, 06 Jun 2026 14:02:05 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!elZ_!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0d12ba37-f4fa-4bd1-93f2-d2a0b73a1cc4_1920x1080.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!elZ_!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0d12ba37-f4fa-4bd1-93f2-d2a0b73a1cc4_1920x1080.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!elZ_!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0d12ba37-f4fa-4bd1-93f2-d2a0b73a1cc4_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!elZ_!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0d12ba37-f4fa-4bd1-93f2-d2a0b73a1cc4_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!elZ_!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0d12ba37-f4fa-4bd1-93f2-d2a0b73a1cc4_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!elZ_!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0d12ba37-f4fa-4bd1-93f2-d2a0b73a1cc4_1920x1080.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!elZ_!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0d12ba37-f4fa-4bd1-93f2-d2a0b73a1cc4_1920x1080.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/0d12ba37-f4fa-4bd1-93f2-d2a0b73a1cc4_1920x1080.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:520935,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.cybermaterial.com/i/200298619?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0d12ba37-f4fa-4bd1-93f2-d2a0b73a1cc4_1920x1080.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!elZ_!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0d12ba37-f4fa-4bd1-93f2-d2a0b73a1cc4_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!elZ_!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0d12ba37-f4fa-4bd1-93f2-d2a0b73a1cc4_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!elZ_!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0d12ba37-f4fa-4bd1-93f2-d2a0b73a1cc4_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!elZ_!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0d12ba37-f4fa-4bd1-93f2-d2a0b73a1cc4_1920x1080.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p><h2><strong>SolarMarker / SOVA Malware</strong><br><br><strong>What it is:</strong></h2><p><br>SolarMarker (also associated with SOVA) is a sophisticated information-stealing malware designed to harvest credentials, browser data, and sensitive files. It&#8217;s built for stealth, persistence, and large-scale data exfiltration, often used in follow-on attacks like account takeover or ransomware.</p><h2><br>Real-world cases &amp; campaigns:</h2><p><strong>SEO poisoning at scale:</strong> </p><p>Since at least 2020, SolarMarker operators have used <em>SEO poisoning</em> to push malicious sites to the top of search results, tricking users searching for everyday tools and documents into downloading infected installers.</p><p><br><strong>Fake job platforms (Indeed impersonation): </strong></p><p>In 2026, attackers impersonated job sites like Indeed, luring victims into downloading malicious files that installed SolarMarker alongside additional payloads.</p><p><br><strong>Enterprise &amp; education targeting: </strong></p><p>Organizations such as school districts have been compromised, with SolarMarker detected exfiltrating data over long periods before discovery.</p><p><br><strong>Fake software &amp; browser updates: </strong></p><p>Users have been tricked into downloading trojanized installers or fake Chrome updates, leading to full system compromise.</p><p><br><strong>Persistence in the wild:</strong> </p><p>Security firms have documented infections maintaining long-term access via startup mechanisms and hidden PowerShell execution, making detection difficult.</p><div><hr></div><p><strong>Watch Summary Video Below: &#11015;&#65039;</strong></p><p></p>
      <p>
          <a href="https://www.cybermaterial.com/p/solarmarker-sova-malware">
              Read more
          </a>
      </p>
   ]]></content:encoded></item><item><title><![CDATA[ Silent Ransom Group]]></title><description><![CDATA[The Rise of Human-Driven Extortion: How Silent Ransom Group Is Changing Cyberattacks]]></description><link>https://www.cybermaterial.com/p/silent-ransom-group</link><guid isPermaLink="false">https://www.cybermaterial.com/p/silent-ransom-group</guid><dc:creator><![CDATA[CyberMaterial]]></dc:creator><pubDate>Sat, 30 May 2026 15:01:58 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!7ACN!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5d39ab55-3b03-4ee7-9fbf-fd03cf390dbf_1536x1024.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!7ACN!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5d39ab55-3b03-4ee7-9fbf-fd03cf390dbf_1536x1024.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!7ACN!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5d39ab55-3b03-4ee7-9fbf-fd03cf390dbf_1536x1024.png 424w, https://substackcdn.com/image/fetch/$s_!7ACN!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5d39ab55-3b03-4ee7-9fbf-fd03cf390dbf_1536x1024.png 848w, https://substackcdn.com/image/fetch/$s_!7ACN!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5d39ab55-3b03-4ee7-9fbf-fd03cf390dbf_1536x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!7ACN!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5d39ab55-3b03-4ee7-9fbf-fd03cf390dbf_1536x1024.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!7ACN!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5d39ab55-3b03-4ee7-9fbf-fd03cf390dbf_1536x1024.png" width="1456" height="971" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/5d39ab55-3b03-4ee7-9fbf-fd03cf390dbf_1536x1024.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:971,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1312068,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.cybermaterial.com/i/199737202?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5d39ab55-3b03-4ee7-9fbf-fd03cf390dbf_1536x1024.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!7ACN!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5d39ab55-3b03-4ee7-9fbf-fd03cf390dbf_1536x1024.png 424w, https://substackcdn.com/image/fetch/$s_!7ACN!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5d39ab55-3b03-4ee7-9fbf-fd03cf390dbf_1536x1024.png 848w, https://substackcdn.com/image/fetch/$s_!7ACN!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5d39ab55-3b03-4ee7-9fbf-fd03cf390dbf_1536x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!7ACN!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5d39ab55-3b03-4ee7-9fbf-fd03cf390dbf_1536x1024.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p><p>For years, ransomware attacks followed a familiar pattern:</p><p>Hackers breached a network, deployed malware, encrypted systems, and demanded payment for a decryption key.</p><p>But what&#8217;s happening now is different &#8212; and arguably more dangerous.</p><p>A threat actor known as Silent Ransom Group (also tracked as Luna Moth, Chatty Spider, and UNC3753) is targeting US law firms using almost no malware at all.</p><p>Instead of relying on technical exploits, they rely on something much easier to manipulate:</p><p>People.</p><h2>The New Ransomware Model</h2><p>This group doesn&#8217;t need to break through firewalls or deploy sophisticated ransomware payloads. They simply convince employees to let them in.</p><p>The attack often begins with a phishing email or a phone call impersonating internal IT support. The attacker claims there&#8217;s suspicious activity on the employee&#8217;s machine and says remote access is needed to resolve the issue.</p><p>The goal is simple: gain trust.</p><div><hr></div><h3><strong>Watch Summary Video Below: &#11015;&#65039;</strong></h3><h3></h3>
      <p>
          <a href="https://www.cybermaterial.com/p/silent-ransom-group">
              Read more
          </a>
      </p>
   ]]></content:encoded></item><item><title><![CDATA[GoldPickaxe]]></title><description><![CDATA[The Mobile Malware That Doesn&#8217;t Just Steal Passwords, It Steals You]]></description><link>https://www.cybermaterial.com/p/goldpickaxe</link><guid isPermaLink="false">https://www.cybermaterial.com/p/goldpickaxe</guid><dc:creator><![CDATA[CyberMaterial]]></dc:creator><pubDate>Sat, 02 May 2026 14:01:48 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!k_aH!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F87dd8e56-dc33-4d01-8055-511ede01b99b_948x630.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!k_aH!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F87dd8e56-dc33-4d01-8055-511ede01b99b_948x630.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!k_aH!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F87dd8e56-dc33-4d01-8055-511ede01b99b_948x630.jpeg 424w, https://substackcdn.com/image/fetch/$s_!k_aH!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F87dd8e56-dc33-4d01-8055-511ede01b99b_948x630.jpeg 848w, https://substackcdn.com/image/fetch/$s_!k_aH!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F87dd8e56-dc33-4d01-8055-511ede01b99b_948x630.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!k_aH!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F87dd8e56-dc33-4d01-8055-511ede01b99b_948x630.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!k_aH!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F87dd8e56-dc33-4d01-8055-511ede01b99b_948x630.jpeg" width="948" height="630" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/87dd8e56-dc33-4d01-8055-511ede01b99b_948x630.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:630,&quot;width&quot;:948,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:117664,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.cybermaterial.com/i/195866647?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F87dd8e56-dc33-4d01-8055-511ede01b99b_948x630.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!k_aH!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F87dd8e56-dc33-4d01-8055-511ede01b99b_948x630.jpeg 424w, https://substackcdn.com/image/fetch/$s_!k_aH!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F87dd8e56-dc33-4d01-8055-511ede01b99b_948x630.jpeg 848w, https://substackcdn.com/image/fetch/$s_!k_aH!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F87dd8e56-dc33-4d01-8055-511ede01b99b_948x630.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!k_aH!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F87dd8e56-dc33-4d01-8055-511ede01b99b_948x630.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Most people think mobile malware is about stolen passwords, banking logins, or credit card details.</p><p>But GoldPickaxe changed that.</p><p>This is one of the more dangerous mobile malware campaigns to emerge in recent years because it doesn&#8217;t stop at account access, it targets identity itself.</p><p>And that changes everything.</p><div><hr></div><h3><strong>Watch Summary Video Below: &#11015;&#65039;</strong></h3><h3></h3>
      <p>
          <a href="https://www.cybermaterial.com/p/goldpickaxe">
              Read more
          </a>
      </p>
   ]]></content:encoded></item><item><title><![CDATA[Smishing Triad]]></title><description><![CDATA[The Smishing Triad is a cybercrime organization known for conducting large-scale SMS phishing (smishing) campaigns targeting mobile users worldwide.]]></description><link>https://www.cybermaterial.com/p/smishing-triad</link><guid isPermaLink="false">https://www.cybermaterial.com/p/smishing-triad</guid><dc:creator><![CDATA[CyberMaterial]]></dc:creator><pubDate>Mon, 20 Apr 2026 21:00:44 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!Iuwa!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1590522f-d429-41bc-a514-5033a327e3fc_1305x855.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Iuwa!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1590522f-d429-41bc-a514-5033a327e3fc_1305x855.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Iuwa!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1590522f-d429-41bc-a514-5033a327e3fc_1305x855.jpeg 424w, https://substackcdn.com/image/fetch/$s_!Iuwa!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1590522f-d429-41bc-a514-5033a327e3fc_1305x855.jpeg 848w, https://substackcdn.com/image/fetch/$s_!Iuwa!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1590522f-d429-41bc-a514-5033a327e3fc_1305x855.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!Iuwa!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1590522f-d429-41bc-a514-5033a327e3fc_1305x855.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Iuwa!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1590522f-d429-41bc-a514-5033a327e3fc_1305x855.jpeg" width="1305" height="855" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/1590522f-d429-41bc-a514-5033a327e3fc_1305x855.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:855,&quot;width&quot;:1305,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:121500,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.cybermaterial.com/i/194794156?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1590522f-d429-41bc-a514-5033a327e3fc_1305x855.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Iuwa!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1590522f-d429-41bc-a514-5033a327e3fc_1305x855.jpeg 424w, https://substackcdn.com/image/fetch/$s_!Iuwa!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1590522f-d429-41bc-a514-5033a327e3fc_1305x855.jpeg 848w, https://substackcdn.com/image/fetch/$s_!Iuwa!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1590522f-d429-41bc-a514-5033a327e3fc_1305x855.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!Iuwa!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1590522f-d429-41bc-a514-5033a327e3fc_1305x855.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p><div><hr></div><p><strong>Key facts</strong></p><ul><li><p><strong>    Threat type: SMS phishing and credential theft</strong></p></li><li><p><strong>    Active since: Around 2021</strong></p></li><li><p><strong>    Primary targets: Mobile users in Europe, Asia, and North America</strong></p></li><li><p><strong>    Techniques: Spoofed SMS, fake websites, Android trojans</strong></p></li><li><p><strong>    Goal: Harvest banking data and online account credentials</strong></p></li></ul><h3><strong>Watch Summary Video Below: &#11015;&#65039;</strong></h3><h3></h3>
      <p>
          <a href="https://www.cybermaterial.com/p/smishing-triad">
              Read more
          </a>
      </p>
   ]]></content:encoded></item><item><title><![CDATA[FluBot / Android banking malware]]></title><description><![CDATA[North Korean financially motivated threat actors, AI-Enabled Social Engineering and the New Face of Crypto Intrusions.]]></description><link>https://www.cybermaterial.com/p/flubot-android-banking-malware</link><guid isPermaLink="false">https://www.cybermaterial.com/p/flubot-android-banking-malware</guid><dc:creator><![CDATA[CyberMaterial]]></dc:creator><pubDate>Mon, 06 Apr 2026 18:04:08 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!xMC4!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7fe99419-93e5-4ff9-b21c-7bb92fc4ed6b_1920x1080.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!xMC4!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7fe99419-93e5-4ff9-b21c-7bb92fc4ed6b_1920x1080.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!xMC4!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7fe99419-93e5-4ff9-b21c-7bb92fc4ed6b_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!xMC4!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7fe99419-93e5-4ff9-b21c-7bb92fc4ed6b_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!xMC4!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7fe99419-93e5-4ff9-b21c-7bb92fc4ed6b_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!xMC4!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7fe99419-93e5-4ff9-b21c-7bb92fc4ed6b_1920x1080.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!xMC4!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7fe99419-93e5-4ff9-b21c-7bb92fc4ed6b_1920x1080.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/7fe99419-93e5-4ff9-b21c-7bb92fc4ed6b_1920x1080.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:2175657,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.cybermaterial.com/i/193359641?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7fe99419-93e5-4ff9-b21c-7bb92fc4ed6b_1920x1080.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!xMC4!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7fe99419-93e5-4ff9-b21c-7bb92fc4ed6b_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!xMC4!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7fe99419-93e5-4ff9-b21c-7bb92fc4ed6b_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!xMC4!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7fe99419-93e5-4ff9-b21c-7bb92fc4ed6b_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!xMC4!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7fe99419-93e5-4ff9-b21c-7bb92fc4ed6b_1920x1080.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p><div><hr></div><p><strong>FluBot</strong> is a fast-spreading mobile threat targeting users of Android devices. It&#8217;s designed to steal sensitive information&#8212;especially banking credentials&#8212;and spread itself aggressively through infected devices.</p><p><strong>What it is:</strong></p><p><strong>FluBot</strong> is a banking trojan that primarily spreads through malicious SMS messages. Once installed, it can steal passwords, intercept SMS messages, and even take control of your device.</p><h3><strong>Watch Summary Video Below: &#11015;&#65039;</strong></h3><h3></h3>
      <p>
          <a href="https://www.cybermaterial.com/p/flubot-android-banking-malware">
              Read more
          </a>
      </p>
   ]]></content:encoded></item><item><title><![CDATA[CryptoCore / UNC1069]]></title><description><![CDATA[North Korean financially motivated threat actors, AI-Enabled Social Engineering and the New Face of Crypto Intrusions.]]></description><link>https://www.cybermaterial.com/p/cryptocore-unc1069</link><guid isPermaLink="false">https://www.cybermaterial.com/p/cryptocore-unc1069</guid><dc:creator><![CDATA[CyberMaterial]]></dc:creator><pubDate>Thu, 19 Feb 2026 19:49:37 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!ZIar!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F584ff969-17eb-46fe-b531-e360c589a30a_1920x1080.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!ZIar!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F584ff969-17eb-46fe-b531-e360c589a30a_1920x1080.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!ZIar!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F584ff969-17eb-46fe-b531-e360c589a30a_1920x1080.jpeg 424w, https://substackcdn.com/image/fetch/$s_!ZIar!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F584ff969-17eb-46fe-b531-e360c589a30a_1920x1080.jpeg 848w, https://substackcdn.com/image/fetch/$s_!ZIar!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F584ff969-17eb-46fe-b531-e360c589a30a_1920x1080.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!ZIar!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F584ff969-17eb-46fe-b531-e360c589a30a_1920x1080.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!ZIar!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F584ff969-17eb-46fe-b531-e360c589a30a_1920x1080.jpeg" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/584ff969-17eb-46fe-b531-e360c589a30a_1920x1080.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:231076,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.cybermaterial.com/i/188537292?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F584ff969-17eb-46fe-b531-e360c589a30a_1920x1080.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!ZIar!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F584ff969-17eb-46fe-b531-e360c589a30a_1920x1080.jpeg 424w, https://substackcdn.com/image/fetch/$s_!ZIar!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F584ff969-17eb-46fe-b531-e360c589a30a_1920x1080.jpeg 848w, https://substackcdn.com/image/fetch/$s_!ZIar!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F584ff969-17eb-46fe-b531-e360c589a30a_1920x1080.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!ZIar!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F584ff969-17eb-46fe-b531-e360c589a30a_1920x1080.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>The group widely tracked as <strong>CryptoCore</strong>, also referred to by Mandiant as <strong><a href="https://cloud.google.com/blog/topics/threat-intelligence/unc1069-targets-cryptocurrency-ai-social-engineering">UNC1069</a></strong>, has evolved from traditional spear-phishing campaigns into multi-stage intrusions powered by AI-generated deception, deepfake video, and tailored malware frameworks.</p><p>This is not opportunistic crime. It is structured, patient, and increasingly sophisticated.</p><p></p><div><hr></div><h2>A Familiar Actor with Evolving Tradecraft</h2><p>CryptoCore has been active since at least <strong>2018</strong>, primarily targeting:</p>
      <p>
          <a href="https://www.cybermaterial.com/p/cryptocore-unc1069">
              Read more
          </a>
      </p>
   ]]></content:encoded></item><item><title><![CDATA[Storm-1811 (Cybercriminal) – Threat Actor]]></title><description><![CDATA[Storm-1811]]></description><link>https://www.cybermaterial.com/p/storm-1811-cybercriminal-threat-actor</link><guid isPermaLink="false">https://www.cybermaterial.com/p/storm-1811-cybercriminal-threat-actor</guid><dc:creator><![CDATA[CyberMaterial]]></dc:creator><pubDate>Mon, 03 Mar 2025 03:06:18 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/8e56b910-bc52-461e-80d4-f6f9b6610353_1920x1080.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!EmY8!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe4b27cee-d16c-44af-ae32-a4616b556465_1920x1080.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!EmY8!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe4b27cee-d16c-44af-ae32-a4616b556465_1920x1080.jpeg 424w, https://substackcdn.com/image/fetch/$s_!EmY8!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe4b27cee-d16c-44af-ae32-a4616b556465_1920x1080.jpeg 848w, https://substackcdn.com/image/fetch/$s_!EmY8!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe4b27cee-d16c-44af-ae32-a4616b556465_1920x1080.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!EmY8!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe4b27cee-d16c-44af-ae32-a4616b556465_1920x1080.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!EmY8!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe4b27cee-d16c-44af-ae32-a4616b556465_1920x1080.jpeg" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/e4b27cee-d16c-44af-ae32-a4616b556465_1920x1080.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:null,&quot;width&quot;:null,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!EmY8!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe4b27cee-d16c-44af-ae32-a4616b556465_1920x1080.jpeg 424w, https://substackcdn.com/image/fetch/$s_!EmY8!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe4b27cee-d16c-44af-ae32-a4616b556465_1920x1080.jpeg 848w, https://substackcdn.com/image/fetch/$s_!EmY8!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe4b27cee-d16c-44af-ae32-a4616b556465_1920x1080.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!EmY8!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe4b27cee-d16c-44af-ae32-a4616b556465_1920x1080.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div></div></div></a><p><strong>Storm-1811</strong></p><p><strong>Date of Initial Activity</strong></p><p>April 2024</p><p><strong>Suspected attribution</strong></p><p>Cybercriminal</p><p><strong>Government Affiliation</strong></p><p>No</p><p><strong>Motivation</strong></p><p>Financial Gain</p><p><strong>Associated tools</strong></p><p>Quick Assist<br>Black Basta Ransomware<br>Batch Files<br>Custom Scrip&#8230;</p>
      <p>
          <a href="https://www.cybermaterial.com/p/storm-1811-cybercriminal-threat-actor">
              Read more
          </a>
      </p>
   ]]></content:encoded></item><item><title><![CDATA[CopyCop (State-Sponsored) – Threat Actor]]></title><description><![CDATA[CopyCop]]></description><link>https://www.cybermaterial.com/p/copycop-state-sponsored-threat-actor</link><guid isPermaLink="false">https://www.cybermaterial.com/p/copycop-state-sponsored-threat-actor</guid><dc:creator><![CDATA[CyberMaterial]]></dc:creator><pubDate>Mon, 03 Mar 2025 03:05:03 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/67674f34-b808-4217-a5bf-0361d41e9a0f_1920x1080.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!DqiV!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2f26f3c6-aec7-4f1d-8c3e-f42066bd2f78_1920x1080.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!DqiV!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2f26f3c6-aec7-4f1d-8c3e-f42066bd2f78_1920x1080.jpeg 424w, https://substackcdn.com/image/fetch/$s_!DqiV!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2f26f3c6-aec7-4f1d-8c3e-f42066bd2f78_1920x1080.jpeg 848w, https://substackcdn.com/image/fetch/$s_!DqiV!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2f26f3c6-aec7-4f1d-8c3e-f42066bd2f78_1920x1080.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!DqiV!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2f26f3c6-aec7-4f1d-8c3e-f42066bd2f78_1920x1080.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!DqiV!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2f26f3c6-aec7-4f1d-8c3e-f42066bd2f78_1920x1080.jpeg" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/2f26f3c6-aec7-4f1d-8c3e-f42066bd2f78_1920x1080.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:null,&quot;width&quot;:null,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!DqiV!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2f26f3c6-aec7-4f1d-8c3e-f42066bd2f78_1920x1080.jpeg 424w, https://substackcdn.com/image/fetch/$s_!DqiV!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2f26f3c6-aec7-4f1d-8c3e-f42066bd2f78_1920x1080.jpeg 848w, https://substackcdn.com/image/fetch/$s_!DqiV!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2f26f3c6-aec7-4f1d-8c3e-f42066bd2f78_1920x1080.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!DqiV!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2f26f3c6-aec7-4f1d-8c3e-f42066bd2f78_1920x1080.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div></div></div></a><p><strong>CopyCop</strong></p><p><strong>Location</strong></p><p>Russia</p><p><strong>Date of Initial Activity</strong></p><p>March 2024</p><p><strong>Suspected attribution</strong></p><p>State-sponsored Threar Group</p><p><strong>Government Affiliation</strong></p><p>Yes</p><p><strong>Motivation</strong></p><p>Spreading Disinformation campaigns by leveraging generative &#8230;</p>
      <p>
          <a href="https://www.cybermaterial.com/p/copycop-state-sponsored-threat-actor">
              Read more
          </a>
      </p>
   ]]></content:encoded></item><item><title><![CDATA[Storm-0539 – Threat Actor]]></title><description><![CDATA[Storm-0539]]></description><link>https://www.cybermaterial.com/p/storm-0539-threat-actor</link><guid isPermaLink="false">https://www.cybermaterial.com/p/storm-0539-threat-actor</guid><dc:creator><![CDATA[CyberMaterial]]></dc:creator><pubDate>Mon, 03 Mar 2025 03:03:04 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/d7502c9e-4e27-4631-916a-6f25dab3486c_1920x1080.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!c7_s!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff315d1bc-a6d8-458c-b575-d27b795477cb_1920x1080.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!c7_s!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff315d1bc-a6d8-458c-b575-d27b795477cb_1920x1080.jpeg 424w, https://substackcdn.com/image/fetch/$s_!c7_s!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff315d1bc-a6d8-458c-b575-d27b795477cb_1920x1080.jpeg 848w, https://substackcdn.com/image/fetch/$s_!c7_s!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff315d1bc-a6d8-458c-b575-d27b795477cb_1920x1080.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!c7_s!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff315d1bc-a6d8-458c-b575-d27b795477cb_1920x1080.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!c7_s!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff315d1bc-a6d8-458c-b575-d27b795477cb_1920x1080.jpeg" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/f315d1bc-a6d8-458c-b575-d27b795477cb_1920x1080.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:null,&quot;width&quot;:null,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!c7_s!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff315d1bc-a6d8-458c-b575-d27b795477cb_1920x1080.jpeg 424w, https://substackcdn.com/image/fetch/$s_!c7_s!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff315d1bc-a6d8-458c-b575-d27b795477cb_1920x1080.jpeg 848w, https://substackcdn.com/image/fetch/$s_!c7_s!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff315d1bc-a6d8-458c-b575-d27b795477cb_1920x1080.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!c7_s!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff315d1bc-a6d8-458c-b575-d27b795477cb_1920x1080.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div></div></div></a><p><strong>Storm-0539</strong></p><p><strong>Location</strong></p><p>Morocco</p><p><strong>Date of Initial Activity</strong></p><p>2021</p><p><strong>Suspected Attribution&nbsp;</strong></p><p>Cybercriminal</p><p><strong>Motivation</strong></p><p>Financial Gain</p><h3><strong>Overview</strong></h3><p>Storm-0539 is a sophisticated cybercrime group originating from Morocco and act&#8230;</p>
      <p>
          <a href="https://www.cybermaterial.com/p/storm-0539-threat-actor">
              Read more
          </a>
      </p>
   ]]></content:encoded></item><item><title><![CDATA[Void Manticore (Storm-0842) – Threat Actor]]></title><description><![CDATA[Void Manticore]]></description><link>https://www.cybermaterial.com/p/void-manticore-storm-0842-threat-actor</link><guid isPermaLink="false">https://www.cybermaterial.com/p/void-manticore-storm-0842-threat-actor</guid><dc:creator><![CDATA[CyberMaterial]]></dc:creator><pubDate>Mon, 03 Mar 2025 02:56:16 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/6217a163-1ad0-4957-ac74-2c8016389a5f_1920x1080.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!wuLn!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7efd11e7-ed74-4104-8646-9e38221a8342_1920x1080.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!wuLn!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7efd11e7-ed74-4104-8646-9e38221a8342_1920x1080.jpeg 424w, https://substackcdn.com/image/fetch/$s_!wuLn!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7efd11e7-ed74-4104-8646-9e38221a8342_1920x1080.jpeg 848w, https://substackcdn.com/image/fetch/$s_!wuLn!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7efd11e7-ed74-4104-8646-9e38221a8342_1920x1080.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!wuLn!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7efd11e7-ed74-4104-8646-9e38221a8342_1920x1080.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!wuLn!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7efd11e7-ed74-4104-8646-9e38221a8342_1920x1080.jpeg" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/7efd11e7-ed74-4104-8646-9e38221a8342_1920x1080.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:null,&quot;width&quot;:null,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!wuLn!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7efd11e7-ed74-4104-8646-9e38221a8342_1920x1080.jpeg 424w, https://substackcdn.com/image/fetch/$s_!wuLn!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7efd11e7-ed74-4104-8646-9e38221a8342_1920x1080.jpeg 848w, https://substackcdn.com/image/fetch/$s_!wuLn!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7efd11e7-ed74-4104-8646-9e38221a8342_1920x1080.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!wuLn!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7efd11e7-ed74-4104-8646-9e38221a8342_1920x1080.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div></div></div></a><p><strong>Void Manticore</strong></p><p><strong>Other Names</strong></p><p>Storm-0842</p><p>Karma</p><p>Homeland Justice</p><p><strong>Location</strong></p><p>Iran</p><p><strong>Date of initial activity</strong></p><p>2023</p><p><strong>Suspected attribution</strong></p><p>State-sponsored Threat Group</p><p><strong>Government Affiliation</strong></p><p>Yes</p><p><strong>Associated Groups</strong></p><p>Scarred Mant&#8230;</p>
      <p>
          <a href="https://www.cybermaterial.com/p/void-manticore-storm-0842-threat-actor">
              Read more
          </a>
      </p>
   ]]></content:encoded></item><item><title><![CDATA[Unfading Sea Haze – Threat Actor]]></title><description><![CDATA[Unfading Sea Haze]]></description><link>https://www.cybermaterial.com/p/unfading-sea-haze-threat-actor</link><guid isPermaLink="false">https://www.cybermaterial.com/p/unfading-sea-haze-threat-actor</guid><dc:creator><![CDATA[CyberMaterial]]></dc:creator><pubDate>Mon, 03 Mar 2025 02:55:03 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/776a7c9b-374c-4123-90a6-a2649b442de8_1920x1080.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!aDgF!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc6dc6364-ab4f-4ca7-824b-c86928789fe7_1920x1080.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!aDgF!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc6dc6364-ab4f-4ca7-824b-c86928789fe7_1920x1080.jpeg 424w, https://substackcdn.com/image/fetch/$s_!aDgF!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc6dc6364-ab4f-4ca7-824b-c86928789fe7_1920x1080.jpeg 848w, https://substackcdn.com/image/fetch/$s_!aDgF!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc6dc6364-ab4f-4ca7-824b-c86928789fe7_1920x1080.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!aDgF!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc6dc6364-ab4f-4ca7-824b-c86928789fe7_1920x1080.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!aDgF!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc6dc6364-ab4f-4ca7-824b-c86928789fe7_1920x1080.jpeg" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/c6dc6364-ab4f-4ca7-824b-c86928789fe7_1920x1080.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:null,&quot;width&quot;:null,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!aDgF!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc6dc6364-ab4f-4ca7-824b-c86928789fe7_1920x1080.jpeg 424w, https://substackcdn.com/image/fetch/$s_!aDgF!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc6dc6364-ab4f-4ca7-824b-c86928789fe7_1920x1080.jpeg 848w, https://substackcdn.com/image/fetch/$s_!aDgF!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc6dc6364-ab4f-4ca7-824b-c86928789fe7_1920x1080.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!aDgF!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc6dc6364-ab4f-4ca7-824b-c86928789fe7_1920x1080.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div></div></div></a><p><strong>Unfading Sea Haze</strong></p><p><strong>Location</strong></p><p>China</p><p><strong>Date of initial activity</strong></p><p>2018</p><p><strong>Suspected attribution</strong></p><p>Cybercriminal</p><p><strong>Government Affiliation</strong></p><p>Unknown</p><p><strong>Motivation</strong></p><p>Cyberespionage</p><p><strong>Associated tools</strong></p><p>SilentGh0st<br>.NET Payloads<br>Ps2dllLoader<br>Sh&#8230;</p>
      <p>
          <a href="https://www.cybermaterial.com/p/unfading-sea-haze-threat-actor">
              Read more
          </a>
      </p>
   ]]></content:encoded></item><item><title><![CDATA[Ikaruz Red Team – Threat Actor]]></title><description><![CDATA[Ikaruz Red Team]]></description><link>https://www.cybermaterial.com/p/ikaruz-red-team-threat-actor</link><guid isPermaLink="false">https://www.cybermaterial.com/p/ikaruz-red-team-threat-actor</guid><dc:creator><![CDATA[CyberMaterial]]></dc:creator><pubDate>Mon, 03 Mar 2025 02:53:43 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/693a88f6-a1a3-4920-b9f0-82ad34216aa0_1920x1080.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!wRhR!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8e8821eb-b76b-445e-a471-a3f735a79a31_1920x1080.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!wRhR!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8e8821eb-b76b-445e-a471-a3f735a79a31_1920x1080.jpeg 424w, https://substackcdn.com/image/fetch/$s_!wRhR!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8e8821eb-b76b-445e-a471-a3f735a79a31_1920x1080.jpeg 848w, https://substackcdn.com/image/fetch/$s_!wRhR!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8e8821eb-b76b-445e-a471-a3f735a79a31_1920x1080.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!wRhR!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8e8821eb-b76b-445e-a471-a3f735a79a31_1920x1080.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!wRhR!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8e8821eb-b76b-445e-a471-a3f735a79a31_1920x1080.jpeg" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/8e8821eb-b76b-445e-a471-a3f735a79a31_1920x1080.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:null,&quot;width&quot;:null,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!wRhR!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8e8821eb-b76b-445e-a471-a3f735a79a31_1920x1080.jpeg 424w, https://substackcdn.com/image/fetch/$s_!wRhR!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8e8821eb-b76b-445e-a471-a3f735a79a31_1920x1080.jpeg 848w, https://substackcdn.com/image/fetch/$s_!wRhR!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8e8821eb-b76b-445e-a471-a3f735a79a31_1920x1080.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!wRhR!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8e8821eb-b76b-445e-a471-a3f735a79a31_1920x1080.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div></div></div></a><p><strong>Ikaruz Red Team</strong></p><p><strong>Location</strong></p><p>Turkey</p><p><strong>Date of Initial Activity</strong></p><p>2004</p><p><strong>Suspected attribution</strong></p><p>Hactivist Group</p><p><strong>Government Affiliation</strong></p><p>Unknown</p><p><strong>Associated Groups</strong></p><p>Turk Hack Team, PHEDS</p><p><strong>Motivation</strong></p><p>Hacktivism</p><p><strong>Associated tools</strong></p><p>Loc&#8230;</p>
      <p>
          <a href="https://www.cybermaterial.com/p/ikaruz-red-team-threat-actor">
              Read more
          </a>
      </p>
   ]]></content:encoded></item><item><title><![CDATA[UAC-0188 (FRwL) – Threat Actor]]></title><description><![CDATA[UAC-0188]]></description><link>https://www.cybermaterial.com/p/uac-0188-frwl-threat-actor</link><guid isPermaLink="false">https://www.cybermaterial.com/p/uac-0188-frwl-threat-actor</guid><dc:creator><![CDATA[CyberMaterial]]></dc:creator><pubDate>Mon, 03 Mar 2025 02:52:10 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/4516d482-9a45-42f5-ac4b-ea2d622a5e9d_1920x1080.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!F1e1!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff1c12912-10db-4c77-a811-07a6c9b36d89_1920x1080.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!F1e1!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff1c12912-10db-4c77-a811-07a6c9b36d89_1920x1080.jpeg 424w, https://substackcdn.com/image/fetch/$s_!F1e1!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff1c12912-10db-4c77-a811-07a6c9b36d89_1920x1080.jpeg 848w, https://substackcdn.com/image/fetch/$s_!F1e1!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff1c12912-10db-4c77-a811-07a6c9b36d89_1920x1080.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!F1e1!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff1c12912-10db-4c77-a811-07a6c9b36d89_1920x1080.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!F1e1!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff1c12912-10db-4c77-a811-07a6c9b36d89_1920x1080.jpeg" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/f1c12912-10db-4c77-a811-07a6c9b36d89_1920x1080.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:null,&quot;width&quot;:null,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!F1e1!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff1c12912-10db-4c77-a811-07a6c9b36d89_1920x1080.jpeg 424w, https://substackcdn.com/image/fetch/$s_!F1e1!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff1c12912-10db-4c77-a811-07a6c9b36d89_1920x1080.jpeg 848w, https://substackcdn.com/image/fetch/$s_!F1e1!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff1c12912-10db-4c77-a811-07a6c9b36d89_1920x1080.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!F1e1!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff1c12912-10db-4c77-a811-07a6c9b36d89_1920x1080.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div></div></div></a><p><strong>UAC-0188</strong></p><p><strong>Other Names</strong></p><p>From Russia With Love, FRwL</p><p><strong>Location</strong></p><p>Russia</p><p><strong>Date of initial activity</strong></p><p>2022</p><p><strong>Suspected attribution</strong></p><p>Hactivist Group</p><p><strong>Government Affiliation</strong></p><p>Unknown</p><p><strong>Motivation</strong></p><p>Hacktivism</p><p><strong>Associated tools</strong></p><p>Somnia Ran&#8230;</p>
      <p>
          <a href="https://www.cybermaterial.com/p/uac-0188-frwl-threat-actor">
              Read more
          </a>
      </p>
   ]]></content:encoded></item><item><title><![CDATA[Ghostr (Cybercriminal) – Threat Actor]]></title><description><![CDATA[Ghostr Location]]></description><link>https://www.cybermaterial.com/p/ghostr-cybercriminal-threat-actor</link><guid isPermaLink="false">https://www.cybermaterial.com/p/ghostr-cybercriminal-threat-actor</guid><dc:creator><![CDATA[CyberMaterial]]></dc:creator><pubDate>Mon, 03 Mar 2025 02:51:25 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/9e5d7e8b-7640-4f41-a74e-8dd7614d9a0d_1920x1080.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!f3fG!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F308dbb4b-242d-4202-a5c9-149b8ce7b301_1920x1080.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!f3fG!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F308dbb4b-242d-4202-a5c9-149b8ce7b301_1920x1080.jpeg 424w, https://substackcdn.com/image/fetch/$s_!f3fG!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F308dbb4b-242d-4202-a5c9-149b8ce7b301_1920x1080.jpeg 848w, https://substackcdn.com/image/fetch/$s_!f3fG!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F308dbb4b-242d-4202-a5c9-149b8ce7b301_1920x1080.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!f3fG!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F308dbb4b-242d-4202-a5c9-149b8ce7b301_1920x1080.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!f3fG!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F308dbb4b-242d-4202-a5c9-149b8ce7b301_1920x1080.jpeg" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/308dbb4b-242d-4202-a5c9-149b8ce7b301_1920x1080.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:null,&quot;width&quot;:null,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!f3fG!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F308dbb4b-242d-4202-a5c9-149b8ce7b301_1920x1080.jpeg 424w, https://substackcdn.com/image/fetch/$s_!f3fG!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F308dbb4b-242d-4202-a5c9-149b8ce7b301_1920x1080.jpeg 848w, https://substackcdn.com/image/fetch/$s_!f3fG!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F308dbb4b-242d-4202-a5c9-149b8ce7b301_1920x1080.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!f3fG!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F308dbb4b-242d-4202-a5c9-149b8ce7b301_1920x1080.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div></div></div></a><p><strong>Ghostr</strong></p><p><strong>Location</strong></p><p>China</p><p><strong>Date of initial activity</strong></p><p>2017</p><p><strong>Suspected attribution</strong></p><p>Cybercriminal</p><p><strong>Government Affiliation</strong></p><p>No</p><p><strong>Associated Groups</strong></p><p>APT10(MenuPass, POTASSIUM, Stone Panda, Red Apollo, and CVNX)</p><p><strong>Motivation</strong></p><p>Financ&#8230;</p>
      <p>
          <a href="https://www.cybermaterial.com/p/ghostr-cybercriminal-threat-actor">
              Read more
          </a>
      </p>
   ]]></content:encoded></item><item><title><![CDATA[UAC-0200 (State-Sponsored) – Threat Actor]]></title><description><![CDATA[UAC-0200]]></description><link>https://www.cybermaterial.com/p/uac-0200-state-sponsored-threat-actor</link><guid isPermaLink="false">https://www.cybermaterial.com/p/uac-0200-state-sponsored-threat-actor</guid><dc:creator><![CDATA[CyberMaterial]]></dc:creator><pubDate>Mon, 03 Mar 2025 02:48:58 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/87c5bbf4-6e79-4c59-811c-786a0aee1237_1920x1080.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!NWWW!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F170d6cb0-1207-4611-9bce-d7d5c0673f1b_1920x1080.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!NWWW!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F170d6cb0-1207-4611-9bce-d7d5c0673f1b_1920x1080.jpeg 424w, https://substackcdn.com/image/fetch/$s_!NWWW!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F170d6cb0-1207-4611-9bce-d7d5c0673f1b_1920x1080.jpeg 848w, https://substackcdn.com/image/fetch/$s_!NWWW!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F170d6cb0-1207-4611-9bce-d7d5c0673f1b_1920x1080.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!NWWW!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F170d6cb0-1207-4611-9bce-d7d5c0673f1b_1920x1080.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!NWWW!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F170d6cb0-1207-4611-9bce-d7d5c0673f1b_1920x1080.jpeg" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/170d6cb0-1207-4611-9bce-d7d5c0673f1b_1920x1080.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:null,&quot;width&quot;:null,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!NWWW!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F170d6cb0-1207-4611-9bce-d7d5c0673f1b_1920x1080.jpeg 424w, https://substackcdn.com/image/fetch/$s_!NWWW!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F170d6cb0-1207-4611-9bce-d7d5c0673f1b_1920x1080.jpeg 848w, https://substackcdn.com/image/fetch/$s_!NWWW!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F170d6cb0-1207-4611-9bce-d7d5c0673f1b_1920x1080.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!NWWW!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F170d6cb0-1207-4611-9bce-d7d5c0673f1b_1920x1080.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div></div></div></a><p><strong>UAC-0200</strong></p><p><strong>Location</strong></p><p>Luhansk People's Republic (LPR- self proclaimed breakaway region in ukraine supported by Russia)</p><p><strong>Date of Initial Activity</strong></p><p>2024</p><p><strong>Suspected attribution</strong></p><p>State-sponsored threat group</p><p><strong>Government&#8230;</strong></p>
      <p>
          <a href="https://www.cybermaterial.com/p/uac-0200-state-sponsored-threat-actor">
              Read more
          </a>
      </p>
   ]]></content:encoded></item><item><title><![CDATA[Turla (The Epic Turla, Snake) – Threat Actor]]></title><description><![CDATA[Turla Other Names]]></description><link>https://www.cybermaterial.com/p/turla-the-epic-turla-snake-threat-actor</link><guid isPermaLink="false">https://www.cybermaterial.com/p/turla-the-epic-turla-snake-threat-actor</guid><dc:creator><![CDATA[CyberMaterial]]></dc:creator><pubDate>Mon, 03 Mar 2025 02:48:04 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/aaf5a45d-70f8-4bcc-bb3e-250cef573059_1920x1080.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Z2d7!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F522f9f89-5f88-4e53-a3a7-18c69e3da042_1920x1080.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Z2d7!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F522f9f89-5f88-4e53-a3a7-18c69e3da042_1920x1080.jpeg 424w, https://substackcdn.com/image/fetch/$s_!Z2d7!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F522f9f89-5f88-4e53-a3a7-18c69e3da042_1920x1080.jpeg 848w, https://substackcdn.com/image/fetch/$s_!Z2d7!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F522f9f89-5f88-4e53-a3a7-18c69e3da042_1920x1080.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!Z2d7!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F522f9f89-5f88-4e53-a3a7-18c69e3da042_1920x1080.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Z2d7!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F522f9f89-5f88-4e53-a3a7-18c69e3da042_1920x1080.jpeg" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/522f9f89-5f88-4e53-a3a7-18c69e3da042_1920x1080.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:null,&quot;width&quot;:null,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Z2d7!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F522f9f89-5f88-4e53-a3a7-18c69e3da042_1920x1080.jpeg 424w, https://substackcdn.com/image/fetch/$s_!Z2d7!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F522f9f89-5f88-4e53-a3a7-18c69e3da042_1920x1080.jpeg 848w, https://substackcdn.com/image/fetch/$s_!Z2d7!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F522f9f89-5f88-4e53-a3a7-18c69e3da042_1920x1080.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!Z2d7!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F522f9f89-5f88-4e53-a3a7-18c69e3da042_1920x1080.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div></div></div></a><p><strong>Turla</strong></p><p><strong>Other Names</strong></p><p>The Epic Turla</p><p>Snake</p><p>Uroburos</p><p>Epic</p><p><strong>Location</strong></p><p>Russia</p><p><strong>Date of initial activity</strong></p><p>2004</p><p><strong>Suspected attribution</strong></p><p>State-sponsored Threat Group</p><p><strong>Government Affiliation</strong></p><p>Yes</p><p><strong>Associated Groups</strong></p><p>IRON HUNTER, Group &#8230;</p>
      <p>
          <a href="https://www.cybermaterial.com/p/turla-the-epic-turla-snake-threat-actor">
              Read more
          </a>
      </p>
   ]]></content:encoded></item><item><title><![CDATA[Royal Tiger – Threat Actor]]></title><description><![CDATA[Royal Tiger]]></description><link>https://www.cybermaterial.com/p/royal-tiger-threat-actor</link><guid isPermaLink="false">https://www.cybermaterial.com/p/royal-tiger-threat-actor</guid><dc:creator><![CDATA[CyberMaterial]]></dc:creator><pubDate>Mon, 03 Mar 2025 02:46:13 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/8f53a436-17f7-4d6a-bd57-3486a70b7faf_1920x1080.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Mq8_!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1d004ff3-d792-4b63-ad4c-0b8656978a6e_1920x1080.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Mq8_!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1d004ff3-d792-4b63-ad4c-0b8656978a6e_1920x1080.jpeg 424w, https://substackcdn.com/image/fetch/$s_!Mq8_!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1d004ff3-d792-4b63-ad4c-0b8656978a6e_1920x1080.jpeg 848w, https://substackcdn.com/image/fetch/$s_!Mq8_!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1d004ff3-d792-4b63-ad4c-0b8656978a6e_1920x1080.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!Mq8_!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1d004ff3-d792-4b63-ad4c-0b8656978a6e_1920x1080.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Mq8_!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1d004ff3-d792-4b63-ad4c-0b8656978a6e_1920x1080.jpeg" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/1d004ff3-d792-4b63-ad4c-0b8656978a6e_1920x1080.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:null,&quot;width&quot;:null,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Mq8_!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1d004ff3-d792-4b63-ad4c-0b8656978a6e_1920x1080.jpeg 424w, https://substackcdn.com/image/fetch/$s_!Mq8_!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1d004ff3-d792-4b63-ad4c-0b8656978a6e_1920x1080.jpeg 848w, https://substackcdn.com/image/fetch/$s_!Mq8_!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1d004ff3-d792-4b63-ad4c-0b8656978a6e_1920x1080.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!Mq8_!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1d004ff3-d792-4b63-ad4c-0b8656978a6e_1920x1080.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div></div></div></a><p><strong>&nbsp;Royal Tiger</strong></p><p><strong>Date of Initial Activity</strong></p><p>2024</p><p><strong>Suspected Attribution&nbsp;</strong></p><p>Cybercriminal</p><p><strong>Government Affiliation</strong></p><p>No</p><p><strong>Motivation</strong></p><p>Financial Gain</p><h3><strong>Overview</strong></h3><p>Royal Tiger, led by figures like Prince Jashvantlal Anand and Kausha&#8230;</p>
      <p>
          <a href="https://www.cybermaterial.com/p/royal-tiger-threat-actor">
              Read more
          </a>
      </p>
   ]]></content:encoded></item><item><title><![CDATA[Sharp Dragon (Sharp Panda) – Threat Actor]]></title><description><![CDATA[Sharp Dragon]]></description><link>https://www.cybermaterial.com/p/sharp-dragon-sharp-panda-threat-actor</link><guid isPermaLink="false">https://www.cybermaterial.com/p/sharp-dragon-sharp-panda-threat-actor</guid><dc:creator><![CDATA[CyberMaterial]]></dc:creator><pubDate>Mon, 03 Mar 2025 02:45:06 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/d50529ec-8a47-47e8-adf1-97c3f38fb3a1_1920x1080.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!gpP-!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2ff15abd-ff3e-429a-8915-ba8992ba3c52_1920x1080.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!gpP-!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2ff15abd-ff3e-429a-8915-ba8992ba3c52_1920x1080.jpeg 424w, https://substackcdn.com/image/fetch/$s_!gpP-!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2ff15abd-ff3e-429a-8915-ba8992ba3c52_1920x1080.jpeg 848w, https://substackcdn.com/image/fetch/$s_!gpP-!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2ff15abd-ff3e-429a-8915-ba8992ba3c52_1920x1080.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!gpP-!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2ff15abd-ff3e-429a-8915-ba8992ba3c52_1920x1080.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!gpP-!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2ff15abd-ff3e-429a-8915-ba8992ba3c52_1920x1080.jpeg" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/2ff15abd-ff3e-429a-8915-ba8992ba3c52_1920x1080.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:null,&quot;width&quot;:null,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!gpP-!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2ff15abd-ff3e-429a-8915-ba8992ba3c52_1920x1080.jpeg 424w, https://substackcdn.com/image/fetch/$s_!gpP-!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2ff15abd-ff3e-429a-8915-ba8992ba3c52_1920x1080.jpeg 848w, https://substackcdn.com/image/fetch/$s_!gpP-!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2ff15abd-ff3e-429a-8915-ba8992ba3c52_1920x1080.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!gpP-!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2ff15abd-ff3e-429a-8915-ba8992ba3c52_1920x1080.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div></div></div></a><p><strong>Sharp Dragon</strong></p><p><strong>Other Names</strong></p><p>Sharp Panda</p><p>Panda</p><p>Panda Dragon</p><p><strong>Location</strong></p><p>China</p><p><strong>Date of initial activity</strong></p><p>2021</p><p><strong>Suspected Attribution&nbsp;</strong></p><p>Cybercriminal</p><p><strong>Government Affiliation</strong></p><p>No</p><p><strong>Motivation</strong></p><p>Cyberespionage</p><p><strong>Associated Tools</strong></p><p>VictoryD&#8230;</p>
      <p>
          <a href="https://www.cybermaterial.com/p/sharp-dragon-sharp-panda-threat-actor">
              Read more
          </a>
      </p>
   ]]></content:encoded></item><item><title><![CDATA[FlyingYeti (UAC-0149) – Threat Actor]]></title><description><![CDATA[FlyingYeti]]></description><link>https://www.cybermaterial.com/p/flyingyeti-uac-0149-threat-actor</link><guid isPermaLink="false">https://www.cybermaterial.com/p/flyingyeti-uac-0149-threat-actor</guid><dc:creator><![CDATA[CyberMaterial]]></dc:creator><pubDate>Mon, 03 Mar 2025 02:44:28 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/9a85bf84-27c3-4f69-a183-668243d15997_1920x1080.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!T_S5!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F38613754-df14-451b-a5e6-b5306af0f778_1920x1080.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!T_S5!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F38613754-df14-451b-a5e6-b5306af0f778_1920x1080.jpeg 424w, https://substackcdn.com/image/fetch/$s_!T_S5!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F38613754-df14-451b-a5e6-b5306af0f778_1920x1080.jpeg 848w, https://substackcdn.com/image/fetch/$s_!T_S5!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F38613754-df14-451b-a5e6-b5306af0f778_1920x1080.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!T_S5!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F38613754-df14-451b-a5e6-b5306af0f778_1920x1080.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!T_S5!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F38613754-df14-451b-a5e6-b5306af0f778_1920x1080.jpeg" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/38613754-df14-451b-a5e6-b5306af0f778_1920x1080.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:null,&quot;width&quot;:null,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!T_S5!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F38613754-df14-451b-a5e6-b5306af0f778_1920x1080.jpeg 424w, https://substackcdn.com/image/fetch/$s_!T_S5!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F38613754-df14-451b-a5e6-b5306af0f778_1920x1080.jpeg 848w, https://substackcdn.com/image/fetch/$s_!T_S5!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F38613754-df14-451b-a5e6-b5306af0f778_1920x1080.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!T_S5!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F38613754-df14-451b-a5e6-b5306af0f778_1920x1080.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div></div></div></a><p><strong>FlyingYeti</strong></p><p><strong>Other Names</strong></p><p>UAC-0149</p><p><strong>Location</strong></p><p>Russia</p><p><strong>Date of Initial Activity</strong></p><p>2014</p><p><strong>Suspected Attribution&nbsp;</strong></p><p>State-sponsored threat actor</p><p><strong>Government Affiliation</strong></p><p>Yes</p><p><strong>Associated Groups</strong></p><p>Fancy Bear, Cozy Bear, Sofacy</p><p><strong>Motivat&#8230;</strong></p>
      <p>
          <a href="https://www.cybermaterial.com/p/flyingyeti-uac-0149-threat-actor">
              Read more
          </a>
      </p>
   ]]></content:encoded></item></channel></rss>