FBI Disrupts China-Linked QTFY Infrastructure Used to Steal Data From U.S. Organizations post, augustus 26, 2026september 4, 2026 The U.S. Department of Justice (DoJ) on Wednesday announced the disruption of two hacking platforms named QScan and QTRouter operated by Chinese threat actors to target critical infrastructure and other sensitive networks in the country. The activity has been attributed to a Chinese state-sponsored group known as QTFY, employed by Nanjing Xinjiuwei… Continue Reading
Iraanse hackers legden Britse energiecentrale 4 dagen plat post, augustus 23, 2026augustus 24, 2026 Iraanse hackers hebben vorige maand een energiecentrale in het Verenigd Koninkrijk vier dagen platgelegd met een cyberaanval. Dat meldt de Britse krant The Telegraph. Volgens de krant is het de eerste keer dat hackers die gelinkt worden aan het Iraanse regime een energiefaciliteit in het VK wisten te raken. Om welke energiecentrale… Continue Reading
Smile, You’re on Camera. Part 2: Hiring Lazarus APT’s IT Workers in a Fake DeFi Startup post, augustus 12, 2026augustus 17, 2026 Back in December, we were the first ever to fully record the Famous Chollima infiltration cycle. From recruiting collaborators to help them land jobs at Western companies, to forging documents, shipping laptops to facilitators’ houses, and even using AI tools for live assistance and translation during interviews. During that investigation,… Continue Reading
China-Nexus JadeProx Uses New TriBack Loader in Government and Healthcare Attacks post, juli 23, 2026juli 27, 2026 An exposed Alibaba Cloud server has revealed a China-nexus operation that Group-IB tracks as JadeProx. The cluster has targeted government, healthcare, and education organizations across Asia and Latin America with a previously undocumented Windows loader called TriBack Loader. Group-IB found the server in mid-April 2026 in Alibaba Cloud’s Singapore region; it… Continue Reading
Iranian-Affiliated Cyber Actors Exploit Programmable Logic Controllers Across US Critical Infrastructure post, juli 22, 2026juli 27, 2026 The authoring agencies urgently warn U.S. organizations of ongoing Iranian-affiliated cyber targeting of internet-connected operational technology (OT) devices, including programmable logic controllers (PLCs). These actions disrupted PLCs across several U.S. critical infrastructure sectors through malicious project file interactions and manipulation of data on human machine interface (HMI) and supervisory control… Continue Reading
Golden Dome: When Data Becomes Ammunition post, april 29, 2026mei 1, 2026 When we think of Golden Dome and what success looks like, we naturally talk about sensors, interceptors, and systems but the reality is much simpler: if the data they rely on doesn’t move, at speed, and securely, then nothing else matters. Data is now the driver of operational advantage. In today’s multi-domain, mission-critical environments, speed isn’t measured in minutes or seconds but in milliseconds. Data… Continue Reading
US warns of Iranian hackers targeting critical infrastructure post, april 7, 2026april 9, 2026 Iranian-linked hackers are targeting Internet-exposed Rockwell/Allen-Bradley programmable logic controllers (PLCs) on the networks of U.S. critical infrastructure organizations. The warning came earlier today in the form of a joint advisory authored by the FBI, CISA, NSA, the Environmental Protection Agency (EPA), Department of Energy (DOE), and the United States Cyber… Continue Reading
FBI confirms hack of Director Patel’s personal email inbox post, maart 29, 2026maart 30, 2026 The Handala hackers associated with Iran have breached the personal email account of FBI Director Kash Patel and published photos and documents. The FBI has confirmed the compromise, saying that the stolen data was not recent and did not include any government data. On Friday, the Handala threat actor announced… Continue Reading
Why Stryker’s Outage Is a Disaster Recovery Wake-Up Call post, maart 12, 2026maart 18, 2026 A cyberattack that appears to have knocked tens of thousands of systems offline at medical technology company Stryker this week is a sobering reminder of the importance for organizations to have robust and tested business continuity and disaster recovery plans. Iranian threat group Handala claimed responsibility for the attack, calling it… Continue Reading
Iran intelligence backdoored US bank, airport, software outfit networks post, maart 5, 2026maart 9, 2026 An Iranian cyber crew believed to be part of the Iranian Ministry of Intelligence and Security (MOIS) has been embedded in multiple US companies’ networks – including a bank, software firm, and airport, among others – since the beginning of February, with more activity in the days following the US… Continue Reading