RecordedFuture

RedNovember Targets Government, Defense, and Technology Organizations

RedNovember is now assessed to be a Chinese state-sponsored cyber-espionage group. Active between June 2024 and July 2025, the group has targeted high-profile government, intergovernmental, and private sector organizations globally.

CopyCop Deepens Its Playbook with New Websites and Targets

A Russian influence operation known as CopyCop has expanded its disinformation infrastructure in 2025, deploying over 300 websites to target democratic institutions and public opinion across the US, France, Canada, Germany, Armenia, and Moldova.

Analysis of TAG-140 Campaign and DRAT V2 Development Targeting Indian Government Organizations

A new Delphi-based variant of the DRAT remote access trojan, dubbed DRAT V2, has been deployed by TAG-140 (a subgroup of Transparent Tribe/APT36) in a campaign targeting Indian government entities.

GrayAlpha Unmasked: New FIN7-Linked Infrastructure, PowerNet Loader, and Fake Update Attacks

GrayAlpha, a threat actor overlapping with FIN7, has been observed deploying NetSupport RAT using diverse infection vectors and custom loaders. The group utilizes PowerNet, a PowerShell loader, and MaskBat.

Predator Spyware Resurgence: Insikt Group Exposes New Global Infrastructure

Researchers identified Predator-related infrastructure in multiple countries, including a new operator in Mozambique. Angola resumed operations in early 2025. A short-lived cluster was active from August to November 2024.

TAG-110 Targets Tajikistan: New Macro Word Documents Phishing Tactics

A Russia-aligned threat actor, TAG-110—linked to APT28 and UAC-0063—has launched a phishing campaign targeting Tajikistan’s government, academic, and research institutions.

Purchase Scam Network Exploits Brand Impersonation and Fraudulent Merchant Accounts to Defraud Victims

The network, active since at least February 2025, includes 71 scam domains and 12 merchant accounts, posing significant financial and compliance risks to card issuers and merchant acquirers.

Defend Against Threats with Cyber Fusion

Cyware is the leading provider of cyber fusion solutions that power threat intelligence sharing , end-to-end automation and 360-degree threat response.

Trending Tags