Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
1 change: 1 addition & 0 deletions .cache/apt-campaigns
Submodule apt-campaigns added at cbf136
876,448 changes: 876,448 additions & 0 deletions .cache/enterprise-attack.json

Large diffs are not rendered by default.

14 changes: 14 additions & 0 deletions .cache/intel_synthesis/0624ce9ae7b43c4b.json
Original file line number Diff line number Diff line change
@@ -0,0 +1,14 @@
{
"cached_at": "2026-04-01T05:38:17.487090+00:00",
"result": {
"actor_summary": "BlueNoroff, a subgroup of the Lazarus Group, conducted a Web3-focused macOS intrusion campaign demonstrating the actor's continued targeting of cryptocurrency and blockchain-related entities. The operation employed a multi-stage attack chain leveraging macOS-specific malware and techniques to compromise Web3 developers and organizations, reflecting Lazarus Group's persistent focus on financial theft and high-value digital asset targets. This activity indicates the actor has expanded its operational sophistication to include macOS platforms alongside its historically documented Windows and Linux capabilities.",
"landscape_summary": "This intrusion reflects an escalating trend of DPRK-nexus threat actors expanding beyond traditional financial targets into Web3 and cryptocurrency ecosystems, where fewer security controls and higher-value assets create attractive opportunities for state-sponsored theft. The shift toward macOS-specific attack chains indicates Lazarus Group's continuing effort to diversify targeting beyond Windows-dominant environments and exploit the assumption of lower security maturity on Apple platforms within developer and crypto-native communities.",
"relevance": 50,
"source": "Huntress Labs Blog",
"source_tier": 3,
"date": "2025-06-18",
"title": "Inside the BlueNoroff Web3 macOS Intrusion Analysis",
"url": "https://www.huntress.com/blog/inside-bluenoroff-web3-intrusion-analysis",
"provider": "claude"
}
}
14 changes: 14 additions & 0 deletions .cache/intel_synthesis/26969be7b7e3a47f.json
Original file line number Diff line number Diff line change
@@ -0,0 +1,14 @@
{
"cached_at": "2026-03-31T18:52:56.743833+00:00",
"result": {
"actor_summary": "APT28 has integrated large language models into its attack infrastructure, deploying the LameHug infostealer to generate attack commands dynamically. This represents an evolution in the group's operational approach, shifting from static command generation to AI-assisted attack execution. The article does not specify targeting sectors, countries, or provide additional tactical details beyond the LLM integration.",
"landscape_summary": "# Threat Landscape Context\n\nThis development reflects an emerging pattern of state-sponsored actors operationalizing large language models to automate command generation and reduce operational friction, potentially lowering the technical barriers for distributed attack execution. APT28's integration of LLM-assisted tooling suggests nation-state adoption of AI-driven attack orchestration is transitioning from experimental to operational deployment in live campaigns.",
"relevance": 50,
"source": "ThreatLocker Blog",
"source_tier": 2,
"date": "2026-03-11",
"title": "What Is LameHug? How APT28 is using LLMs to generate attack commands",
"url": "https://www.threatlocker.com/blog/what-is-lamehug-how-apt28-is-using-llms-to-generate-attack-commands",
"provider": "claude"
}
}
14 changes: 14 additions & 0 deletions .cache/intel_synthesis/2d5372595f84b53b.json
Original file line number Diff line number Diff line change
@@ -0,0 +1,14 @@
{
"cached_at": "2026-03-31T18:52:53.377682+00:00",
"result": {
"actor_summary": "APT28 exploited a Microsoft Office zero-day vulnerability during January 2026, demonstrating continued focus on widely-used productivity software as an attack vector. The article provides no additional details regarding targeting scope, geographic focus, or tactical evolution beyond this single exploit activity.",
"landscape_summary": "The January 2026 CVE landscape reflects an accelerating pattern of nation-state actors like APT28 moving away from custom exploit development and toward rapid weaponization of public zero-days, particularly targeting productivity suites that maintain privileged access within enterprise environments. This shift underscores a strategic pivot toward exploits with immediate operational impact over traditional persistence mechanisms, driven by the expanding public disclosure cycle and compressed patching windows in enterprise deployments.",
"relevance": 60,
"source": "Recorded Future (Public)",
"source_tier": 2,
"date": "2026-02-24",
"title": "January 2026 CVE Landscape: 23 Critical Vulnerabilities Mark 5% Increase, APT28 Exploits Microsoft Office Zero-Day",
"url": "https://www.recordedfuture.com/blog/january-2026-cve-landscape",
"provider": "claude"
}
}
14 changes: 14 additions & 0 deletions .cache/intel_synthesis/45c37addec8985e9.json
Original file line number Diff line number Diff line change
@@ -0,0 +1,14 @@
{
"cached_at": "2026-03-31T18:52:50.268633+00:00",
"result": {
"actor_summary": "APT28 (tracked as BlueDelta by Insikt Group) evolved credential-harvesting campaigns targeting government, energy, and research organizations across Europe and Eurasia as of early 2026. The group's operational focus reflects a shift toward intensified collection against critical infrastructure and state institutions in the specified regions. No specific tactical innovations, tool changes, or temporal details beyond the January 2026 reporting date are provided in the article excerpt.",
"landscape_summary": "This reflects an ongoing shift toward persistent, low-detection-risk credential harvesting as a precursor to targeted intrusions, particularly against critical infrastructure where initial access brokers command premium value in the espionage supply chain. The geographic focus on Europe and Eurasia signals GRU's prioritization of strategic sectors where credential compromise enables sustained intelligence collection with minimal operational exposure.",
"relevance": 60,
"source": "Recorded Future (Public)",
"source_tier": 2,
"date": "2026-01-07",
"title": "GRU-Linked BlueDelta Evolves Credential Harvesting",
"url": "https://www.recordedfuture.com/research/gru-linked-bluedelta-evolves-credential-harvesting",
"provider": "claude"
}
}
14 changes: 14 additions & 0 deletions .cache/intel_synthesis/bd310a1a05a209eb.json
Original file line number Diff line number Diff line change
@@ -0,0 +1,14 @@
{
"cached_at": "2026-03-31T18:52:46.883538+00:00",
"result": {
"actor_summary": "APT28 (operating as BlueDelta) conducted a persistent credential-harvesting campaign targeting UKR.NET users, employing advanced phishing techniques across multiple stages. The campaign demonstrates evolved tradecraft in the actor's ongoing operations against Ukrainian infrastructure and users.",
"landscape_summary": "**Threat Landscape Context:**\n\nThis campaign reflects an intensifying focus by Russian state-sponsored actors on compromising Ukrainian critical infrastructure and government communications through identity-layer attacks, exploiting the accessibility and scale advantages of phishing over direct network intrusion during sustained conflict. The evolution of BlueDelta's credential-harvesting tradecraft against UKR.NET specifically indicates Russian operators are refining targeting precision and social engineering sophistication against high-value organizational email systems as traditional perimeter defenses improve.",
"relevance": 60,
"source": "Recorded Future (Public)",
"source_tier": 2,
"date": "2025-12-17",
"title": "BlueDelta\u2019s Persistent Campaign Against UKR.NET",
"url": "https://www.recordedfuture.com/research/bluedeltas-persistent-campaign-against-ukrnet",
"provider": "claude"
}
}
Loading