Verticals Targeted: Government, Ministries of Foreign Affairs, Healthcare, Research, Logistics, Law Enforcement, Urban Planning and Facilities Management, Education
Regions Targeted: Afghanistan, Kazakhstan, Kyrgyzstan, Syria, Tajikistan, Uzbekistan
Related Families: OctLurk, SilkLurk, LurkProxy, PlugX
OctLurk and SilkLurk: Analysis of a Modular Cyber Espionage Framework
Aug 6, 2026, 2:14:03 PM / by The Hivemind posted in Threat Bulletin, PlugX, credential theft, cyber espionage, OctLurk, SilkLurk, LurkProxy, modular backdoor
Mirage Kitten Deploys NightLedger Backdoor in Espionage Campaign Targeting the Middle East and Africa
Jul 31, 2026, 1:58:15 PM / by The Hivemind posted in Threat Bulletin, Spear Phishing, Nimbus Manticore, cyber espionage, aerospace cybersecurity, UNC1549, Mirage Kitten, NightLedger, ArcBridge, Smoke Sandstorm, WebSocket tunneling, BridgeHead
Verticals Targeted: Aerospace, Aviation, Defense, Telecommunications, Government, Financial Services, SMBs
Regions Targeted: Egypt, Jordan, Tanzania, Pakistan, Ethiopia, Burkina Faso
Related Threat Actors: Mirage Kitten
Related Families: NightLedger, BridgeHead, ArcBridge
Executive Summary
New research details the continued evolution of Mirage Kitten, an advanced persistent threat (APT) group conducting cyber-espionage operations across the Middle East and Africa. The campaign introduces three previously undocumented malware families, NightLedger, BridgeHead, and ArcBridge, that provide reconnaissance, command execution, covert tunneling, and persistent post-compromise access capabilities. The findings demonstrate Mirage Kitten's continued investment in bespoke malware development and operational security to support long-term intelligence collection.
HOLLOWGRAPH: The New Face of Cloud-Based Espionage
Jul 24, 2026, 2:46:49 PM / by The Hivemind posted in Threat Bulletin, cyber espionage, cloud-native malware, Cavern framework, HOLLOWGRAPH, Microsoft Graph API malware, DNS tunneling, Microsoft 365 calendar malware
Regions Targeted: Israel
Related Families: HOLLOWGRAPH, Cavern Framework
Executive Summary
Industry researchers identified HOLLOWGRAPH, a newly discovered malware component that it attributes with high confidence to the Cavern backdoor framework. Rather than relying on traditional command-and-control (C2) infrastructure, HOLLOWGRAPH abuses the Microsoft Graph API to transform a compromised Microsoft 365 calendar into a covert communications channel for receiving commands and exfiltrating stolen data. The campaign appears highly targeted, with at least 12 identified victims, primarily Israeli organizations, and only a small subset actively communicating with attacker infrastructure, suggesting a disciplined espionage operation.
“Shadow Campaigns” Show Evidence of Global Espionage Using ShadowGuard Rootkit
Feb 13, 2026, 1:01:00 PM / by The Hivemind posted in Threat Bulletin, Cobalt Strike, cyber espionage, government targeting, TGR-STA-1030, Diaoyu Loader, ShadowGuard rootkit, eBPF backdoor, global reconnaissance, Shadow Campaigns, state-aligned threat
Verticals Targeted: Government, Telecommunications, Finance, Aerospace
Regions Targeted: North America, South America, Africa, Europe, Asia
Related Families: Diaoyu Loader, ShadowGuard, Cobalt Strike, VShell
Executive Summary
A sophisticated state-aligned cyberespionage operation attributed to TGR-STA-1030 (also tracked as UNC6619) has been discovered, operating from Asia. It has compromised government and critical infrastructure entities across 37 countries over the past year while conducting reconnaissance against government infrastructure in 155 countries. The group's “Shadow Campaigns” leverage phishing, N-day exploitations, and advanced tooling to prioritize intelligence collection on economic partnerships, trade, and diplomatic activities.
Transparent Tribe Evolves Tradecraft With Multi-Stage LNK Malware
Jan 12, 2026, 1:55:19 PM / by The Hivemind posted in Threat Bulletin, APT36, Spear Phishing, Remote Access Trojan, cyber espionage, LNK Malware
Verticals Targeted: Government, Academia
Regions Targeted: India
Related Families: None
Executive Summary
APT36, also known as Transparent Tribe, a Pakistan-aligned threat actor, has launched a targeted cyber espionage campaign against Indian governmental, academic, and strategic entities using sophisticated deception techniques. The operation delivers a multi-stage Remote Access Trojan (RAT) through a weaponized LNK file disguised as a PDF, enabling persistent access, surveillance, and data exfiltration with minimal detection risk. The campaign has targeted government, academic, and strategic entities in India.
MuddyWater's UDPGangster Backdoor
Dec 15, 2025, 2:04:50 PM / by The Hivemind posted in Threat Bulletin, anti-analysis techniques, Phishing Campaigns, cyber espionage, VBA macros, UDPGangster, UDP backdoor
Verticals Targeted: Not specified
Regions Targeted: Turkey, Israel, Azerbaijan
Related Families: Phoenix
MuddyWater Targets MENA Governments With Phoenix Backdoor
Nov 3, 2025, 2:09:14 PM / by The Hivemind posted in Threat Bulletin, MuddyWater, Phishing Campaign, credential stealers, cyber espionage, Middle East targeting, VBA macros, FakeUpdate injector, Iran APT, Phoenix Backdoor, RMM tools
Verticals Targeted: Government
Regions Targeted: Middle East, North Africa
Related Families: Phoenix, FakeUpdate
Executive Summary
A sophisticated phishing operation has been attributed to the Iran-linked APT MuddyWater, deploying an updated Phoenix backdoor to conduct espionage against government and international entities. The campaign leverages compromised mailboxes and macro-enabled Word documents to deliver custom injectors and persistence mechanisms, highlighting the group's reliance on trusted channels for initial access.
Salt Typhoon Targets European Telecom
Oct 28, 2025, 12:48:06 PM / by The Hivemind posted in Threat Bulletin, Telecommunications, Salt Typhoon, DLL sideloading, zero-day exploits, SNAPPYBEE, Citrix NetScaler, cyber espionage
Verticals Targeted: Telecommunications
Regions Targeted: Europe
Related Families: SNAPPYBEE (Deed RAT)