Threat Intelligence
Community feed · APT

Nation-State Threat Intelligence

The latest threat research aggregated from Nation-State Threat Intelligence — browse the feed inside NivX, click through to read the full article on the source site.

Article previews are curated from Nation-State Threat Intelligence. We show the title, cover image and a short snippet here; clicking any card opens the full article on the source site so the original authors get proper credit.
Threat Research

DeadLock ransomware: Breaking down a Rust-based encryptor with decentralized recovery infrastructure

Microsoft Threat Intelligence examines DeadLock ransomware, an emerging financially motivated operation distinguished by its use of decentralized infrastructure to support victim communications, negot…

Aug 10, 2026
Read on APT
Threat Research

From open lures to cloaked gates: How a macOS ClickFix campaign learned to hide

A macOS ClickFix campaign shifted tactics from openly serving infostealer lures to hiding them behind a browser-fingerprinting gate. The change makes malicious infrastructure harder to detect while gi…

Aug 5, 2026
Read on APT
Threat Research

ChainDrop supply chain compromise: Anatomy of a self-propagating worm

A credential-stealing worm hidden in more than 400 compromised npm packages automatically spread across software ecosystems by republishing malicious updates. This analysis details the attack chain, a…

Aug 4, 2026
Read on APT
Threat Research

CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft

Storm-2945, a sub-cluster of the Russian threat actor Midnight Blizzard, has been observed compromising the sign-in portals of hospitality-related organizations such as hotels since May 2026 in order…

Jul 31, 2026
Read on APT
Threat Research

Email threat landscape: Q2 2026 trends and insights

In the second quarter of 2026, the continuing effects of Microsoft’s disruption of the Tycoon2FA phishing platform contributed to sustained declines in several major phishing techniques, while threat…

Jul 23, 2026
Read on APT
Threat Research

ACR Stealer: Two observed intrusion chains amid increased threat activity

From late April 2026 to mid-June 2026, Microsoft Defender Experts observed increased ACR Stealer activity across customer environments. These campaigns are successfully using ClickFix lures to steal b…

Jul 16, 2026
Read on APT
Threat Research

Unpacking the AsyncAPI npm supply chain compromise and import-time payload delivery

Threat actors compromised AsyncAPI packages and weaponized trusted CI/CD workflows to distribute malware through npm. This analysis breaks down the attack chain, payload delivery, and recommended defe…

Jul 16, 2026
Read on APT
Threat Research

GigaWiper: Anatomy of a destructive backdoor assembled from multiple malware

GigaWiper, also tracked as BLUERABBIT, is a destructive backdoor that combines multiple wiping and ransomware-like capabilities into a single operational platform. This blog analyzes how the malware i…

Jul 9, 2026
Read on APT
Threat Research

StealC and Amadey: Breaking down infostealers and the cybercrime services that deliver them

On June 24, 2026, Microsoft’s Digital Crimes Unit (DCU) facilitated the takedown, suspension, and blocking of domains that formed the backbone of the StealC and Amadey infrastructure. This blog is a t…

Jun 24, 2026
Read on APT
Threat Research

From package to postinstall payload: Inside the Mastra npm supply chain compromise by Sapphire Sleet

A poisoned npm package infected 140+ projects with a hidden payload. This report highlights how to detect, hunt, and defend against supply chain attacks using Microsoft Defender and actionable threat…

Jun 18, 2026
Read on APT

Made with Emergent