Threat Intelligence
Community feed · APT

Nation-State Threat Intelligence

The latest threat research aggregated from Nation-State Threat Intelligence — browse the feed inside NivX, click through to read the full article on the source site.

Article previews are curated from Nation-State Threat Intelligence. We show the title, cover image and a short snippet here; clicking any card opens the full article on the source site so the original authors get proper credit.
Threat Research

Protecting organizations from AI-assisted executive impersonation and invoice fraud

Microsoft examines an AI-assisted business email compromise campaign that used executive impersonation and fake invoices to target finance teams with ACH payment fraud. The post Protecting organizatio…

Sep 10, 2026
Read on APT
Threat Research

Passkey-themed social engineering leads to identity and cloud compromise

Passkey-themed social engineering is being used to compromise identities and enable broader cloud attacks. Learn how threat actors establish MFA persistence, abuse Microsoft Graph for reconnaissance,…

Sep 9, 2026
Read on APT
Threat Research

ASCII smuggling crosses over from AI prompt injection to phishing evasion

Invisible Unicode characters popularized for hiding instructions from AI models are now being used to obfuscate words before email filters parse them. The post ASCII smuggling crosses over from AI pro…

Sep 3, 2026
Read on APT
Threat Research

Impersonating IT support: how threat actors turn a remote session into enterprise-wide access

Microsoft Threat Intelligence observed a human-operated intrusion campaign that abuses Microsoft Teams external collaboration to impersonate IT support, gain remote access, and deploy a Node.js-based…

Sep 2, 2026
Read on APT
Threat Research

Counterfeit installers to system compromise: Tracking a deceptive software download campaign

An active campaign is impersonating legitimate software vendors to deliver malware through look-alike download pages and regenerated installer archives. Microsoft Defender Experts shares observed atta…

Sep 1, 2026
Read on APT
Threat Research

TerminalFix campaign deploys a reverse tunnel through multistage intrusion

Microsoft Threat Intelligence provides analysis of a ClickFix campaign that uses fake CAPTCHA prompts, DLL sideloading, and a reverse tunnel, with detections and hunting guidance. The post TerminalFix…

Aug 29, 2026
Read on APT
Threat Research

DeadLock ransomware: Breaking down a Rust-based encryptor with decentralized recovery infrastructure

Microsoft Threat Intelligence examines DeadLock ransomware, an emerging financially motivated operation distinguished by its use of decentralized infrastructure to support victim communications, negot…

Aug 10, 2026
Read on APT
Threat Research

From open lures to cloaked gates: How a macOS ClickFix campaign learned to hide

A macOS ClickFix campaign shifted tactics from openly serving infostealer lures to hiding them behind a browser-fingerprinting gate. The change makes malicious infrastructure harder to detect while gi…

Aug 5, 2026
Read on APT
Threat Research

ChainDrop supply chain compromise: Anatomy of a self-propagating worm

A credential-stealing worm hidden in more than 400 compromised npm packages automatically spread across software ecosystems by republishing malicious updates. This analysis details the attack chain, a…

Aug 4, 2026
Read on APT
Threat Research

CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft

Storm-2945, a sub-cluster of the Russian threat actor Midnight Blizzard, has been observed compromising the sign-in portals of hospitality-related organizations such as hotels since May 2026 in order…

Jul 31, 2026
Read on APT