Threats Affecting Turkey
View all threats affecting or targeting Turkey. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Affecting Turkey
Click on any threat for detailed analysis and mitigation recommendations
Between late September 2025 and early April 2026, the threat group BlueDelta conducted espionage campaigns targeting government and diplomatic organizations in Romania, Spain, and Türkiye. They deployed HOOKEDGE, a lightweight Windows batch-script backdoor, via macro-enabled Word documents with diplomatic-themed lures. HOOKEDGE shares code and tradecraft overlap with the HEADLACE backdoor and abuses legitimate webhook services for command-and-control, payload staging, and data exfiltration. The implant was continuously refined to evade sandbox detection and adapt to webhook service constraints. BlueDelta used a tiered operational model, deploying second-stage payloads with shorter beaconing intervals for high-value targets while preserving initial access infrastructure. Join the discussion | AlienVault OTX General | 08/27/2026, 17:37:41 UTC Added: 08/28/2026, 09:07:13 UTC |
Tracked as CVE-2026–59310, the directory traversal bug allows remote attackers to execute arbitrary code. The post Critical VMware vCenter Vulnerability in Attackers’ Crosshairs appeared first on SecurityWeek . Join the discussion | SecurityWeek | 08/13/2026, 09:06:40 UTC Added: 08/13/2026, 09:11:14 UTC |
This report highlights a cyber espionage campaign attributed to the Iranian APT group Charming Kitten, targeting eight countries and eight critical sectors simultaneously. The campaign, dubbed Operation Olalampo, affects Egypt, Saudi Arabia, UAE, Turkey, Hungary, Turkmenistan, Israel, and South America, focusing on government, healthcare, financial services, energy, education, telecommunications, defense, and industrial sectors. The information is sourced from a Reddit post linking to a GitHub repository simulating adversary tactics. No specific vulnerabilities or exploits are detailed, and no affected software versions are identified. CriticalCampaign Join the discussion | Reddit BlueTeam | 08/03/2026, 07:07:43 UTC Added: 08/03/2026, 19:33:10 UTC |
OkoBot is a malicious framework delivering over 20 payloads aimed at stealing cryptocurrency wallet seed phrases, credentials, and sensitive data. It spreads via ClickFix attacks and trojanized GitHub repositories. The infection chain involves multiple stages, starting with a PowerShell script that installs an SSH bot to collect system info and disable Windows Defender notifications. Key modules include browser injectors, fake seed phrase prompts targeting hardware wallets, keyloggers, and spyware that records video and keystrokes. The campaign has been active since early 2025 with a global reach, primarily impacting Brazil, Vietnam, Canada, Mexico, and Turkey. Indicators of compromise and detailed telemetry are available from Kaspersky. No official patch or remediation is noted. Join the discussion | Bleeping Computer | 07/16/2026, 19:09:35 UTC Added: 07/16/2026, 19:17:35 UTC |
In January 2026, researchers identified a sophisticated malware framework dubbed OkoBot that targets cryptocurrency users through a multi-stage infection chain. The campaign begins with TookPS PowerShell scripts delivered via ClickFix attacks or fake software on GitHub. An automated SSH bot deploys over 20 malicious modules including HDUtil launcher, browser extension injectors installing Rilide stealer, and specialized tools like SeedHunter for wallet seed phrase theft and OkoSpyware for window capture. The framework uses VMProtect obfuscation, UAC bypass techniques, and maintains persistence through RDP access and scheduled tasks. Victims span more than 25 countries with concentrations in Brazil, Vietnam, Canada, Mexico, and Turkey. Attribution suggests Russian-speaking threat actors based on geoblocking patterns and Russian language artifacts. Join the discussion | AlienVault OTX General | 07/15/2026, 11:58:10 UTC Added: 07/15/2026, 21:47:49 UTC |
We analyze how fake IPTV apps gain control of Android devices, abuse screen access features, and steal credentials, cash, and crypto assets. Join the discussion | Kaspersky Security Blog | 05/29/2026, 13:02:47 UTC Added: 05/29/2026, 13:09:53 UTC |
Kaspersky experts have detected a supply chain attack using the popular DAEMON Tools software. Join the discussion | Kaspersky Security Blog | 05/05/2026, 12:09:52 UTC Added: 05/05/2026, 12:23:38 UTC |
DarkSword and Coruna are new iOS malware strains that infect devices through zero-click attacks. Learn how these threats operate, which iOS versions are at risk, and how to protect your devices. Join the discussion | Kaspersky Security Blog | 04/17/2026, 13:09:31 UTC Added: 04/17/2026, 13:17:04 UTC |
A threat cluster has been identified leveraging a customized Adwind (Java RAT) variant with polymorphic characteristics to deliver JanaWare ransomware. The campaign specifically targets Turkish users through geofencing mechanisms that check system locale and external IP geolocation. Active since at least 2020, the operation primarily affects home users and small to medium-sized businesses. Initial access occurs via phishing emails with malicious Java archives distributed through Google Drive links. The ransomware employs AES encryption and communicates over Tor networks, demanding modest ransoms between $200-$400. The malware uses multiple obfuscation techniques including Stringer and Allatori obfuscators, implements file pumping for polymorphism, and disables Windows security features before encryption. Victims are instructed to contact attackers through qTox or dedicated Tor onion sites. Join the discussion | AlienVault OTX General | 04/15/2026, 15:04:44 UTC Added: 04/15/2026, 16:01:51 UTC |
0 The new CrystalX remote access Trojan combines pranks with full control over the victim’s computer. It also spies on its victims, steals their cryptocurrency and accounts, and uses advanced methods to bypass protection. We explain how it works, and how to avoid infection. Join the discussion | Kaspersky Security Blog | 04/01/2026, 15:05:19 UTC Added: 04/01/2026, 15:08:42 UTC |
Showing 1 to 10 of 275 results