Threats Tagged 'nation-state'
View all threats tagged with 'nation-state'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'nation-state'
Click on any threat for detailed analysis and mitigation recommendations
Kazuar is a sophisticated malware attributed to Russian state actor Secret Blizzard, having evolved from a traditional backdoor into a highly modular peer-to-peer botnet ecosystem. The malware comprises three distinct module types—Kernel, Bridge, and Worker—that distribute functionality across infected systems. A leadership election mechanism ensures only one Kernel module communicates externally, reducing detection opportunities. The architecture supports flexible configuration with over 150 options, multiple C2 channels including HTTP, WebSockets, and Exchange Web Services, and extensive data collection capabilities. Secret Blizzard primarily targets government, diplomatic, and defense organizations in Europe, Central Asia, and Ukraine to support Russian foreign policy and military intelligence objectives. The botnet maintains persistent access through sophisticated IPC mechanisms, staged data exfiltration during working hours, and comprehensive anti-analysis checks. Join the discussion | AlienVault OTX General | 05/14/2026, 20:10:32 UTC Added: 05/15/2026, 18:51:38 UTC |
The Harvester APT group has developed a highly-evasive Linux version of its GoGra backdoor that leverages Microsoft Graph API and Outlook mailboxes as a covert command-and-control channel to bypass traditional network defenses. Initial VirusTotal submissions originated from India and Afghanistan, indicating these regions as primary targets. The attackers use social engineering with tailored decoy documents masquerading as legitimate files, including references to Indian food delivery services. The backdoor uses hardcoded Azure AD credentials to poll mailboxes every two seconds, executing commands received via email and exfiltrating results back to operators. Analysis confirms this Linux variant shares nearly identical code with a previously known Windows version, including matching spelling errors, demonstrating the group's multi-platform development strategy and continued expansion of capabilities targeting South Asia for espionage purposes. Join the discussion | AlienVault OTX General | 04/22/2026, 11:35:15 UTC Added: 04/22/2026, 15:31:05 UTC |
Airstalk is a newly discovered Windows-based malware family used by a suspected nation-state actor, CL-STA-1009, in supply chain attacks targeting business process outsourcing companies. It exists in PowerShell and . NET variants, with the latter exhibiting advanced features such as multi-threaded command-and-control (C2) protocols, versioning, and signed binaries. The malware abuses the AirWatch API for mobile device management to covertly communicate with its C2 infrastructure. It exfiltrates sensitive browser data including cookies, history, and bookmarks, enabling extensive data theft. Its evasion techniques and adaptive behavior make it particularly dangerous in third-party vendor environments. No known public exploits exist yet, but the threat poses a medium severity risk with potential for significant impact on confidentiality and operational security. European organizations relying on outsourcing and mobile device management solutions are at elevated risk, especially in countries with strong BPO sectors. Mitigation requires enhanced supply chain security, monitoring of AirWatch API usage, and behavioral detection of anomalous PowerShell and . NET activities. Join the discussion | AlienVault OTX General | 10/29/2025, 12:35:47 UTC Added: 10/29/2025, 13:30:11 UTC |
Showing 1 to 3 of 3 results