Skip to main content

Campaign Threats

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Type: Campaign

Filtered Threats

Click on any threat for detailed analysis and mitigation recommendations

An Israeli influence-for-hire company called BlackCore has been identified conducting digital manipulation campaigns across multiple countries. The company operates through a sophisticated infrastructure offering services including discourse dominance, organic engagement manipulation, and counter-operations. Researchers identified a specific campaign involving a 14-week training program delivered to Angolan government employees in early 2026, which included the creation and deployment of fake social media personas and coordinated inauthentic behavior. The operation utilized AI-generated profile pictures, fake news outlets like 'Agita News', and coordinated amplification tactics across Facebook, Instagram, and TikTok. BlackCore's promotional materials openly advertised their capabilities to conduct deceptive influence operations on behalf of government clients, demonstrating how influence-for-hire services have become accessible to state actors seeking to manipulate online discourse.

Join the discussion

A significant supply chain attack compromised Brevo's infrastructure on September 14, 2026, affecting over 100,000 customer websites. Attackers injected malicious code into Brevo's JavaScript assets and widgets, delivering two distinct payloads: a WordPress plugin backdoor automatically installed when site administrators visited their own sites while logged in, and ClickFix overlays targeting regular visitors. The attack vector involved modification of Brevo's CDN-hosted files and creation of malicious subdomains under sendibt1.com. Evidence suggests attackers gained access to Brevo's Cloudflare account, allowing them to modify DNS records and rewrite content dynamically. The malicious activity lasted approximately four hours, from 16:05 to 20:12 UTC. Brevo's prominent clients include eBay, Louis Vuitton, Michelin, and Amnesty International, amplifying the attack's potential impact significantly.

Join the discussion

Since early May 2026, a large-scale phishing campaign has targeted individuals with fraudulent text messages claiming their T-Mobile rewards points are about to expire. The messages create urgency by stating that point balances, typically cited as 18,400 points, will expire imminently if not redeemed. Recipients are directed to click on phishing links using rotating domains designed to mimic legitimate T-Mobile websites. The campaign has generated over 1,000 closely related message templates with only superficial variations in salutations, dates, and point balances. The operation experienced two major spikes in activity before declining. The criminals employed at least 81 domains over four months, all following a recognizable pattern. These messages use generic greetings and formal language to appear legitimate, exploiting social engineering tactics to trick recipients into divulging login credentials, personal information, or payment details.

Join the discussion

BragJack is a security research discovery demonstrating how a single browser extension can hijack internal browser agents across five Chromium-based browsers: Chrome, Comet, Edge, Opera Neon, and Claude in Chrome. The attack leverages the declarativeNetRequest (DNR) API to weaken security headers and redirect JavaScript resources, enabling code execution within privileged browser contexts. This allows access to sensitive capabilities such as local file access, browsing history, camera and microphone, and screenshots without user interaction. The research resulted in two CVEs and $20,000 in bounty rewards from major vendors. The vulnerabilities primarily exploit weaknesses in how these browsers handle network requests and security policies within embedded web views. No patch or remediation status is provided in the source data.

Join the discussion

A Chinese-speaking threat actor group known as Red Heron exploited a recently disclosed remote code execution vulnerability (CVE-2026-60004) in Gitea, a self-hosted Git service, in a multinational campaign. The campaign targeted internet-facing Gitea instances across multiple countries, including Canada, Argentina, Taiwan, the United States, and Sri Lanka, focusing on sectors such as defense, elections, energy, aerospace, telecommunications, government, and research. The attackers used automated tools to steal source code, credentials, and maintain persistent access, including root-level control on some infrastructure. They deployed a novel Linux implant named JITTERLY with extensive post-exploitation capabilities and embedded a previously undocumented rootkit called SIXZUT to maintain stealth and persistence. The campaign demonstrates rapid weaponization of n-day vulnerabilities in development platforms and highlights significant risks to source code confidentiality and infrastructure integrity.

Join the discussion

Cybercriminals have created numerous fake websites mimicking Bitrefill, a legitimate cryptocurrency-based gift card and eSIM retailer. These fraudulent sites appear in search engine results and use lookalike domains incorporating the Bitrefill brand name with added words or character substitutions, including internationalized domain names using Punycode. Victims are guided through convincing checkout processes that replicate Bitrefill's legitimate payment flow, complete with cryptocurrency options, QR codes, and countdown timers. However, payments are sent directly to attacker-controlled cryptocurrency addresses rather than Bitrefill, with virtually no chance of recovery. The operation demonstrates sophisticated measurement using commercial analytics software to optimize conversion rates, indicating organized criminal activity rather than opportunistic fraud.

Join the discussion

A campaign named Miasma exploited a vulnerability in the Model Context Protocol (MCP) tool configuration process to gain OS-level access to 73 GitHub repositories, including one owned by Microsoft Azure. The attack leverages the fact that MCP clients trust tool descriptions as executable instructions without re-prompting or sandboxing, allowing malicious edits to MCP config files to run with developer privileges. This attack class, known as MCP tool poisoning, was first documented in 2025 and escalated to real-world exploitation by mid-2026. The campaign abused the approval process tied to server names rather than content, enabling malicious commands to execute automatically after initial approval. OWASP ranks this attack third in its MCP Top 10 threats. Mitigations include rigorous code review of MCP config changes, pinning tool definitions, scoping privileges per tool, maintaining allowlists of MCP servers, and sandboxing agent execution.

Join the discussion

A malicious browser extension called 'Twitch Enhanced Viewer | JeetBot' distributed on Chrome Web Store and Firefox Add-ons captures and forwards users' live Twitch OAuth session tokens to Russian-controlled proxy servers. The extension, with approximately 30,000 Chrome users and 552 Firefox users, markets itself as a quality-of-life tool for blocking ads and unlocking streams. While delivering these features, it secretly extracts users' account-scoped OAuth tokens and forwards them as query parameters to operator-controlled infrastructure. Current versions append tokens inline during video playlist redirects, while earlier builds explicitly POSTed tokens to dedicated collection endpoints. The operator is identified as a commercial Russian bot service called JeetBot, with infrastructure hosted across German and cloud providers.

Join the discussion

Threat actors exploited trusted brands and cloud services in a sophisticated web campaign combining fraudulent DocuSign workflows, Florida healthcare screening lures, and deceptive cloud infrastructure to deploy ConnectWise ScreenConnect Access clients. The attack utilized Cloudflare Pages hosting with fake Cloudflare verification workflows to establish legitimacy. Victims were socially engineered to download a ZIP archive containing a malicious HTA file that employed Base64-encoded VBScript, fake Adobe interfaces, UAC privilege escalation, and Microsoft Defender SmartScreen registry modifications. The attack leveraged living-off-the-land techniques using native Windows tools like mshta.exe, curl.exe, and msiexec.exe for silent ScreenConnect installation, ultimately providing unauthorized remote access. The campaign was classified as Zero Hour Fraudulent and blocked at the web entry point before payload delivery could occur.

Join the discussion

Threat actors are leveraging generative AI to enhance financial fraud campaigns targeting enterprise organizations. Between August 3-5, over one million phishing emails were distributed through third-party infrastructure, primarily targeting US-based organizations (87.7%). The attacks employed sophisticated executive impersonation, specifically CEOs and CFOs, combined with fabricated ServiceNow invoices requesting ACH transfers of approximately $50,000. The campaign demonstrated multiple AI-assisted indicators including extensive HTML comments, structured section labeling, and uniform template construction. Attackers registered lookalike domains and created elaborate forwarded email threads between spoofed executives to establish legitimacy. The fraudulent invoices contained detailed branding, personalized recipient information, and specific payment instructions to attacker-controlled bank accounts. Multiple layered social engineering techniques were deployed to reduce recipient skepticism and convince acc...

Join the discussion

Showing 1 to 10 of 768 results

Filters:Type: Campaign
Page 1 of 77
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses