| 2026-08-26 |
Joint CSA: China-Linked Hacking Group QTFY Targets Military and Critical Infrastructure with Malicious Distributed Systems
The Federal Bureau of Investigation, National Security Agency, and Cyber National Mission Force are releasing this joint cybersecurity advisory to alert organizations concerning China-linked cyber threat actors, who use the acronyms QTFY, QT, and QTCYBER for themselves and their tools and have developed malicious distributed platforms to compromise the networks of US and foreign organizations.
|
FBI
NSA
|
| 2026-04-07 |
Iranian-Affiliated Cyber Actors Exploit Programmable Logic Controllers Across US Critical Infrastructure
This activity has led to PLC disruptions across several U.S. critical infrastructure sectors through malicious interactions with the project file and manipulation of data on human machine interface (HMI) and supervisory control and data acquisition (SCADA) displays, resulting in operational disruption and financial loss. U.S.
|
CISA
DOE
EPA
FBI
NIST
NSA
|
| 2024-10-10 |
Update on SVR Cyber Operations and Vulnerability Exploitation
The Federal Bureau of Investigation (FBI), the The authoring agencies recommend the following mitigations to protect their networks. Mission Force (CNMF), and the United See the Mitigations section for the complete Kingdom’s National Cyber Security Centre (NCSC-UK) are releasing this joint Cybersecurity Advisory (CSA) to highlight the tactics, • Reduce attack surface by disabling techniques, and procedures (TTPs) employed by Internet-accessible s…
|
FBI
NCSC-UK
NSA
|
| 2024-09-18 |
People's Republic of China-Linked Actors Compromise Routers and IoT Devices for Botnet Operations
The actors may then use the botnet as a proxy to conceal their identities while deploying distributed denial of service (DDoS) attacks or compromising targeted U.S. networks. Integrity Technology Group (Integrity Tech), a PRC-based company, has controlled and managed a botnet active since mid-2021.
|
FBI
|
| 2024-09-05 |
Russian Military Cyber Actors Target US and Global Critical Infrastructure
GRU Unit 29155 cyber actors began deploying the destructive WhisperGate malware against multiple Ukrainian victim organizations as early as January 13, 2022. These cyber actors are separate from other known and more established GRU-affiliated cyber groups, such as Unit 26165 and Prioritize routine system updates and remediate known exploited vulnerabilities. Segment networks to prevent the spread of malicious activity.
|
ASD/ACSC
CCCS
CISA
FBI
MIVD
NCSC-UK
NIST
NSA
Treasury
USCC
|
| 2024-09-05 |
Russian Military Cyber Actors Target U.S. and Global Critical Infrastructure
GRU Unit 29155 cyber actors began deploying the destructive WhisperGate malware against multiple Ukrainian victim organizations as early as January 13, 2022. These cyber actors are separate from other known and more established GRU-affiliated cyber groups, such as Unit 26165 and Prioritize routine system updates and remediate known exploited vulnerabilities. Segment networks to prevent the spread of malicious activity.
|
ASD/ACSC
CCCS
CISA
FBI
MIVD
NCSC-UK
NSA
Treasury
USCC
|
| 2024-07-25 |
North Korea Cyber Group Conducts Global Espionage Campaign to Advance Regime’s Military and Nuclear Programs
Cyber National Mission Force (CNMF) U.S. Cybersecurity and Infrastructure Security Agency (CISA) U.S. Department of Defense Cyber Crime Center (DC3) U.S. National Security Agency (NSA) Republic of Korea’s National Intelligence Service (NIS) Republic of Korea’s National Police Agency (NPA) United Kingdom’s National Cyber Security Centre (NCSC) The RGB 3rd Bureau includes a DPRK (aka North Korean) state-sponsored cyber group known publi…
|
CISA
DC3
FBI
NCSC-UK
NIS
NSA
|
| 2024-07-25 |
North Korea Cyber Group Conducts Global Espionage Campaign to Advance Regime's Military and Nuclear Programs
The group primarily targets defense, aerospace, nuclear, and engineering entities to obtain sensitive and classified type of activity; number of people affected; type of equipment used for the activity; the name of the submitting company or organization; and a designated point of contact.
|
CISA
DC3
FBI
NCSC-UK
NIS
NSA
|
| 2024-07-09 |
State-Sponsored Russian Media Leverages Meliorator Software for Foreign Malign Influence Activity
Affiliates of RT (formerly Russia Today), a Russian state-sponsored media organization, used Meliorator—a covert artificial intelligence (AI) enhanced software package—to create fictitious online personas, representing a number of nationalities, to post content on X (formerly Twitter).
|
AIVD
CCCS
FBI
MIVD
|
| 2024-02-26 |
SVR Cyber Actors Adapt Tactics for Initial Cloud Access
The US National Security Agency (NSA), the US Cybersecurity and Infrastructure Security Agency (CISA), the US the Canadian Centre for Cyber Security (CCCS) and the New Zealand National Cyber Security Centre (NCSC) agree with this attribution and the details This advisory provides an overview of TTPs deployed by the actor to gain initial access into the cloud environment and includes advice to detect and mitigate The NCSC has previously detailed h…
|
ASD/ACSC
CCCS
CISA
FBI
NCSC-UK
NSA
|