Threat intelligence

Cyber campaigns and intrusion activity

Follow named operations from their first known activity through the latest source-backed attribution. Each page keeps campaign evidence separate from the broader history of the actors involved.

56Campaigns tracked
56Marked active
1Seen in the past year
56Matching this view

56 campaigns

Campaign dates describe the activity window recorded by the source. They are not publication dates unless explicitly labeled.

ActiveMITRE ATT&CK

2025 Poland Wiper Attacks

2025 Poland Wiper Attacks is a Russian state-sponsored campaign that conducted destructive cyberattacks against Polish energy infrastructure in December 2025. Targets included more than 30 wind and photovoltaic farms, a combined heat and power (CHP) plant, ...

0 actors0 related CVEs0 techniques
Investigate campaign
ActiveMITRE ATT&CK

Anthropic AI-orchestrated Campaign

The Anthropic AI-orchestrated Campaign was conducted in September 2025 by a likely China nexus espionage actor identified as GTG-1002. The Anthropic AI-orchestrated Campaign was a highly coordinated operation that manipulated Claude Code to perform reconnai...

0 actors0 related CVEs0 techniques
Investigate campaign
ActiveMITRE ATT&CK

Salesforce Data Exfiltration

The Salesforce Data Exfiltration campaign began in October 2024 with financially-motivated threat actor UNC6040 using Spearphishing Voice (vishing) to compromise corporate Salesforce instances for large-scale data theft and extortion. Following the initial ...

0 actors0 related CVEs0 techniques
Investigate campaign
ActiveMITRE ATT&CK

Quad7 Activity

Quad7 Activity, also known as CovertNetwork-1658 or the 7777 Botnet, is a network of compromised small office/home office (SOHO) routers. The botnet was initially composed primarily of TP-Link routers and was named Quad7 due to compromised devices exposing ...

0 actors0 related CVEs0 techniques
Investigate campaign
ActiveMITRE ATT&CK

SharePoint ToolShell Exploitation

The SharePoint ToolShell Exploitation campaign was conducted in July 2025 and encompassed the first waves of exploitation against incompletely patched spoofing (CVE-2025-49706) and remote code execution (CVE-2025-49704) vulnerabilities affecting on-premises...

0 actors0 related CVEs0 techniques
Investigate campaign
ActiveMITRE ATT&CK

RedPenguin

The RedPenguin project was launched by Juniper in July 2024 to investigate reported malware infections of Juniper MX Series routers. RedPenguin activity was separately attributed to UNC3886 and included the deployment of multiple custom versions of the publ...

Attributed actorsUNC3886
1 actors0 related CVEs49 techniques
Investigate campaign
ActiveMITRE ATT&CK

RedDelta Modified PlugX Infection Chain Operations

RedDelta Modified PlugX Infection Chain Operations was executed by Mustang Panda from mid-2023 through the end of 2024 against multiple entities in East and Southeast Asia. RedDelta Modified PlugX Infection Chain Operations involved phishing to deliver mali...

Attributed actorsMustang Panda
1 actors1 related CVEs85 techniques
Investigate campaign
ActiveMITRE ATT&CK

APT28 Nearest Neighbor Campaign

APT28 Nearest Neighbor Campaign was conducted by APT28 from early February 2022 to November 2024 against organizations and individuals with expertise on Ukraine. APT28 primarily leveraged living-off-the-land techniques, while leveraging the zero-day exploit...

Attributed actorsAPT28
1 actors4 related CVEs93 techniques
Investigate campaign
ActiveMITRE ATT&CK

Versa Director Zero Day Exploitation

Versa Director Zero Day Exploitation was conducted by Volt Typhoon from early June through August 2024 as zero-day exploitation of Versa Director servers controlling software-defined wide area network (SD-WAN) applications. Since tracked as CVE-2024-39717, ...

Attributed actorsVolt Typhoon
1 actors5 related CVEs81 techniques
Investigate campaign
ActiveMITRE ATT&CK

Operation Digital Eye

Operation Digital Eye was conducted in June and July of 2024 by suspected People's Republic of China (PRC)-nexus threat actors targeting business-to-business IT service providers in Southern Europe. Operation Digital Eye activity included the use of Visual ...

0 actors0 related CVEs0 techniques
Investigate campaign
ActiveMITRE ATT&CK

APT41 DUST

APT41 DUST was conducted by APT41 from 2023 to July 2024 against entities in Europe, Asia, and the Middle East. APT41 DUST targeted sectors such as shipping, logistics, and media for information gathering purposes. APT41 used previously-observed malware suc...

Attributed actorsAPT41
1 actors3 related CVEs82 techniques
Investigate campaign
ActiveMITRE ATT&CK

J-magic Campaign

The J-magic Campaign was active from mid-2023 to at least mid-2024 and featured the use of the J-magic backdoor, a custom cd00r variant tailored for use against Juniper routers. The J-magic Campaign targeted Junos OS routers serving as VPN gateways primaril...

0 actors0 related CVEs0 techniques
Investigate campaign
ActiveMITRE ATT&CK

FLORAHOX Activity

FLORAHOX Activity is conducted using a hybrid operational relay box (ORB) network, which combines two types of infrastructure: compromised devices and leased Virtual Private Servers (VPS). The compromised devices include end-of-life routers and IoT devices,...

0 actors0 related CVEs0 techniques
Investigate campaign
ActiveMITRE ATT&CK

SPACEHOP Activity

SPACEHOP Activity is conducted through commercially leased Virtual Private Servers (VPS), otherwise known as provisioned Operational Relay Box (ORB) networks. The network leveraged for SPACEHOP Activity enabled China-nexus cyber threat actors – such as APT5...

Attributed actorsAPT5, Ke3chang
2 actors0 related CVEs63 techniques
Investigate campaign
ActiveMITRE ATT&CK

Operation MidnightEclipse

Operation MidnightEclipse was a campaign conducted in March and April 2024 that involved initial exploit of zero-day vulnerability CVE-2024-3400, a critical command injection vulnerability in the GlobalProtect feature of Palo Alto Networks PAN-OS.

0 actors0 related CVEs0 techniques
Investigate campaign
ActiveMITRE ATT&CK

ArcaneDoor

ArcaneDoor is a campaign targeting networking devices from Cisco and other vendors between July 2023 and April 2024, primarily focused on government and critical infrastructure networks. ArcaneDoor is associated with the deployment of the custom backdoors L...

0 actors0 related CVEs0 techniques
Investigate campaign
ActiveMITRE ATT&CK

ShadowRay

ShadowRay was a campaign that began in late 2023 targeting the education, cryptocurrency, biopharma, and other sectors through a vulnerability (CVE-2023-48022) in the Ray AI framework named ShadowRay. According to security researchers ShadowRay was the firs...

0 actors0 related CVEs0 techniques
Investigate campaign
ActiveMITRE ATT&CK

Pikabot Distribution February 2024

Pikabot was distributed in Pikabot Distribution February 2024 using malicious emails with embedded links leading to malicious ZIP archives requiring user interaction for follow-on infection. The version of Pikabot distributed featured significant changes ov...

0 actors0 related CVEs0 techniques
Investigate campaign
ActiveMITRE ATT&CK

Cutting Edge

Cutting Edge was a campaign conducted by suspected China-nexus espionage actors, variously identified as UNC5221/UTA0178 and UNC5325, that began as early as December 2023 with the exploitation of zero-day vulnerabilities in Ivanti Connect Secure (previously...

0 actors0 related CVEs0 techniques
Investigate campaign
ActiveMITRE ATT&CK

FrostyGoop Incident

FrostyGoop Incident took place in January 2024 against a municipal district heating company in Ukraine. Following initial access via likely exploitation of external facing services, FrostyGoop was used to manipulate ENCO control systems via legitimate Modbu...

0 actors0 related CVEs0 techniques
Investigate campaign
ActiveMITRE ATT&CK

KV Botnet Activity

KV Botnet Activity consisted of exploitation of primarily “end-of-life” small office-home office (SOHO) equipment from manufacturers such as Cisco, NETGEAR, and DrayTek. KV Botnet Activity was used by Volt Typhoon to obfuscate connectivity to victims in mul...

Attributed actorsVolt Typhoon
1 actors5 related CVEs81 techniques
Investigate campaign
ActiveMITRE ATT&CK

Water Curupira Pikabot Distribution

Pikabot was distributed in Water Curupira Pikabot Distribution throughout 2023 by an entity linked to BlackBasta ransomware deployment via email attachments. This activity followed the take-down of QakBot, with several technical overlaps and similarities wi...

0 actors0 related CVEs0 techniques
Investigate campaign
ActiveMITRE ATT&CK

3CX Supply Chain Attack

The 3CX Supply Chain Attack was the first publicly reported case of one supply chain compromise triggering another, leading to a cascading, two-stage intrusion. The initial supply chain attack began when a 3CX employee downloaded and executed a trojanized, ...

Attributed actorsAppleJeus
1 actors0 related CVEs2 techniques
Investigate campaign
ActiveMITRE ATT&CK

C0033

C0033 was a PROMETHIUM campaign during which they used StrongPity to target Android users. C0033 was the first publicly documented mobile campaign for PROMETHIUM, who previously used Windows-based techniques.

Attributed actorsPROMETHIUM
1 actors0 related CVEs11 techniques
Investigate campaign
How we handle attribution

Every attribution includes its source.

A campaign is a named cluster of related activity from an identified source. Different publishers may define the same operation differently or revise an attribution later.

SecurityAlert keeps the source and confidence with each actor relationship. Actor-level CVEs, techniques, malware, and indicators are displayed as investigation context rather than direct campaign evidence unless the underlying source makes that connection.