Threat intelligence

Cyber campaigns and intrusion activity

Follow named operations from their first known activity through the latest source-backed attribution. Each page keeps campaign evidence separate from the broader history of the actors involved.

56Campaigns tracked
56Marked active
1Seen in the past year
56Matching this view

56 campaigns

Campaign dates describe the activity window recorded by the source. They are not publication dates unless explicitly labeled.

ActiveMITRE ATT&CK

C0027

C0027 was a financially-motivated campaign linked to Scattered Spider that targeted telecommunications and business process outsourcing (BPO) companies from at least June through December of 2022. During C0027 Scattered Spider used various forms of social e...

Attributed actorsScattered Spider
1 actors0 related CVEs64 techniques
Investigate campaign
ActiveMITRE ATT&CK

Juicy Mix

Juicy Mix was a campaign conducted by OilRig throughout 2022 that targeted Israeli organizations with the Mango backdoor.

Attributed actorsOilRig
1 actors0 related CVEs77 techniques
Investigate campaign
ActiveMITRE ATT&CK

2022 Ukraine Electric Power Attack

The 2022 Ukraine Electric Power Attack was a Sandworm Team campaign that used a combination of GOGETTER, Neo-REGEORG, CaddyWiper, and living of the land (LotL) techniques to gain access to a Ukrainian electric utility to send unauthorized commands from thei...

Attributed actorsSandworm Team
1 actors0 related CVEs79 techniques
Investigate campaign
ActiveMITRE ATT&CK

C0026

C0026 was a campaign identified in September 2022 that included the selective distribution of KOPILUWAK and QUIETCANARY malware to previous ANDROMEDA malware victims in Ukraine through re-registered ANDROMEDA C2 domains. Several tools and tactics used durin...

0 actors0 related CVEs0 techniques
Investigate campaign
ActiveMITRE ATT&CK

Leviathan Australian Intrusions

Leviathan Australian Intrusions consisted of at least two long-term intrusions against victims in Australia by Leviathan, relying on similar tradecraft such as external service exploitation followed by extensive credential capture and re-use to enable privi...

Attributed actorsLeviathan
1 actors6 related CVEs50 techniques
Investigate campaign
ActiveMITRE ATT&CK

HomeLand Justice

HomeLand Justice was a disruptive cyber campaign conducted by Iranian state-affiliated actors against Albanian government networks in July and September 2022. The activity combined ransomware, wiper malware, and data leak operations. Initial access for Home...

Attributed actorsVOID MANTICORE
1 actors0 related CVEs63 techniques
Investigate campaign
ActiveMITRE ATT&CK

C0010

C0010 was a cyber espionage campaign conducted by UNC3890 that targeted Israeli shipping, government, aviation, energy, and healthcare organizations. Security researcher assess UNC3890 conducts operations in support of Iranian interests, and noted several l...

0 actors0 related CVEs0 techniques
Investigate campaign
ActiveMITRE ATT&CK

C0011

C0011 was a suspected cyber espionage campaign conducted by Transparent Tribe that targeted students at universities and colleges in India. Security researchers noted this campaign against students was a significant shift from Transparent Tribe's historic t...

Attributed actorsTransparent Tribe
1 actors0 related CVEs14 techniques
Investigate campaign
ActiveMITRE ATT&CK

Operation CuckooBees

Operation CuckooBees was a cyber espionage campaign targeting technology and manufacturing companies in East Asia, Western Europe, and North America since at least 2019. Security researchers noted the goal of Operation CuckooBees, which was still ongoing as...

0 actors0 related CVEs0 techniques
Investigate campaign
ActiveMITRE ATT&CK

Indian Critical Infrastructure Intrusions

Indian Critical Infrastructure Intrusions is a sequence of intrusions from 2021 through early 2022 linked to People’s Republic of China (PRC) threat actors, particularly RedEcho and Threat Activity Group 38 (TAG38). The intrusions appear focused on IT syste...

0 actors0 related CVEs0 techniques
Investigate campaign
ActiveMITRE ATT&CK

C0018

C0018 was a month-long ransomware intrusion that successfully deployed AvosLocker onto a compromised network. The unidentified actors gained initial access to the victim network through an exposed server and used a variety of open-source tools prior to exec...

0 actors0 related CVEs0 techniques
Investigate campaign
ActiveMITRE ATT&CK

C0017

C0017 was an APT41 campaign conducted between May 2021 and February 2022 that successfully compromised at least six U.S. state government networks through the exploitation of vulnerable Internet facing web applications. During C0017, APT41 was quick to adap...

Attributed actorsAPT41
1 actors3 related CVEs82 techniques
Investigate campaign
ActiveMITRE ATT&CK

Outer Space

Outer Space was a campaign conducted by OilRig throughout 2021 that used the SampleCheck5000 downloader and Solar backdoor to target Israeli organizations.

Attributed actorsOilRig
1 actors0 related CVEs77 techniques
Investigate campaign
ActiveMITRE ATT&CK

C0015

C0015 was a ransomware intrusion during which the unidentified attackers used Bazar, Cobalt Strike, and Conti, along with other tools, over a 5 day period. Security researchers assessed the actors likely used the widely-circulated Conti ransomware playbook ...

0 actors0 related CVEs0 techniques
Investigate campaign
ActiveMITRE ATT&CK

Operation Spalax

Operation Spalax was a campaign that primarily targeted Colombian government organizations and private companies, particularly those associated with the energy and metallurgical industries. The Operation Spalax threat actors distributed commodity malware an...

0 actors0 related CVEs0 techniques
Investigate campaign
ActiveMITRE ATT&CK

SolarWinds Compromise

The SolarWinds Compromise was a sophisticated supply chain cyber operation conducted by APT29 that was discovered in mid-December 2020. APT29 used customized malware to inject malicious code into the SolarWinds Orion software build process that was later di...

Attributed actorsAPT29
1 actors5 related CVEs66 techniques
Investigate campaign
ActiveMITRE ATT&CK

CostaRicto

CostaRicto was a suspected hacker-for-hire cyber espionage campaign that targeted multiple industries worldwide, with a large number being financial institutions. CostaRicto actors targeted organizations in Europe, the Americas, Asia, Australia, and Africa,...

0 actors0 related CVEs0 techniques
Investigate campaign
ActiveMITRE ATT&CK

FunnyDream

FunnyDream was a suspected Chinese cyber espionage campaign that targeted government and foreign organizations in Malaysia, the Philippines, Taiwan, Vietnam, and other parts of Southeast Asia. Security researchers linked the FunnyDream campaign to possible ...

0 actors0 related CVEs0 techniques
Investigate campaign
ActiveMITRE ATT&CK

Operation Dream Job

Operation Dream Job was a cyber espionage operation likely conducted by Lazarus Group that targeted the defense, aerospace, government, and other sectors in the United States, Israel, Australia, Russia, and India. In at least one case, the cyber actors trie...

Attributed actorsLazarus Group
1 actors3 related CVEs94 techniques
Investigate campaign
ActiveMITRE ATT&CK

Operation Wocao

Operation Wocao was a cyber espionage campaign that targeted organizations around the world, including in Brazil, China, France, Germany, Italy, Mexico, Portugal, Spain, the United Kingdom, and the United States. The suspected China-based actors compromised...

0 actors0 related CVEs0 techniques
Investigate campaign
ActiveMITRE ATT&CK

Operation Ghost

Operation Ghost was an APT29 campaign starting in 2013 that included operations against ministries of foreign affairs in Europe and the Washington, D.C. embassy of a European Union country. During Operation Ghost, APT29 used new families of malware and leve...

Attributed actorsAPT29
1 actors5 related CVEs66 techniques
Investigate campaign
ActiveMITRE ATT&CK

Frankenstein

Frankenstein was described by security researchers as a highly-targeted campaign conducted by moderately sophisticated and highly resourceful threat actors in early 2019. The unidentified actors primarily relied on open source tools, including Empire. The c...

0 actors0 related CVEs0 techniques
Investigate campaign
ActiveMITRE ATT&CK

Operation Sharpshooter

Operation Sharpshooter was a global cyber espionage campaign that targeted nuclear, defense, government, energy, and financial companies, with many located in Germany, Turkey, the United Kingdom, and the United States. Security researchers noted the campaig...

0 actors0 related CVEs0 techniques
Investigate campaign
ActiveMITRE ATT&CK

C0021

C0021 was a spearphishing campaign conducted in November 2018 that targeted public sector institutions, non-governmental organizations (NGOs), educational institutions, and private-sector corporations in the oil and gas, chemical, and hospitality industries...

0 actors0 related CVEs0 techniques
Investigate campaign
How we handle attribution

Every attribution includes its source.

A campaign is a named cluster of related activity from an identified source. Different publishers may define the same operation differently or revise an attribution later.

SecurityAlert keeps the source and confidence with each actor relationship. Actor-level CVEs, techniques, malware, and indicators are displayed as investigation context rather than direct campaign evidence unless the underlying source makes that connection.