Loading the current evidence view. Navigation and account controls remain available.
Indicator investigation
Loading the current evidence view. Navigation and account controls remain available.
Loading verdict, provenance, relationships and sightings.
Indicator
Type domain · source intel_report_ingest
Shared non-noise tags (narrow join).
tags: report:checkpoint_research, report:crowdstrike, report:eset, report:unit42
tags: report:checkpoint_research, report:unit42
tags: report:checkpoint_research, report:crowdstrike
tags: report:checkpoint_research, report:unit42
tags: report:unit42
tags: report:checkpoint_research
tags: report:checkpoint_research
tags: report:checkpoint_research
High-signal pivots without leaving the thread you started in search.
Structured pivots from local graph context.
Full investigation canvas with neighbor expansion.
Title/body text match only.
Fast and Furious – Nimbus Manticore Operations During the Iranian Conflict Key Findings Introduction During the recent geopolitical tensions in the Middle East, we reported on multiple Iran-nexus threat actors advancing Iran’s strategic objectives through cyber operati
CL-STA-1062 Targets Southeast Asian Governments and Critical Infrastructure Government entities and critical infrastructure were targeted for espionage in SE Asia by attackers using a hybrid toolkit, including custom TinyRCT backdoor. The post CL-STA-1062 Targets Southeast Asian
AI brands as bait: How threat actors are using the AI hype in social engineering As threat actors operationalize AI to accelerate attacks, they are also leveraging the wider global interest around AI itself as a social engineering lure. The post AI brands as bait: How threat act
Tracking Iranian APT Screening Serpens’ 2026 Espionage Campaigns Unit 42 details Screening Serpens' use of AppDomainManager hijacking and new RAT variants to target tech and defense sectors in recent campaigns. The post Tracking Iranian APT Screening Serpens’ 2026 Espionage Camp
OceanLotus: From external espionage to domestic targeting A shift in operational pattern of the infamous Vietnam-aligned APT group OceanLotus: From external espionage to domestic targeting Award-winning news, views, and insight from the ESET security community English Español D
N-able N-central exploitation results in RMM tool deployment After compromising systems via CVE-2026-18577, threat actors use the additional RMM tools and network tunnels to establish persistent remote access Categories: Threat Research Tags: RMM, N-able, vulnerability N-able N
Deduped connector weight from graph context.