Ido Cohen: APT73 continues to expand its operations. The group has added 3 new victims to its leak site, including a government entity in South America and a major international airport operator in Central Europe serving tens of millions of passengers annually. APT73 was added to the DarkFeed platform in mid-2024 and has since claimed 110+ victims.2026-06-23
ido_cohen2ransomwareUnknownT1566
Independent cyber threat research covering malware campaigns, phishing infrastructure and vulnerability exploitation.
Israeli-based organizations in the government2026-06-20
middle-eastreferenceIsraelT1566
Apt grupo regional Middle East se centra en sectores críticos como transporte, infraestructura, defensa y academia. Su actividad incluye ataques de spear phishing y operaciones cibernéticas ...
The group's primary objective is to stop violence and repression by the Belarusian government and restore democratic principles and rule of law. They have carried out various cyber attacks2026-06-20
other-actorsreferenceUnited States
Other Actors es un actor APT (Advanced Persistent Threat) regional vinculado a actividades de ciberseguridad orientadas a contrarrestar la violencia y la represión del gobierno belarusiano, ...
dinodas indicators and references2026-06-18
dinodasiocUnknown
APTTrail mantiene indicadores publicos asociados a dinodas. Aliases observados: dinodas, dinodasrat, linodas, linodasrat. Conteo por tipo: domain: 12, ipv4: 7, url: 5.
backconfig indicators and references2026-06-18
backconfigiocUnknown
APTTrail mantiene indicadores publicos asociados a backconfig. Aliases observados: backconfig, monsoon, neon, viceroy tiger. Conteo por tipo: domain: 3, ipv4: 2, url: 3.
APT TODDYCAT indicators and references2026-06-18
apt-toddycatiocUnited States
APTTrail mantiene indicadores publicos asociados a APT TODDYCAT. Aliases observados: APT TODDYCAT. Conteo por tipo: domain: 29, ipv4: 1, url: 1.
StealthMole: RT by @stealthmole_int: Government-Related Darkweb/Deepweb Leak Activity — First Week of June 2026 Observed activity consists of 26 government-related leak or sale postings and 4 ransomware/extortion listings tied to public-sector or government-associated entities. The activity is distributed across multiple underground forums and Tor-hosted leak sites, with visible concentration on darkforums, spear, and craxpro.2026-06-10
stealthmole_intransomwareMexico
StealthMole cyber threat intelligence on ransomware, data leaks and criminal underground ecosystems.