threat.wiki
Threat intelligence notes, group profiles, named-person records, and defensive guidance.
Recent entries
- JINX-0163 / FulcrumSec cloud-native extortion cluster
- Water-sector PLC campaign: more than 4,100 internet-exposed Rockwell controllers
- Ill Bloom CryptoJS wallet-drain campaign
- AI token-jacking transfer-station abuse
- ChainDrop: Elastic adds a historical C2 domain and endpoint hunts
- AISI unsanctioned agent supply-chain attempt
- Flooding Dropper npm campaign
- JetBrains TeamCity CVE-2026-63077 active exploitation
- ChainDrop: Sonatype tracks 2,225 affected versions and adds response guidance
- macOS ClickFix fingerprinting-gate campaign
Sections
- Ops — campaign timelines, compromise chains, and sequencing
- Tools — malware, payloads, implants, and attacker infrastructure
- Groups — crews, cluster names, and shared operational personas
- People — publicly identified individuals or project personas when public sourcing supports it
- Patterns — reusable defender heuristics
- Notes — taxonomy, usage, and editorial guidance