Discover the latest articles and insights on Dark Atlas
July 19, 2026
21 min read
Executive Summary APT42 continues to refine a familiar operating model, making it harder to detect and easier to scale. Three developments define the current picture. SpearSpecter combined prolonged WhatsApp engagement, Windows search-ms and WebDAV abuse, and a substantially expanded TAMECAT backdoor. APT42 also incorporated generative AI into target research, persona and pretext development, translation, malware engineering, debugging, code generation, ...
April 27, 2026
Overview On January 19, 2026, the Vect ransomware operation publicly announced its affiliate program through a post on a Brechforums, marking a clear step toward scaling its ransomware-as-a-service (RaaS) model. The announcement was made by the actor behind the operation (“vect”), who used the platform to introduce the program and share access to a dedicated ...
February 09, 2026
11 min read
Ransomware is no longer just a malicious program deployed by a single attacker — it has evolved into a complex, profit-driven ecosystem operating much like a legitimate business model. Today’s ransomware operations involve multiple specialized actors, automated platforms, and underground services working together to maximize impact and financial gain. From Initial Access Brokers selling compromised ...
October 17, 2025
22 min read
Executive Summary APT35, also known as Magic Hound and Charming Kitten, is an Iranian state-backed cyber espionage group active since at least 2014. The threat actor is known for strategic intelligence-gathering, data theft, and disruption operations aligned with Iran’s geopolitical and military objectives. The group’s primary targets include energy, government, defense, and technology sectors, with ...
No more posts to load.