Official Twitter page of the 780th MI Brigade (Cyber). The Army's only offensive cyberspace operations brigade (following, retweets and links ≠ endorsement).
"Ubique Et Semper In Pugna" latin for "Everywhere and always fighting" – We don't talk about what we do nor who we are in a cyber 'knife fight' with; however we are "Everywhere and Always...In the Fight!" We are the only offensive cyberspace operations brigade in the U.S. Army.
FSB’s matryoshka #2/3 – Gamaredon’s gifts that keeps unpacking – GammaLoad
Sekoia
"Gamaredon, officially operated by Russia’s FSB, the group is focusing government, military, and critical infrastructure networks, and is still actively operating at the time of this publication."
https://t.co/5oNeSUHtTq
@sekoia_io
TA4922: The Suspected Chinese Crime Group is Going Global
The Proofpoint Threat Research Team
"Many of the threats observed in the landscape are descendants of malware first used by Chinese espionage threat actors, namely Gh0stRAT"
https://t.co/n84xScBWSe
@proofpoint
Iran’s Ministry of Intelligence has likely broadened the use of its “Handala” brand to encompass MOIS’s external physical and influence operations targeting US and Israeli interests.
Recorded Future
https://t.co/GJvYAgcfRd
@RecordedFuture
Detecting Nimbus Manticore and their sideloading infection chains
Nextron
Nimbus Manticore, also tracked as UNC1549 and Smoke Sandstorm, is an Iran-nexus APT group
https://t.co/tUoyOG3Q7Y
@nextronsystems
FSB’s matryoshka #1/3 – Gamaredon’s gifts that keeps unpacking – GammaPhish and GammaWorm
https://t.co/VpB7IqSCGK
Gamaredon is a cyberespionage group specialized in long-term and persistent intrusion operations targeting Ukraine. Officially operated by Russia’s FSB.
https://t.co/FdmV4L2Rir
@sekoia_io
The Server Seizure That Affects Also Iran’s Cyber Operations
Check Point
...a ghost operation built on sanctioned infrastructure, quietly serving as the backbone for some of Iran’s most active cyber espionage campaigns.
https://t.co/3eHXKrEJu4
@CheckPointSW
Famous Chollima Targets PHP Developers Through Compromised Packagist Package
Socket
The North Korean malware loader hides in a Packagist-listed package and its GitHub branch to fetch and execute remote code in a likely Contagious Interview-style lure.
https://t.co/5ZqouzxYnN
@SocketSecurity
Operation Overload - Matryoshka's Next Layer
Clemson University | Media Forensics Hub Creative Inquiry Reports
Matryoshka is a campaign connected to the Social
Design Agency (SDA), a Moscow-based firm.
https://t.co/lSphUlEvrP
@ClemsonUniv
APT Profile – Silver Fox
Cyfirma
Silver Fox (also known as Void Arachne or APT-Q-27) is a China-based, state-aligned cyber threat actor.
https://t.co/TJIzBL5RAA
@cyfirma
Sapphire Sleet Targets macOS in Multi-Stage Intrusion Campaign
LevelBlue
https://t.co/l9mJxBcG96
@LevelBlueCyber recently observed a multi-stage macOS intrusion campaign conducted by the North Korean state-sponsored threat group Sapphire Sleet (also tracked as BlueNoroff/UNC1069).
Through April 2026, ENKI WhiteHat detected Kimsuky campaigns targeting South Korean military and corporate sectors.
The threat actor used spoofed security software pages and fake Webex meeting pages for malware delivery, while employing a new "JSONPing" technique to verify infections in real time.
Our findings include a new three-stage HttpSpy infection chain and multiple links to Kimsuky.
Read our in-depth report and attribution analysis:
https://t.co/QYJVZ6NeWw
ESET APT Activity Report Q4 2025–Q1 2026
@ESETresearch
"During the monitored time frame, China-aligned threat actors remained highly active worldwide, conducting espionage campaigns"
https://t.co/fZcLU6093R
Director GCHQ warns UK at ‘moment of consequence�� in inaugural Annual lecture
She warned that “Russia is scaling up its daily hybrid activity against the UK and Europe” and highlighted GCHQ’s role in “seeing around corners” to help the UK prepare.
@GCHQ | https://t.co/6YqjLrVKBj
https://t.co/F00iTQQWFi