<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Threat-Actors on CuraSec</title><link>https://curasec.metacog.co.kr/tags/threat-actors/</link><description>Recent content in Threat-Actors on CuraSec</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Thu, 27 Aug 2026 21:01:55 +0000</lastBuildDate><atom:link href="https://curasec.metacog.co.kr/tags/threat-actors/index.xml" rel="self" type="application/rss+xml"/><item><title>Australia arrests alleged TeamPCP supply-chain hackers</title><link>https://curasec.metacog.co.kr/insights/2026-08-27-australia-arrests-alleged-teampcp-hackers-behind-supply-chai/</link><pubDate>Thu, 27 Aug 2026 21:01:55 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-27-australia-arrests-alleged-teampcp-hackers-behind-supply-chai/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Learn:&lt;/strong> Arrest confirms a supply-chain threat group was active at scale, but the summary provides no IOCs, affected packages, or specific compromised registries to audit against — no concrete remediation action available from this item alone.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Learn:&lt;/strong> Attribution news without published IOCs, TTPs, or ATT&amp;amp;CK mappings offers no immediate detection or hunting surface; useful background on an active supply-chain threat actor if future intelligence on this group is released.&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> Law enforcement action against a supply-chain attack group is useful context for board conversations on software supply-chain risk, but the thin summary lacks named victims or vendors needed to assess whether your organization&amp;rsquo;s suppliers were targeted.&lt;/li>
&lt;/ul></description></item><item><title>Global police op arrests 58 suspects tied to African cybercrime networks</title><link>https://curasec.metacog.co.kr/insights/2026-08-25-police-arrests-dozens-of-suspects-in-global-cybercrime-crack/</link><pubDate>Tue, 25 Aug 2026 11:39:54 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-25-police-arrests-dozens-of-suspects-in-global-cybercrime-crack/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>SOC/IR — Learn:&lt;/strong> Awareness of disrupted cybercrime infrastructure can inform threat landscape understanding, but no IOCs, TTPs, or detection opportunities are surfaced in this reporting.&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> Demonstrates continued international enforcement pressure on cybercrime networks; useful context for board-level threat landscape briefings but requires no immediate action.&lt;/li>
&lt;/ul></description></item><item><title>UNC6671/BlackFile extortion group actively targets financial firms</title><link>https://curasec.metacog.co.kr/insights/2026-08-07-hedge-fund-cyberattacks-tied-to-blackfile-linked-unc6671-ext/</link><pubDate>Fri, 07 Aug 2026 00:21:58 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-07-hedge-fund-cyberattacks-tied-to-blackfile-linked-unc6671-ext/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>SOC/IR — Learn:&lt;/strong> Actor profile useful for financial-sector defenders: UNC6671 is tied to BlackFile and is running an active extortion campaign against hedge funds and PE firms, but no IOCs, TTPs, or detection-ready technical details are available in this item yet.&lt;/li>
&lt;li>&lt;strong>Leader — Act:&lt;/strong> If your organization is in financial services, brief leadership now on the active UNC6671 extortion campaign targeting hedge funds and private-equity firms; verify whether your firm has received any suspicious outreach and confirm IR retainer readiness.&lt;/li>
&lt;/ul></description></item><item><title>EU and UK jointly sanction Russian GRU hackers for cyberattacks</title><link>https://curasec.metacog.co.kr/insights/2026-07-13-eu-sanctions-russian-gru-military-hackers-over-cyberattacks/</link><pubDate>Mon, 13 Jul 2026 13:18:50 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-07-13-eu-sanctions-russian-gru-military-hackers-over-cyberattacks/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>SOC/IR — Learn:&lt;/strong> Attribution of GRU-linked groups provides actor context useful for prioritizing threat intel feeds, but no IOCs or TTPs were released with this announcement.&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> Formal EU/UK attribution of GRU cyber operations signals continued escalation in state-sponsored threat activity against European targets — useful framing for board risk discussions and sector threat briefings.&lt;/li>
&lt;/ul></description></item></channel></rss>