- Lazarus Launches Ransomware Attacks: The Lazarus APT group began using the MATA multi-platform framework to distribute malware and initiate ransomware attacks.
- Cactus Pete Leverages ShadowPad: Chinese-speaking threat actor Cactus Pete used the ShadowPad modular attack platform to launch cyberattacks.
- MuddyWater Uses a New C++ Toolchain: The MuddyWater APT utilized a new C++ toolchain in cyberattacks; during these attacks, APT groups leveraged the Secure Socket Funneling open-source utility for lateral movement.
- APT Groups Use HoneyMyte to Attack a Southeast Asian Government: APT groups used the HoneyMyte APT to launch a watering hole attack on the website of a Southeast Asian government; the attack was set up in March and may have used a combination of whitelisting and social engineering techniques to infect its targets.
- New OceanLotus Variants Discovered: New variants of OceanLotus, a multi-stage loader, were found that leveraged usernames, hostnames and other target-specific information to attack specific victims.