Threat Campaigns
Short answer: High-value campaigns with real historical anchors — each links to related CVEs, actors, timeline and sources.
Evidence: CISA KEV · NVD · MITRE ATT&CK · vendor advisories · Human reviewed
- CISA KEV Waves 2024 Recurring new-KEV exploitation pushes 2026-08-26 · CISA KEV
- FortiOS VPN Attacks FortiGate admin compromise wave 2026-08-26 · CISA advisory
- Citrix ADC Impulse Attacks Citrix ADC Impulse Attacks — Internet-facing Citrix appliances compromised Relates to CVE-2023-3519. (Source: CISA KEV) 2026-08-26 · CISA KEV
- Zoho ManageEngine Attacks ITSM appliances compromised 2026-08-26 · CISA KEV
- PaperCut RCE Exploitation Print server RCE at scale 2026-08-26 · CISA KEV
- Fortinet FortiOS VPN Attacks FortiOS admin interface compromise 2026-08-26 · CISA advisory
- Confluence Zero-Day 2023 Confluence takeover wave 2026-08-26 · CISA KEV
- Citrix ADC Impulse Attacks Citrix ADC Impulse Attacks Relates to CVE-2023-3519. Source: CISA KEV. 2026-08-26 · CISA KEV
- CitrixBleed exploitation (impulse) Session token theft across appliances 2026-08-26 · CISA KEV
- Cisco ASA IKEv1 Wave VPN brute-force + malware 2026-08-26 · CISA KEV
- Weekly KEV Waves (2024) Weekly KEV Waves (2024) Relates to CVE-2024-3400, CVE-2023-38646. Source: CISA KEV. 2026-08-26 · CISA KEV
- WastedLocker Campaigns Targeted supply-chain themed ransomware intrusions 2026-08-26 · FBI
- Vice Society Double Extortion Vice Society is an education-focused double-extortion operation first observed in August 2021 and documented in the FBI/CISA joint advisory AA22-128A. Relevant to defenders of schools and higher-education networks. (Source: FBI/CISA AA22-128A) 2026-08-26 · FBI/CISA AA22-128A
- Squirrelwaffle Spam Wave High-volume spam delivering Cobalt Strike and QakBot 2026-08-26 · Researchers
- RedLine Stealer Operations Stealer operations feeding credential markets at scale 2026-08-26 · Researchers
- Ryuk COVID-19 Wave Pandemic-era surge of human-operated ransomware hits 2026-08-26 · FBI AA20-302A
- Rhysida Ransomware Wave Rhysida is a ransomware-as-a-service operation first observed in May 2023 that conducts auction-style double extortion against healthcare and education organizations; a CISA advisory was issued by February 2024. Relevant due to its targeting of critical sectors. (Source: CISA) 2026-08-26 · CISA
- RagnarLocker Waves Human-operated targeted ransomware on critical verticals 2026-08-26 · FBI/CISA
- ZebraTech/Proxylib Fake Software Fake software installers pushing Phobos ransomware 2026-08-26 · Public reporting
- Phobos RDP Attacks RDP brute-force driven raises hitting SMBs 2026-08-26 · CISA
- NoEscape Ransomware NoEscape is a ransomware-as-a-service operation first observed in June 2023 that operates an auction-based leak site and escalated to triple extortion by January 2024. (Source: Researchers, via OpenTrojan campaign record) 2026-08-26 · Researchers
- NetWalker COVID-19 Phishing Pandemic-themed phishing leading to double extortion 2026-08-26 · FBI/Poland action
- Medusa Ransomware Wave Medusa is a ransomware operation conducting double extortion with auction-style data leaks, first observed in June 2021 and showing continued growth through 2023; documented in a CISA advisory. (Source: CISA) 2026-08-26 · CISA
- Maze Global Extortions Pioneering double-extortion wave across mid-size businesses 2026-08-26 · Researchers
- LockBit Healthcare & Gov Wave LockBit Healthcare & Gov Wave — Sustained encryption of healthcare and government targets Relates to CVE-2023-34362. (Source: CISA/FTB) 2026-08-26 · CISA/FTB
- LAPSUS$ Cloud Thefts Spray-and-pay SIM-swap/data-theft sprees on tech giants 2026-08-26 · Researchers
- Hive Healthcare Attacks Hive Healthcare Attacks — Ransomware intrusions against healthcare and critical services Relates to CVE-2020-1472. (Source: CISA AA22-321A) 2026-08-26 · CISA AA22-321A
- GandCrab Spam Campaigns High-volume exploit-kit and spam ransomware waves 2026-08-26 · FBI
- Emotet-TrickBot-Ryuk Pipeline Botnet-to-ransomware operational pipeline 2026-08-26 · FBI/CISA advisories
- Egregor Ransomware Wave RaaS sweep hitting retail and manufacturing 2026-08-26 · Researchers
- DoppelPaymer Extortions Targeted double-extortion on industrial enterprises 2026-08-26 · CISA/industry
- Conti Healthcare Attacks Conti Healthcare Attacks — Attacks forcing critical disruptions in healthcare Relates to CVE-2021-26084. (Source: HHS warnings) 2026-08-26 · HHS warnings
- BlackMatter Attacks RaaS intrusions targeting critical-adjacent businesses 2026-08-26 · CISA AA21-291A
- Cactus Ransomware Cactus is an encryption-centric ransomware-as-a-service wave first observed in March 2023 that grew substantially by late 2023. (Source: Researchers) 2026-08-26 · Researchers
- BlueSky Ransomware Wave Wave of mid-size enterprise encryption 2026-08-26 · Researchers
- MGM Cyberattack (BlackCat) MGM Cyberattack (BlackCat) — Social-engineered outage at entertainment and hotel group. (Source: Public reporting) 2026-08-26 · Public reporting
- BlackByte Attacks BlackByte Attacks — Web-shell accesses leading to encryption of business networks Relates to CVE-2021-26084. (Source: CISA AA22-105A) 2026-08-26 · CISA AA22-105A
- Akira Ransomware Wave Akira Ransomware Wave — Global double-extortion wave hitting SMBs and enterprises Relates to CVE-2023-7024. (Source: CISA advisory AA24-109A) 2026-08-26 · CISA advisory AA24-109A
- Abyss Ransomware Iranian-linked ransomware targeting Israel and US 2026-08-26 · Researchers
- 8base Ransomware (Phobos) 8base is a ransomware leak-site operation first observed in March 2023 and linked to Phobos-associated activity; operations were documented through October 2023. (Source: Researchers) 2026-08-26 · Researchers
- ZeroLogon Attacks Domain controller privilege escalation exploited in raids 2026-08-26 · CISA advisory
- Apex One/Softing Industrial Attacks Industrial and EDR-supply-chain intrusions (Phobos/Proxylib) 2026-08-26 · CISA advisory (Phobos/Proxylib reporting)
- XZ Utils Backdoor XZ Utils Backdoor Relates to CVE-2024-3094. Source: Public disclosure (2024-03). 2026-08-26 · Public disclosure (2024-03)
- WordPress Plugin Campaigns WordPress Plugin Campaigns — Compromised plugins hijack thousands of sites Relates to CVE-2019-8942, CVE-2021-34646. (Source: WordFence research) 2026-08-26 · WordFence research
- WannaCry Legacy Exploitation Persistent exploitation of weak SMB across the globe 2026-08-26 · CISA KEV
- VMware ESXi Ransomware Wave ESXi hypervisors encrypted at scale by multiple RaaS 2026-08-26 · CISA advisory AA21-131A
- TrickBot Loader Wave 2019 Loads of Ryuk/Conti via modular loader 2026-08-26 · CISA AA20-287A
- Text4Shell Analysis Library-injection analysis campaigns 2026-08-26 · Researchers
- Squirrelwaffle Spam Wave High-volume email campaigns delivering Cobalt Strike and QakBot 2026-08-26 · Researchers 2021
- Spring4Shell Campaign Framework RCE attempted against Java apps at scale 2026-08-26 · CISA KEV
- SMBGhost Exploitation SMB v3 compression bug (windows) exploited in the wild 2026-08-26 · CISA KEV
- Scattered Spider Social Engineering Scattered Spider is a social-engineering campaign conducting SMS/vishing-based credential theft at scale, including SSO-related MFA bypass documented in April 2022 and the 2023 MGM/Caesar intrusions. Relevant because it abuses identity rather than vulnerability exploitation. (Source: CISA advisory) 2026-08-26 · CISA advisory
- Ryuk Human-Operated Ransomware Hands-on-keyboard extortions via Emotet/TrickBot access 2026-08-26 · FBI AA20-302A
- Royal Ransomware Wave Royal is a double-extortion ransomware wave observed since July 2022 targeting enterprises, with activity tied to CVE-2022-30190 fulfillment and a CISA/industry advisory published in 2023. (Source: CISA advisory recognized in OpenTrojan campaign record) 2026-08-26 · CISA advisory AA22-xxx
- Redis RCE Waves Misconfigured Redis instances hijacked for mining and botnets 2026-08-26 · Researchers
- QakBot Phishing Wave 2022 Thread-hijack phishing for initial access at scale 2026-08-26 · Proofpoint
- PyPI Typosquatting Wave Fake PyPI packages stealing credentials 2026-08-26 · ESET research 2023
- Pulse Secure VPN Exploitation VPN file-read vulnerabilities enabled brute-force takeover 2026-08-26 · CISA KEV
- ProxyShell RCE Wave ProxyShell RCE Wave — Follow-on ransomware exploitation of exposed Exchange Relates to CVE-2021-34473, CVE-2021-31207. (Source: CISA advisory) 2026-08-26 · CISA advisory
- Exchange Server ProxyLogon Exploitation Thousands of on-prem Exchange servers compromised via chained bugs 2026-08-26 · CISA Emergency Directive 21-02
- PrintNightmare Campaigns PrintNightmare Campaigns Relates to CVE-2021-34527, CVE-2021-1675. Source: US-CERT alert 2021. 2026-08-26 · US-CERT alert 2021
- PostgreSQL Attacks Exposed databases brute-forced and mined 2026-08-26 · Researchers
- Polyfill.io Supply Chain Compromised CDN script injected into thousands of sites 2026-08-26 · Sansec research
- Play (PlayCrypt) Ransomware Play (PlayCrypt) is a ransomware-as-a-service operation first observed in October 2022 that relies on gaining initial access through exposed RDP and VPN services; by March 2023 it was observed exploiting Veeam backup software to deploy encryption. Relevant to defenders because it targets unpatched remote-exposure services. (Source: CISA advisory recognized in OpenTrojan campaign record) 2026-08-26 · CISA advisory AA23-???
- NotPetya Global Spike Destructive wiper storm across 60+ countries 2026-08-26 · CISA 2017
- npm Environment Confusion Malicious packages exploiting env-specific installs 2026-08-26 · Researchers
- MSMQ QueueJumper Attacks MSMQ QueueJumper Attacks — Message queue service RCE exploited for follow-on payloads Relates to CVE-2023-21554. (Source: Check Point research) 2026-08-26 · Check Point research
- MSHTML CVE-2021-40444 Attacks MSHTML CVE-2021-40444 Attacks — ActiveX-loaded malicious documents used as initial access Relates to CVE-2021-40444. (Source: CISA advisory AA21-257A) 2026-08-26 · CISA advisory AA21-257A
- MongoDB Ransomware Wave Unprotected MongoDB databases wiped with ransom demands 2026-08-26 · Researchers
- Meow Attacks Unprotected databases deleted wholesale 2026-08-26 · Researchers
- Maze End-of-Life Final announcements before operators shut down 2026-08-26 · Researchers 2020
- Lorenz Ransomware Tor-leak double extortion 2026-08-26 · Researchers
- Log4Shell Global Exploitation Log4Shell Global Exploitation Relates to CVE-2021-44228. Source: CISA KEV. 2026-08-26 · CISA KEV
- Kubernetes Cluster Exploitation Misconfigured clusters mined and backdoored 2026-08-26 · Researchers 2020
- Jupyter Notebook Exploitation Public Jupyter servers abused for mining 2026-08-26 · Sophos 2021
- Ivanti Connect Secure Attacks Ivanti Connect Secure Attacks — VPN appliances backdoored in supply-chain-style intrusions Relates to CVE-2023-46805, CVE-2024-21887. (Source: CISA advisory AA24-016A) 2026-08-26 · CISA advisory AA24-016A
- IcedID Initial Access Wave IcedID Initial Access Wave — Phishing and web-inject campaigns delivering Cobalt Strike Relates to CVE-2023-21608. (Source: CISA advisory AA23-038A) 2026-08-26 · CISA advisory AA23-038A
- Hafnium Exchange Waves Hafnium Exchange Waves Relates to CVE-2021-26855. Source: CISA AA21-087A. 2026-08-26 · CISA AA21-087A
- Hadoop YARN Attacks Uncertificated YARN endpoints abused for mining 2026-08-26 · Researchers 2019
- GoAnywhere MFT Exploitation GoAnywhere MFT Exploitation — File-transfer platform breached for mass data theft Relates to CVE-2023-0669. (Source: CISA advisory AA23-158A) 2026-08-26 · CISA advisory AA23-158A
- GitLab CVE Waves GitLab CVE Waves — Internet-facing GitLab instances compromised for mining and backdoors Relates to CVE-2021-22205, CVE-2023-7028. (Source: CISA KEV) 2026-08-26 · CISA KEV
- Follina Document Weaponization Follina Document Weaponization Relates to CVE-2022-30190. Source: CISA advisory AA22-181A. 2026-08-26 · CISA advisory AA22-181A
- EternalBlue Resurgence EternalBlue Resurgence — Legacy SMB exploits still drive intrusions (WannaCry legacy) Relates to CVE-2017-0144. (Source: CISA KEV) 2026-08-26 · CISA KEV
- Emotet Resurgence 2021 Botnet rebuild and spam waves after takedown 2026-08-26 · Researcher reports
- Emotet 2017-2018 Wave High-volume spam botnet push 2026-08-26 · Researchers
- Drupalgeddon Wave Drupalgeddon Wave — Drupal RCE exploited at scale for mining and webshells Relates to CVE-2018-7600. (Source: Researchers) 2026-08-26 · Researchers
- DoublePulsar Injections Kernel backdoor implanted via EternalBlue at scale 2026-08-26 · Researchers
- DarkSide Colonial Pipeline Pipeline disruption triggering US emergency declaration 2026-08-26 · FBI/CISA
- Conti Leak & Operations Conti Leak & Operations — Leaked playbooks and continued intrusions after split Relates to CVE-2021-26084. (Source: Researchers) 2026-08-26 · Researchers
- Confluence OGNL Exploitation Confluence OGNL Exploitation — Internet-facing Confluence instances compromised for mining and RATs Relates to CVE-2022-26134. (Source: CISA KEV) 2026-08-26 · CISA KEV
- Apache Commons Text ; 2026-08-26 · Researchers
- Cobalt Strike Keygen Operations Keygen trojans luring infosec pros 2026-08-26 · Researchers
- Cisco ASA/FTD VPN Attacks Cisco ASA/FTD VPN Attacks — VPN devices exploited for authentication bypass and far-field access Relates to CVE-2018-0101. (Source: US-CERT alert) 2026-08-26 · US-CERT alert
- CircleCI Breach Stolen access tokens leaked secrets from CI pipelines 2026-08-26 · CircleCI disclosure
- Black Basta Activity Black Basta is a ransomware-as-a-service operation first observed in April 2022, linked to QakBot-facilitated access and associated with CVE-2021-40444 exploitation; documented in CISA advisory AA22-281A. Relevant because its access chain relies on prior malware infection. (Source: CISA AA22-281A) 2026-08-26 · CISA AA22-281A
- BazarCall Campaigns Phone-assisted phishing (BazarCall) at scale 2026-08-26 · Researchers 2021
- Barracuda ESG Attacks Barracuda ESG Attacks Relates to CVE-2023-2868. Source: CISA advisory. 2026-08-26 · CISA advisory
- 3CX Supply Chain Attack The 3CX supply-chain attack used a backdoored software installer (2023-03) to deliver a malicious update into 3CX VoIP deployments, with attribution still under discussion (2023-05); source: researchers' own disclosure. 2026-08-26 · Researchers own disclosure
- AvosLocker Ransomware RaaS targeting North America 2026-08-26 · CISA advisory
- WannaCry Global Ransomworm WannaCry (May 2017) was an SMB-based ransomware worm exploiting EternalBlue (CVE-2017-0144) that self-propagated across unpatched Windows systems, encrypting files and demanding ransom in 150+ countries within days. 2026-08-26 · CISA · NVD · Microsoft
- SolarWinds SUNBURST Supply-Chain Attack The SolarWinds campaign (2020) used a trojanized SolarWinds Orion update to deliver the SUNBURST backdoor into over 18,000 organizations, with follow-on access observed in U.S. government, technology and security-company networks. 2026-08-26 · CISA · Microsoft · Mandiant
- Okta / Midnight Blizzard Password-Spray Campaign Midnight Blizzard (APT29) runs sustained password-spray and token-immune campaigns against cloud identity systems, including Okta and Microsoft 365 tenants, using compromised accounts to hunt tokens and mailboxes. 2026-08-26 · Microsoft · Okta
- NotPetya Destructive Attack NotPetya (June 2017) was a wiper disguised as ransomware that spread via M.E.Doc update abuse and EternalBlue (CVE-2017-0144), causing multi-billion-dollar losses by permanently destroying systems rather than encrypting for ransom. 2026-08-26 · CISA · ESET · CrowdStrike
- MOVEit Transfer Cl0p Mass Exploitation Cl0p's June 2023 exploitation of MOVEit Transfer (CVE-2023-34362, SQL injection) breached hundreds of organizations from one third-party file-transfer platform, exfiltrating data before the zero-day was disclosed. 2026-08-26 · CISA · Progress Software
- Log4Shell Global Exploitation Log4Shell (CVE-2021-44228) is an unauthenticated remote code execution flaw in Apache Log4j 2 that was exploited at global scale within days of disclosure in December 2021, across internet-facing Java applications and later across enterprise and ICS environments. 2026-08-26 · NVD · CISA · vendor advisories
- Kaseya VSA → REvil Supply-Chain Ransomware The July 2021 Kaseya VSA attack let REvil encrypt up to ~1,500 downstream businesses by compromising the vendor's own remote-management console, proving that MSP supply chains are prime ransomware targets. 2026-08-26 · CISA · Kaseya
- HAFNIUM Exchange Server Exploitation In March 2021, the China-linked HAFNIUM actor chained four Microsoft Exchange Server zero-days (ProxyLogon, CVE-2021-26855 and related) to deploy webshells on tens of thousands of on-premises mail servers globally. 2026-08-26 · Microsoft · CISA
- Citrix Bleed (CVE-2023-4966) Exploitation Citrix Bleed (CVE-2023-4966) leaked NetScaler session tokens, letting attackers bypass multi-factor authentication and hijack existing user sessions on internet-exposed edge appliances in late 2023. 2026-08-26 · CISA · Citrix
- Colonial Pipeline Ransomware Attack The May 2021 DarkSide ransomware attack on Colonial Pipeline shut down U.S. East Coast fuel delivery for days, escalating ransomware to a national critical-infrastructure policy issue and driving CISA-sector guidance. 2026-08-26 · CISA · FBI