Severity: All Severities Critical High Medium Low
Status: All Statuses Active Monitoring Contained Resolved
Actor Type: All Types Nation State Cybercrime Hacktivism Unknown
Clear All Apply Filters
24h 7d 30d 90d Custom
Active Campaigns8 Archived3
Sophisticated spearphishing campaign targeting financial institutions. Uses custom Cobalt Strike beacons with domain fronting.
Financial Sector Spearphishing T1566.001
View Details IOCs Alert Archive
Supply chain compromise targeting software vendors. Leverages legitimate update mechanisms.
Supply Chain SUNBURST T1195.002
View Details IOCs Alert Archive
Business email compromise using AI-generated content and deepfake voice synthesis.
BEC Deepfake T1566.001
View Details IOCs Alert Archive
Renewed ransomware campaign targeting healthcare. Uses double extortion tactics.
Ransomware Healthcare T1486
View Details IOCs Alert Archive
Large-scale credential phishing using lookalike domains targeting M365 and Google.
Phishing M365 T1566.002
View Details IOCs Alert Archive
Advanced firmware-level attacks targeting UEFI/BIOS in enterprise environments.
Firmware UEFI T1542
View Details IOCs Alert Archive
Targeting cloud infrastructure via social engineering of IT help desks.
Cloud Social Engineering T1566
View Details IOCs Alert Archive
Targeting telecommunications providers for intelligence collection and surveillance.
Telecom Espionage T1557
View Details IOCs Alert Archive
Election interference campaign that has been contained. All known IOCs blocked.
Election Disinformation
View Details IOCs Restore
Major ransomware campaign now contained. Group infrastructure seized by law enforcement.
Ransomware RaaS
View Details IOCs Restore
Mass phishing campaign that has subsided. Infrastructure taken down.
Phishing Mass Campaign
View Details IOCs Restore
Midnight Storm escalated
2 hours ago
47 IOCs added to Ransomware
5 hours ago
ShadowGate archived
1 day ago
REvil contained
3 days ago
Campaign IdentificationDefine the core identity and classification of this threat campaign
Target ProfileDefine the industries, regions, and asset types this campaign targets
Threat Actor AttributionLink this campaign to known threat actors or create new actor profiles
Known Actor New Actor Unknown
Spearphishing, Supply Chain, Cloud Exploitation
Supply Chain, Ransomware, Financial Theft
Cryptocurrency Theft, Destructive Malware
Ransomware, Data Extortion, RaaS Model
Unknown Threat Actor Attribution will be determined through analysis. STRATUM will automatically suggest potential actors based on observed TTPs and IOCs.
MITRE ATT&CK MappingSelect known tactics and techniques associated with this campaign
Phishing Exploit Public App Supply Chain
Command Line User Execution WMI
Scheduled Task Boot/Logon Valid Accounts
App Layer Protocol Ingress Tool Transfer Protocol Tunneling
Indicators of CompromiseAdd known IOCs to automatically detect and correlate campaign activity
Auto-Enrichment SettingsConfigure automatic IOC enrichment from threat intelligence sources
Alert ConfigurationDefine when and how you want to be notified about campaign activity
Alert when any tracked IOC is detected in your environment
Critical Priority High Priority Medium Priority Alert when MITRE ATT&CK techniques match campaign TTPs
Critical Priority High Priority Medium Priority Alert when new threat intel is published about this campaign
Critical Priority High Priority Medium Priority Alert when campaign or actor is mentioned on dark web sources
Critical Priority High Priority Medium Priority Automated Response ActionsConfigure automatic actions when campaign activity is detected
Notification RecipientsConfigure who receives alerts and notifications for this campaign
SIEM/SOAR IntegrationConnect campaign tracking to your security infrastructure
Reporting & AnalyticsConfigure automatic reporting and analytics for this campaign