Salt Typhoon

Chinese state-sponsored hacking group known as “Salt Typhoon” is linked to a series of cyberattacks targeting telecommunications firms globally. These breaches compromised at least nine major telecom providers, including AT&T, Verizon, and T-Mobile. The group reportedly focused on infiltrating telecom infrastructure to steal text messages, phone call information, and voicemails from targeted people. The threat actors also targeted the wiretapping platforms used by the US government, raising serious national security concerns.

Trigona

Trigona is a successor to users of the CryLock ransomware. They are believed to have begun operations in October 2022 and have already achieved a degree of infamy. A pro-Ukrainian group of white hat hackers stated that they had taken Trigona’s web servers offline in 2023, but evidently Trigona has resurrected itself since.

RA World

RA World, active since at least April 2023, primarily targets organizations in the United States and South Korea. The group utilizes a modified variant of the Babuk ransomware, which includes a built-in messaging application for victim communication. They reportedly exploit poorly secured internet-facing systems to gain initial access, followed by credential theft and lateral movement within the network. Security researchers have also suggested a possible link between RA World and a Chinese hacking group known as Bronze Starlight.

Team Insane PK

Team Insane PK is a group known for its activities in the realm of religious hacktivism. This group, allegedly based out of Pakistan, has been involved in numerous cyberattacks targeting Indian businesses and government websites. Their operations often involve the use of Distributed Denial of Service (DDoS) attacks, a common tactic in cyber warfare that overwhelms a network with traffic, rendering it inaccessible.

Religious hacktivism, a form of digital jihad, involves the use of digital tools and cybercrime techniques to carry out attacks driven by religious ideologies. These attacks aim to promote a certain belief system or discredit others.

Sarcoma Group

The Sarcoma Group is a ransomware group that emerged in October 2024. In November 2024, cybersecurity specialists at CYFIRMA warned: “Sarcoma ransomware is rapidly becoming a significant threat due to its aggressive tactics and increasing victim count.” In December 2024, operational technology cyber threat intelligence company Dragos listed Sarcoma among the most important emerging threats for industrial organizations worldwide. A report by RedPiranha shares more details about Sarcoma, explaining that its operators employ phishing emails and n-day vulnerabilities exploitation to gain initial access, while they have also conducted supply chain attacks to pivot from service vendors to their clients.

Post-compromise, Sarcoma engages in RDP exploitation, lateral movement, and data exfiltration. However, the tools the threat group uses have not been analyzed yet, so although the threat group’s operation indicates experience in the field, its exact origin and tactics haven’t been deciphered yet.