State cyber operations
Assessment
Anthropic's Sept 11 threat report describes GTG-20006, an actor whose attribution is consistent with Russia's Midnight Blizzard, automating phishing, malware development and detection evasion in a machine-speed loop against more than 20 organisations, mostly Ukrainian government, military and diplomatic entities, and hijacking DNS records at three hotel Wi-Fi providers to stage malware on guests' devices. Turkish officials said on Sept 9 that at least three ministers' phones were examined and replaced after Apple mercenary-spyware notifications sent on Aug 13, with no attribution offered. The China-aligned APT31 first deployed the BlueMoon exploit kit, chaining Windows and Chrome vulnerabilities, on Aug 28, and other suspected China-nexus clusters adopted it within days, while Iranian-affiliated actors widened targeting of internet-exposed control systems at US water, energy and telecommunications providers into early September under a CISA advisory first published Apr 7. Salt Typhoon's telecom compromise remains unresolved and no new state-attributed operation was disclosed on Sept 14 or Sept 15, ahead of the Sept 18-20 Duma vote and the Nov 3 US midterms.
Recent, assessed
- 2026-09-11Anthropic threat intelligence report: GTG-20006, attribution consistent with Midnight Blizzard, used AI-driven workflows to rebuild its toolkit whenever detected, targeting 20-plus mostly Ukrainian government, military and diplomatic organisations and hijacking DNS at three hotel Wi-Fi providers. anthropic.com
- 2026-09-09OFAC issues transnational criminal organization designations and a counter-terrorism designation, with new and amended FAQs. ofac.treasury.gov
Level history
Levels set by research reviews. A level set by hand is shown at the top of the page while it is in force and is not part of this history.
| Date | Level | Status | Trend | Review |
|---|---|---|---|---|
| 2026-09-15 | 4 | Escalating | ▲ escalating | Weekly review |
| 2026-09-14 | 4 | Escalating | ▲ escalating | Weekly review |
| 2026-09-12 | 4 | Escalating | ▲ escalating | Weekly review |
| 2026-09-12 | 4 | Escalating | ▲ escalating | Baseline |
Latest headlines 14
Matched to this entry by keyword from the pull of 19 Sep, 11:09 UTC. Not reviewed; some may be off-topic.
- North Korean Hackers Targeted IT Professionals with Fake Job Listings and Stole Data from 7,000 Crypto Wallets
- North Korean hackers behind crypto thefts across 100 countries, including Japan
- North Korea-Linked Hackers Used Fake Jobs to Steal Crypto From IT Workers
- North Korean hackers disguise cyberattacks as job interviews with AI
- Foreign hackers breach two more US water utilities, threaten safety of Colorado residents
- The U.S. Is Highly Vulnerable to Cyber Threats From China. Here’s What It Should Do
- International security agencies warn about North Korean hackers exploiting job seekers to steal crypto, data
- Iran-Linked Hackers target Windows Machines through WhatsApp and Telegram
- UAE's digital success comes with a price: Highest cyberattack rate in the Gulf, says study
- FBI and Coast Guard Investigate Cyberattack on US-Bound Oil Tanker in Strait of Gibraltar
- AI Fuels 440% Surge in Hackers Using Blockchains to Execute Cyberattacks
- North Korean hackers infect thousands of devices across 100 countries as part of ‘WaterPlum’ campaign
- German police call Vitaly Kovalev a founder of Trickbot, the hacking group whose ransomware hit U.S. hospitals. New People had him on its Duma candidate list before dropping him in July.
- China’s FamousSparrow hackers target Latin America with new backdoor