HackWatch

Campaign intelligence

Threat actor profiles and campaign monitoring

Track actor-focused incident clusters and jump directly into verified alert coverage, response workflows and category archives.

APT29 campaign tracking

Credential theft, cloud account targeting and stealthy long-tail intrusion operations.

Open related alerts

Lazarus and financially motivated intrusion clusters

Hybrid espionage and finance-driven operations including malware and exchange targeting.

Open related alerts

Scattered Spider and social-engineering operations

Identity-centered compromise paths with account takeover and help-desk abuse patterns.

Open related alerts

LockBit and ransomware-extortion ecosystem

Ransomware campaign coverage with leak-site context, victim pressure patterns and containment links.

Open related alerts

How to use actor pages operationally

  • Use actor landings to spot repeated tactics across phishing, breach and malware incidents.
  • Pivot from actor references into category archives and recovery tools, not just isolated headlines.
  • Prioritize alerts tagged with high risk, active exploitation and account takeover indicators.