Global Law Enforcement Dismantles Cybercrime Networks, Disrupts State-Sponsored Espionage
An international wave of law enforcement actions has targeted major cybercrime syndicates and state-sponsored hacking groups, leading to arrests, asset seizures, and disruption of critical infrastructure espionage.

Operation Jackal IV, a coordinated effort involving 22 nations and led by INTERPOL, has resulted in the arrest of 58 individuals and the identification of over 200 suspects associated with West African cybercrime networks. This significant operation successfully dismantled key components of the Black Axe syndicate, a notorious group responsible for orchestrating global romance scams, investment fraud, and business email compromise (BEC) schemes. Law enforcement agencies in South Africa, Argentina, and Romania also played crucial roles in disrupting major Crime-as-a-Service (CaaS) providers, leading to the freezing of millions of dollars in illicit financial assets.
In parallel, the U.S. Federal Bureau of Investigation (FBI), in collaboration with the Department of Justice (DoJ), has disrupted the global QScan and QTRouter hacking platforms. These platforms were operated by Chinese state-sponsored threat actors, identified as the QTFY group, which has direct ties to China’s military and intelligence services. The group utilized these compromised Internet of Things (IoT) botnets to mask cyber espionage traffic targeting sensitive U.S. networks, including those of the Federal Reserve and NASA. Law enforcement successfully seized the core command-and-control (C2) domains that were hardcoded within the malicious frameworks, significantly hindering the group's operations.
The U.S. Treasury has also taken action through a new operation named "Economic Outcast," imposing sweeping sanctions on five members of the Mabna Institute and nearly 60 Iran-linked entities. Under the direction of Iran's Ministry of Intelligence and Security (MOIS), these state-sponsored actors had breached multiple American critical infrastructure organizations, state governments, and defense contractors. The attackers exfiltrated sensitive datasets and executed high-value cryptocurrency heists. Federal indictments have been issued against these actors, with a $10 million reward offered for information leading to their arrest.
Further disrupting malicious activities, the Australian Federal Police (AFP) have arrested and charged two individuals for their principal roles in TeamPCP, a cybercrime syndicate. This group systematically compromised trusted open-source projects, including Trivy, Checkmarx KICS, and LiteLLM, by stealing developer credentials and distributing backdoored software updates through major ecosystem release channels. This extensive software supply chain campaign potentially compromised organizations worldwide and facilitated the unauthorized theft of hundreds of thousands of credentials.
Separately, security researchers have detailed "NovaCookies," a subscription-based phishing platform that targets corporate networks to steal authenticated Microsoft 365 session tokens. Operating as an Adversary-in-the-Middle (AitM) proxy, this toolkit, advertised on Telegram for $320 monthly, has compromised hundreds of organizations across the U.S., U.K., Germany, and the UAE. Attackers distribute counterfeit document-sharing lures within legitimate DocuSign notifications, which bypass standard sender authentication checks. The malicious link within the decoy document, once clicked, uses an OAuth error-redirect technique to route traffic through legitimate Microsoft or Google endpoints before reaching the phishing infrastructure, making the attack chain appear trustworthy.
In a targeted campaign, organizations and individuals in Cambodia have been targeted with Spark RAT, an open-source remote access trojan developed in Go. Threat actors distribute compressed archives via phishing emails containing lures such as Cambodian government notices or public health announcements. The attack chain involves a multi-stage process, including dynamic link library side-loading, anti-sandbox checks, and privilege escalation techniques. The malware abuses a legitimate but vulnerable OPSWAT AppRemover driver (ardrv.sys) to terminate security programs and escalate privileges, operating under CVE-2026-36425.
These multifaceted operations highlight a global, concerted effort by law enforcement and security researchers to combat diverse cyber threats, ranging from organized crime syndicates to sophisticated state-sponsored espionage and supply chain attacks.