Radar links OSINT items by specificity-weighted similarity inside a 45-day window — a rare malware, CVE, or tracked actor binds strongly; generic techniques (T1566) barely count, and a specific shared pivot is required to form an edge — then groups them by community detection (Louvain). Clusters are tracked across runs with stable identity (candidate → corroborated → named); when their activity ages out they go dormant. Each is an Activity Group — a cluster of shared tradecraft and victimology, named independently of vendor aliases. Deterministic correlation, not confirmed attribution.
Reporting cadence by month per Activity Group — cells count items by publication date, a proxy for activity, not a confirmed activity timeline (reporting lags the event it describes). The two italic rows are deliberate intelligence gaps: Provisional = correlated but not yet a named campaign; Pending attribution = clusters with no linked actor. Gaps get worked, not hidden.
| Campaign | 26-02 | 26-03 | 26-04 | 26-05 | 26-06 | 26-07 | 26-08 | 26-09 | Σ |
|---|---|---|---|---|---|---|---|---|---|
| Lazarus Group (TraderTraitor cluster) / APT38 / BlueNoroff · SPECTRE | 3 | 10 | 5 | 18 | |||||
| AnyDesk | 1 | 5 | 5 | 11 | |||||
| payload · Amatera | 3 | 6 | 9 | ||||||
| SparrowDoor | 2 | 7 | 9 | ||||||
| UNC1549 / TA455 · NightLedger | 2 | 5 | 7 | ||||||
| JWR | 1 | 4 | 1 | 6 | |||||
| Qilin ransomware | 3 | 2 | 5 | ||||||
| PowerShell-based RAT | 5 | 5 | |||||||
| Astaroth | 2 | 3 | 5 | ||||||
| Warlock · MeshAgent | 2 | 1 | 1 | 4 | |||||
| JSCeal | 3 | 1 | 4 | ||||||
| Qilin (fka Agenda) · Qilin | 2 | 1 | 3 | ||||||
| msgbox.exe | 3 | 3 | |||||||
| infostealer | 1 | 2 | 3 | ||||||
| CVE-2026-83548 | 3 | 3 | |||||||
| msaRAT | 2 | 1 | 3 | ||||||
| MacSync | 3 | 3 | |||||||
| Cavern Manticore · Cavern | 2 | 2 | |||||||
| Cyclops Blink | 2 | 2 | |||||||
| CVE-2026-85880 | 2 | 2 | |||||||
| CornFlake | 1 | 1 | 2 | ||||||
| Provisional (correlated, unnamed) | 2 | 11 | 5 | 18 | |||||
| Pending attribution (no actor) | 9 | 41 | 34 | 84 |