KELA Research Center
Welcome to KELA Cyber Threat Intelligence Research! Stay informed, stay protected. Our expert team monitors evolving cyber threats, analyzing cybercrime underground sources, trends, tactics, and vulnerabilities. Get ahead of bad actors with insights on emerging attack techniques, industry-specific threats, and actionable recommendations to fortify your defenses.
Recent Research

Research
TeamPCP Threat Actor Profile
How KELA identified the man who led TeamPCP and handed law enforcement the identifier chain behind the arrest, plus the full technical profile of the group’s tradecraft and infrastructure.

Research
2026 AI Threat Landscape Report
KELA REPORT 2026 AI Threat Landscape:Offensive AI Has Gone Autonomous From assistant to operator — the agentic shift already rewriting the threat landscape In 2026, AI stopped waiting for instructions.Autonomous, goal-directed agents now run intrusions end to end — finding vulnerabilities, writing exploits, hijacking sessions, and moving laterally at machine speed. Drawing on KELA’s…

Research
2026 FIFA World Cup: Threats & Predictions
KELA REPORT 2026 FIFA World Cup: Threats & Predictions State-sponsored APTs, industrial-scale ticket fraud, and 1.5M+ leaked credentials: KELA’s CIC breaks down the cyber threats facing the 2026 FIFA World Cup and how to defend The world’s largest sporting event is also one of its largest attack surfaces. Across 16 host cities and a digital…

Research
The State of Cybercrime 2026: STRATEGIC REPORT
KELA REPORT The State of Cybercrime 2026: STRATEGIC REPORT Ground-truth intelligence from the KELA Cyber Intelligence Center on the threats that redefined 2025 and will dictate 2026 and beyond. 2025 was marked by the industrialization of zero-day exploits and the rise of high-velocity extortion. This retrospective provides the raw data and expert analysis required to…

Research
OpenClaw Threat Assessment
KELA REPORT OpenClaw or OpenFlaw? The Essential Threat Assessment of the Agentic AI Ecosystem Has your “productivity assistant” become a searchable entry point for global threat actors? The rapid transition from passive chat interfaces to autonomous OpenClaw agents has created a hyper-connected attack surface where a single compromise grants adversaries a persistent,…

Research
Alleged Knownsec Data Leak
KELA REPORT Alleged Knownsec Data Leak Unmasking the convergence of commercial innovation and state-sponsored cyber espionage in China. In late October 2025, a significant data leak allegedly exposed the internal operations of Knownsec, one of China’s leading cybersecurity firms. This research report analyzes the 12,000+ file dataset to reveal a company operating under a “civil-military…

Research
The Rise of macOS Infostealers: 2025 in Review
KELA REPORT The Rise of macOS Infostealers: 2025 in Review As Apple’s enterprise footprint expands, macOS has become an increasingly attractive target for threat actors. This report traces the rapid professionalization of macOS infostealers—fueled by Malware-as-a-Service (MaaS)—and shows how stolen credentials, cookies, and tokens translate into sellable corporate access. In KELA’s new report, you’ll learn:…

Research
Escalating Ransomware Threats to National Security
REPORT EscalatingRansomware Threats to National Security A Rising Scale of Attacks on Critical Infrastructure Sectors In KELA’s new report, you’ll learn: Ransomware has evolved from an enterprise risk into a strategic national security threat. Once driven primarily by profit, it is now leveraged by organized cybercriminals and state-linked actors to disrupt critical infrastructure, destabilize economies,…

Research
2025 Midyear Threat Report: Evolving Tactics and Emerging Dangers
KELA REPORT 2025 Midyear Threat Report: Evolving Tactics and Emerging Dangers A Guide to Prepare for the Growing Threats of Hacktivists, Infostealers, Ransomware and More This report features critical data, real-world examples, and actionable recommendations to help organizations protect themselves against the growing complexity of cyber threats arising from geopolitical tensions to multi-extortion ransomware campaigns.…

Research
Unveiling Black Basta’s Use of PhaaS Platforms Report
KELA REPORT Unveiling Black Basta’s Use of PhaaS Platforms How Top-Tier Ransomware Relies on External Phishing Services. A new investigation by KELA reveals how ransomware operators like Black Basta rely on professionalized Phishing-as-a-Service (PhaaS) offerings to scale their initial access operations. Based on leaked internal chats, the report exposes how these underground services play a…

Research
Beyond the Perimeter: Strengthening Security with External Risk Management
INDUSTRY REPORT Beyond the Perimeter: Strengthening Security with External Risk Management Frost & Sullivan provides a guide on how to enhance threat visibility, response and resilience in an evolving cyber landscape. As cloud adoption, IoT, and remote work continue to expand the attack surface, many organizations are focusing inward – relying on EDR, firewalls, and…

Research
Inside the Infostealer Epidemic: Exposing the Risks to Corporate Security Report
KELA REPORT Inside the Infostealer Epidemic: Exposing the Risks to Corporate Security How stolen credentials are fueling ransomware, fraud, and modern cybercrime With infostealer infections surging by 266% in recent years and attackers shifting to automated, subscription-based marketplaces, the cybercrime ecosystem is evolving rapidly – and becoming harder to stop. In this report, KELA analyzes…



