Yoroi researchers disclosed SteelCorgi, a sophisticated modular espionage framework described as a "Swiss Army knife" for advanced persistent threat operations. The toolkit appears designed for flexible post-compromise activity, supporting surveillance, persistence, and broader intelligence collection through a range of interchangeable capabilities that make it suitable for long-term covert intrusions against high-value targets.
Separate reporting by IrpiMedia said a prominent Italian businessman was among the targets of Paragon spyware, adding to scrutiny of commercial and state-grade surveillance activity affecting individuals in Italy. Taken together, the reports point to an active threat environment in which advanced spyware and modular cyber-espionage tooling are being used against politically or economically significant targets, underscoring the risk to executives, public-interest figures, and other high-profile organizations.

TTPs, infrastructure, and targeting history in one profile.
2 events from the most recent confirmed update back to the earliest known activity.
IRPI Media reported that a prominent Italian businessman was among the targets of Paragon spyware, adding a newly disclosed victim to the spyware targeting story in Italy. No earlier event date is provided in the reference, so the publication date is used as the estimate.
Yoroi published research describing Steelcorgi as a sophisticated APT "Swiss Army knife," indicating public disclosure of technical details about the threat and its capabilities. The reference does not provide an earlier event date, so the publication date is used as the estimate.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.