Recorded Future Insikt Group
recordedfuture-insikt · B · active
https://www.recordedfuture.com/research/insikt-group
Recorded Future research arm. URL CORRECTED 2026-05-08: /research is a marketing landing, sub-agents got no article list. The Insikt Group blog listing is at /research/insikt-group; the threat-research feed is at /threat-research/feed. 2026-05-08 audit: still STUB-prone (page rendered without article cards). Treat as low-frequency rotation source. | 2026-06-20 full audit (v2.62): live=Y, drill=Y. FETCH → rss: python3 tools/fetch_source.py feed https://www.recordedfuture.com/feed 5 (then WebFetch the /blog/<slug> URL for the body). The /feed works; the documented /threat-research/feed and /research/insikt-group landing do NOT.. AVOID: Don't WebFetch /research/insikt-group, it's a marketing stub with no article cards. The documented /threat-research/feed 404s. Use /feed instead.. | 2026-07-05 admiralty audit: B, original vendor threat-research lab (Insikt), first-hand actor/campaign analysis. Live via /feed; active retained. | 2026-08-04 run: RECIPE GAP, https://www.recordedfuture.com/research/insikt-group is a landing/mission page with no dated article listing reachable via WebFetch. Needs a replacement discovery path. | 2026-08-16 weekly (RECIPE FIX): the logged recipe gap is resolved, https://www.recordedfuture.com/feed returns a full, dated RSS feed with direct article links (the /research/rss.xml path 404s). fetch_method webfetch -> rss with that rss_url; the /research/insikt-group landing page remains a mission page with no dated listing and should not be used for discovery. Contributed the crypting-services market survey this run.
Cited in 3 entries
Citation cadence
Citation days per ISO week (17 weeks of coverage span, total 3).
- Recorded Future's H1 2026 Malware and Vulnerability Trends: two clusters reuse an identical post-exploitation tool stack across thirteen and ten unrelated initial CVEs2026-09-07
- PurpleDelta: Insikt Group gets inside a North Korean IT-worker operation and finds the detectable half is on the endpoint, a second remote-management tool on the company laptop, and a device whose location never matches the login2026-08-19
- Netherlands FIOD arrests two over EU sanctions evasion for Stark Industries front; 800 servers seized; NoName057(16) DDoS plumbing dismantled2026-05-23