home.social

#apt — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #apt, aggregated by home.social.

fetched live
  1. HoneyMyte aggiorna CoolClient: la backdoor di Mustang Panda ora si nasconde con un rootkit kernel

    Il gruppo APT cinese HoneyMyte (Mustang Panda) ha potenziato la sua backdoor CoolClient con un driver kernel firmato che nasconde processi, file e traffico C2. Analisi tecnica completa della catena di infezione e degli IoC contro obiettivi in Myanmar, Mongolia, Pakistan e Russia.

    insicurezzadigitale.com/honeym

  2. HoneyMyte aggiorna CoolClient: la backdoor di Mustang Panda ora si nasconde con un rootkit kernel

    Il gruppo APT cinese HoneyMyte (Mustang Panda) ha potenziato la sua backdoor CoolClient con un driver kernel firmato che nasconde processi, file e traffico C2. Analisi tecnica completa della catena di infezione e degli IoC contro obiettivi in Myanmar, Mongolia, Pakistan e Russia.

    insicurezzadigitale.com/honeym

  3. We have added indicators: Evilginx (+2), DanaBot (+1), Havoc (+2), Stealc (+1), Quasar RAT (+1), Remus (+2) and Chaos (+1). vuldb.com/actor #apt #cti #ioc

  4. We have added indicators: Evilginx (+2), DanaBot (+1), Havoc (+2), Stealc (+1), Quasar RAT (+1), Remus (+2) and Chaos (+1). vuldb.com/actor #apt #cti #ioc

  5. We have updated indicators: BillGates (+1), Havoc (+1), SnappyClient (+1), Kimwolf (+5), XenoRAT (+1), NonEuclid RAT (+1) and Gafgyt (+2). vuldb.com/actor #apt #cti #ioc

  6. We have updated indicators: BillGates (+1), Havoc (+1), SnappyClient (+1), Kimwolf (+5), XenoRAT (+1), NonEuclid RAT (+1) and Gafgyt (+2). vuldb.com/actor #apt #cti #ioc

  7. 📰 Armored Likho APT Targets Russia With New 'Still Toolkit'

    The 'Armored Likho' APT is targeting Russia with a new Rust-based 'Still Toolkit'. The malware steals Telegram session data to hijack accounts and covertly records audio from the victim's microphone for espionage. #APT #Malware #Espionage #Telegram

    🔗 cyber.netsecops.io/articles/ar

  8. 📰 Chinese Mercenary APT 'Jewelbug' Juggles Espionage and Crypto Theft

    A Chinese mercenary APT 'Jewelbug' is running dual espionage and crypto theft campaigns from the same platform. The group targets governments and military while also scamming crypto users with custom malware like 'Fostealer'. #APT #CyberSecurity #China

    🔗 cyber.netsecops.io/articles/je

  9. We have updated these actors: IClickFix (+1), XWorm (+2), Nanocore RAT (+1), FAKEUPDATES (+1), Remcos (+3), Unidentified VBS 001 (+2) and RemcosRAT (+1). vuldb.com/actor #apt #cti #ioc

  10. We have updated these actors: IClickFix (+1), XWorm (+2), Nanocore RAT (+1), FAKEUPDATES (+1), Remcos (+3), Unidentified VBS 001 (+2) and RemcosRAT (+1). vuldb.com/actor #apt #cti #ioc

  11. 📢 ⚠️ Researchers have linked 361 victim IPs in 47 countries to a suspected APT campaign exploiting a critical VMware vCenter flaw, CVE-2026-59310.

    Listen/Read: hackread.com/apt-exploits-crit

    #CyberSecurity #VMware #vCenter #APT #Vulnerability

  12. 📢 ⚠️ Researchers have linked 361 victim IPs in 47 countries to a suspected APT campaign exploiting a critical VMware vCenter flaw, CVE-2026-59310.

    Listen/Read: hackread.com/apt-exploits-crit

    #CyberSecurity #VMware #vCenter #APT #Vulnerability

  13. Improved indicators: Remcos (+1), DanaBot (+1), PoshC2 (+1), Sliver (+1), AdaptixC2 (+1), Aisuru (+4) and PureLogs Stealer (+1). vuldb.com/actor #apt #cti #ioc

  14. Improved indicators: Remcos (+1), DanaBot (+1), PoshC2 (+1), Sliver (+1), AdaptixC2 (+1), Aisuru (+4) and PureLogs Stealer (+1). vuldb.com/actor #apt #cti #ioc

  15. Google's top #hacker hunter explains why #hacking groups get codenames
    Gone are the days APT1, APT41 or #APT whatever number, which was the system adopted by #Mandiant, once an independent security firm now part of Google.
    From now on, Google’s system is relatively simple: A hacking group will have a first name that is memorable and random, and a second word whose initial indicates country of origin: Castle = #China, Ion = #Iran, Neptune = #NorthKorea, and Relic = #Russia
    techcrunch.com/2026/08/08/goog

  16. Google's top #hacker hunter explains why #hacking groups get codenames
    Gone are the days APT1, APT41 or #APT whatever number, which was the system adopted by #Mandiant, once an independent security firm now part of Google.
    From now on, Google’s system is relatively simple: A hacking group will have a first name that is memorable and random, and a second word whose initial indicates country of origin: Castle = #China, Ion = #Iran, Neptune = #NorthKorea, and Relic = #Russia
    techcrunch.com/2026/08/08/goog

  17. Tczew sotto attacco (di nuovo): dentro la campagna filorussa che sabota le centrali polacche

    Il 10 agosto una centrale idroelettrica vicino Danzica è stata sabotata per la seconda volta da hacker filorussi, che questa volta hanno colpito l'impianto a pieno regime. Il fatto si inserisce in una campagna più ampia che include il wiper DynoWiper di Sandworm e una tecnica di pivoting su APN privata mai documentata prima.

    insicurezzadigitale.com/tczew-

  18. Tczew sotto attacco (di nuovo): dentro la campagna filorussa che sabota le centrali polacche

    Il 10 agosto una centrale idroelettrica vicino Danzica è stata sabotata per la seconda volta da hacker filorussi, che questa volta hanno colpito l'impianto a pieno regime. Il fatto si inserisce in una campagna più ampia che include il wiper DynoWiper di Sandworm e una tecnica di pivoting su APN privata mai documentata prima.

    insicurezzadigitale.com/tczew-

  19. Added some more indicators for: GuLoader (+1), AgentTesla (+1), Kimwolf (+9), DeimosC2 (+1), DanaBot (+1), Chaos (+1) and AdaptixC2 (+2). vuldb.com/actor #apt #cti #ioc

  20. Added some more indicators for: GuLoader (+1), AgentTesla (+1), Kimwolf (+9), DeimosC2 (+1), DanaBot (+1), Chaos (+1) and AdaptixC2 (+2). vuldb.com/actor #apt #cti #ioc

  21. Added more indicators for: Evilginx (+1), Sliver (+2), AsyncRAT (+3), QuasarRAT (+1), Quasar RAT (+2), Remus (+1) and PureLogs Stealer (+1). vuldb.com/actor #apt #cti #ioc

  22. Added some indicators for: Monero (+4), XMRIG (+8), DeimosC2 (+1), Chaos (+1), AdaptixC2 (+4), Stealc (+1) and ClickFix (+1). vuldb.com/actor #apt #cti #ioc

  23. Alert. Masowo hackują sieci WiFi w hotelach / kawiarniach / na konferencjach na całym świecie. Cel: podróżujący pracownicy korporacji.

    O akcji ostrzega Microsoft, pisząc: zidentyfikowaliśmy w kilku krajach powszechne naruszenia bezpieczeństwa sieci WiFi w organizacjach z branży hotelarsko-gastronomicznej oraz w innych sieciach obsługiwanych przez urządzenia wspierające captive portal.Najpierw przejmowane są routerki dające dostęp do sieci WiFi. Umówmy się, często jedynym zabezpieczeniem w hotelu jest nieaktualizowany od 5 lat TP-Link...

    #Aktualności #Apt #Cyberawareness #Hotele #Rosja #Wifi

    sekurak.pl/alert-masowo-hackuj

  24. Added indicators for: Quasar RAT (+1), HijackLoader (+1), DeimosC2 (+1), pupy (+1), Remus (+1), Vidar (+8) and QuasarRAT (+1). vuldb.com/actor #apt #cti #ioc

  25. OctLurk e SilkLurk: la backdoor cinofona che si decifra solo sulla macchina della vittima

    Kaspersky svela OctLurk e SilkLurk, due backdoor usate da un attore cinofono per colpire enti governativi e sanitari in Asia Centrale dal 2025. Il payload si decifra solo sul dispositivo del bersaglio, usando il seriale del disco o il nome del computer come chiave, per rendere quasi impossibile l'analisi forense.

    insicurezzadigitale.com/octlur

  26. New indicators for: BillGates (+1), DeimosC2 (+1), XWorm (+2), SectopRAT (+1), AgentTesla (+2), RemcosRAT (+6) and Aisuru (+7). vuldb.com/actor #apt #cti #ioc

  27. OVERCAST PANDA: la Cina compromette fisicamente i laptop di giornalisti e scienziati in hotel

    Il CrowdStrike 2026 Threat Hunting Report rivela come, tra marzo e maggio 2026, l’adversary china-nexus OVERCAST PANDA abbia installato il backdoor FlowCloud su laptop incustoditi di giornalisti e ricercatori in viaggio in Cina, avviando i dispositivi da USB per bypassare EDR e difese di rete.

    insicurezzadigitale.com/overca

  28. Updated threat actors: Kimwolf (+10), PureLogs Stealer (+1), SmartApeSG (+1), AdaptixC2 (+7), Rekoobe (+1), Loda (+1) and Kimsuky (+1). vuldb.com/actor #apt #cti #ioc

  29. Как агентные LLM встроили в операцию против госструктур: разбор кампании Hunt.io

    Разбор отчёта Hunt.io о предполагаемой китайской кампании: открытый каталог, TencShell-инфраструктура, SQL-инъекции, фишинг и роль Claude Code с DeepSeek. Отделяем подтверждённые факты от атрибуционных гипотез и формулируем меры защиты.

    habr.com/ru/articles/1066644/

    #кибербезопасность #threat_intelligence #Claude_Code #DeepSeek #LLM #AIагенты #кибершпионаж #китай #apt

  30. We have improved indicators: Formbook (+1), BianLian (+1), XWorm (+3), SVCStealer (+1), Overlord RAT (+1), PureLogs Stealer (+3) and Sliver (+1). vuldb.com/actor #apt #cti #ioc

  31. Debian apt history-* commands introduced in version 3.2 (April 2026) are a major improvement: very useful when you want to test new softwares and/or development libraries. #APT #Debian linux.org/threads/using-apt-hi

  32. We have added indicators: Quasar RAT (+1), Eye Pyramid (+1), Havoc (+1), Evilginx (+2), Vidar (+32), Atomic Stealer (+1) and NetSupport (+1). vuldb.com/actor #apt #cti #ioc

  33. @protonblog Thank you!

    Could we kindly ask for an update on #ProtonPass automatic updates on #Linux #Debian ?
    The redownload of DEB file is easy but quite annoying to do. I'd love to have this handled via my #apt upgrades.

    Thank you!

  34. We have updated indicators: DPRK (+1), Havoc (+1), AsyncRAT (+2), Quasar RAT (+1), Meterpreter (+1), Aisuru (+1) and Evilginx (+2). vuldb.com/actor #apt #cti #ioc

  35. There are increased offensive activities for products of the category Remote Access Software vuldb.com/type/remote_access_s #cti #apt

  36. We have updated these actors: BillGates (+1), Evilginx (+2), Brute Ratel C4 (+2), Prometei (+1), Cobalt Strike (+13), Tsundere (+1) and AdaptixC2 (+3). vuldb.com/actor #apt #cti #ioc