#cyberespionage — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #cyberespionage, aggregated by home.social.
-
📰 China-Aligned APTs Use Public AI Tools in Espionage Campaigns
China-aligned APTs are now using public AI tools like Claude Code and DeepSeek in espionage campaigns. The attackers use the AI for scripting and command execution, targeting government and financial entities in Asia. #APT #CyberEspionage #AI #Threat...
🌐 cyber[.]netsecops[.]io
-
GoSerpent backdoor drives a patient cyber espionage campaign against Southeast Asian governments, stealing files and credentials since at least 2021.
#GoSerpent #CyberEspionage #Kaspersky #Backdoor #APT #SoutheastAsia #ThreatIntel
https://securityonline.info/goserpent-backdoor/?utm_source=mastodon&utm_medium=jetpack_social
-
Global Webmail Espionage
A persistent cyberespionage campaign tracked as CL-STA-1114, overlapping with Russian threat actor activity known as Void Blizzard and LAUNDRY BEAR, has been targeting Zimbra webmail in government, defense, transportation, and financial organizations. The campaign focuses on NATO member states, Ukraine, Commonwealth of Independent States countries, and Africa. Attackers exploit CVE-2025-66376, a vulnerability in Zimbra Collaboration Suite, using zero-click phishing emails that automatically inject malicious JavaScript payloads without user interaction. The payload exfiltrates sensitive data including login credentials, email archives, CSRF tokens, 2FA scratch codes, and 90 days of email history to command and control servers. Active since 2024, the campaign targeting Zimbra servers began in July 2025, utilizing HTML attachments with obfuscated Base64-encoded scripts that deploy SVG elements to inject the JavaScript into victims' browsers.
Pulse ID: 6a624073df6738006a6f6e5a
Pulse Link: https://otx.alienvault.com/pulse/6a624073df6738006a6f6e5a
Pulse Author: AlienVault
Created: 2026-07-23 16:25:23Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#2FA #Africa #Browser #CyberSecurity #Cyberespionage #Email #Espionage #Government #HTML #InfoSec #Java #JavaScript #NATO #OTX #OpenThreatExchange #Phishing #RAT #Russia #SVG #UK #Ukr #Ukraine #Vulnerability #Webmail #Zimbra #bot #AlienVault
-
🚨 SIGINT // Cybersecurity Watch — 2026-07-24
US agencies warn Iran-affiliated hackers are targeting Siemens, Schneider Electric & Rockwell ICS devices in critical infrastructure attacks.
https://www.securityweek.com/us-warns-of-iranian-hackers-targeting-siemens-schneider-and-rockwell-ics-devices/
#ICS #CriticalInfrastructure #CyberEspionage #InfoSec -
New Project CAV3RN .NET Native AOT communication module
Kaspersky identified a new .NET Native AOT communication module for Project CAV3RN, a sophisticated cyberespionage framework targeting Israel. This module replaces the previous HTTP/WebSocket component by exchanging commands through Outlook calendar events accessed via Microsoft Graph API. Commands and results are stored in a fixed time window (2050-05-13 22:00-23:00 UTC) using specific subject patterns to identify heartbeats, commands, and outputs. The module implements RSA and AES-GCM encryption for secure communications. If Microsoft Graph authentication fails, it retrieves replacement configuration settings through DNS AAAA record responses from actor-controlled nameservers. The infrastructure analysis and behavioral patterns suggest low-confidence attribution to OilRig (APT34), based on the use of Microsoft-hosted services for command and control and compromised regional infrastructure.
Pulse ID: 6a5f55d6d75eaa9d17122eea
Pulse Link: https://otx.alienvault.com/pulse/6a5f55d6d75eaa9d17122eea
Pulse Author: AlienVault
Created: 2026-07-21 11:19:50Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#APT34 #CyberSecurity #Cyberespionage #DNS #Encryption #Espionage #HTTP #InfoSec #Israel #Kaspersky #Microsoft #NET #OTX #OilRig #OpenThreatExchange #Outlook #RAT #Troll #bot #AlienVault
-
📰 China-Aligned APTs Use Public AI Tools in Espionage Campaigns
China-aligned APTs are now using public AI tools like Claude Code and DeepSeek in espionage campaigns. The attackers use the AI for scripting and command execution, targeting government and financial entities in Asia. #APT #CyberEspionage #AI #Threat...
🌐 cyber[.]netsecops[.]io
-
GoSerpentMalware Targets GovermnentNetworks to Steal Classified Data
"A cyber-espionage campaign using the GoSerpentremote access Trojan targeted government and diplomatic organizations across Southeast Asia, silently collecting sensitive documents, dumping credentials, and staging stolen data for weeks before exfiltrating it through compromised network shares using an evolved toolchain.
Pulse ID: 6a5cbd8f107f8c3b9ebaf4d3
Pulse Link: https://otx.alienvault.com/pulse/6a5cbd8f107f8c3b9ebaf4d3
Pulse Author: cryptocti
Created: 2026-07-19 12:05:35Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Asia #CyberSecurity #Espionage #Government #InfoSec #Malware #OTX #OpenThreatExchange #RAT #RemoteAccessTrojan #Trojan #bot #cyberespionage #cryptocti
-
He was an astronomer. Not a spy. Not a cop. Just a curious man who found a 75-cent error and followed it all the way to the KGB. Read The Cuckoo's Egg.
#CuckoosEgg #CliffordStoll #CyberEspionage #books #bookreviews
https://thisgrandpablogs.com/cuckoos-egg-book-review/ -
This is one of the first true accounts of cyber espionage ever written. It holds up after 35 years. Read why.
#books #bookreview #cyberespionage #coldwarspy
https://thisgrandpablogs.com/cuckoos-egg-book-review/ -
CRITICAL threat: Russian FSB-linked cyber espionage & sabotage campaign hits gov & infrastructure across Europe since 2010. No CVE, but big impact on power, heating, transport. Follow national guidance; boost vigilance. https://radar.offseq.com/threat/eu-targets-russian-intelligence-officers-accused-o-fc2dc036f7820f41 #OffSeq #CyberEspionage #FSB #EU
-
One Target, Two Flags | Rival Espionage Actors Converge On Pakistani Law Enforcement
Between February 2024 and April 2026, multiple cyberespionage actors, suspected to be China-nexus and India-nexus threat groups, conducted sustained intrusions into Pakistani law enforcement organizations, particularly Balochistan Police. The compromised infrastructure included network appliances and servers hosting web applications managing criminal records, biometric data, hotel registrations, and citizen complaints. A suspected China-nexus actor weaponized the Complaint Management System web application by deploying custom implants disguised as portal updates, targeting both police personnel and citizens. China's likely motivation stems from concerns over the safety of Chinese nationals in Pakistan, particularly regarding attacks by separatist groups. India's suspected interest relates to its adversarial relationship with Pakistan, with Balochistan Police offering intelligence on security operations in a strategically sensitive province. The attackers deployed PlugX, ShadowPad, Cobalt Strike, Remcos, an...
Pulse ID: 6a501da43fb3cb230cc9a9b9
Pulse Link: https://otx.alienvault.com/pulse/6a501da43fb3cb230cc9a9b9
Pulse Author: AlienVault
Created: 2026-07-09 22:16:04Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Biometric #China #Chinese #CobaltStrike #CyberSecurity #Cyberespionage #Espionage #India #InfoSec #LawEnforcement #OTX #OpenThreatExchange #Pakistan #PlugX #RAT #RCE #Remcos #ShadowPad #bot #AlienVault
-
🚨 A newly identified APT dubbed #ArmoredLikho is targeting government agencies and energy organizations with #BusySnake Stealer, a Python-based infostealer delivered through AI-generated loaders and spear-phishing campaigns.
The malware steals credentials, Telegram sessions, cryptocurrency wallets, and more, while built-in reverse SSH tunneling gives attackers long-term remote access.
Listen/Read: https://hackread.com/armored-likho-government-energy-busysnake-stealer/
#CyberSecurity #InfoSec #APT #Malware #Phishing #CyberEspionage
-
2/3
GTG-1002: Anthropic's own disclosed report on a Chinese state-sponsored group that jailbroke Claude Code by claiming to be a legitimate security firm, then ran ~80-90% of a 30-target espionage campaign autonomously. Five months before contested (unconfirmed) covert China-proxy detection code turned up in Claude Code. The timing isn't abstract. -
APT group targeting governmental agencies in East Asia
A Chinese-speaking cyber-espionage group known as LuckyMouse is behind a new campaign targeting government institutions in East Asia, according to research by Avast and the Kaspersky Labs security team.
Pulse ID: 6a449938480820de2d1f55b6
Pulse Link: https://otx.alienvault.com/pulse/6a449938480820de2d1f55b6
Pulse Author: Tr1sa111
Created: 2026-07-01 04:36:08Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Asia #Chinese #CyberSecurity #Espionage #Government #InfoSec #Kaspersky #OTX #OpenThreatExchange #bot #cyberespionage #Tr1sa111
-
During H1 2026 I recorded 55 incidents exploiting 66 #vulnerabilities targeting security vendors
🔴 50% #Cybercrime
🔴 22% #Cyberespionage
🔴 #Malware & #RCE dominate attack techniquesFull interactive report 👇
https://hackmageddon.com/2026/06/25/exploited-security-vendor-vulnerabilities-in-2026/ -
MuddyWater Exploits Ransomware Disguise for Cyber Espionage
The line between ransomware attacks and nation-state espionage is rapidly blurring, as cyber groups like MuddyWater now disguise their operations as financially motivated ransomware attacks to further their strategic objectives. MuddyWater, linked to Iran's Ministry of Intelligence and Security, has been caught posing as the Chaos ransomware group in…
-
During June 1-15 2026 I collected 80 incidents: #cybercrime 68.8%, #malware 40%, #cyberespionage 25%. #Supplychain worms hit npm/PyPI/GitHub. ShinyHunters, Qilin & Volt Typhoon most active.#Infographic below, full data 👉 http://hackmageddon.com/2026/06/23/1-15-june-2026-cyber-attacks-timeline/
-
The FBI ignored it. The CIA passed. One scientist refused to let it go. This book is that story.
#books #bookreview #cyberespionage #hackerthriller
https://thisgrandpablogs.com/cuckoos-egg-book-review/ -
Cyber Recon: My Life in Cyber Espionage and Ransomware Negotiation by Kurtis Minder, 2025
An up close and personal look at cyber espionage and digital spycraft In Cyber Recon: My Life in Cyber Espionage and Ransomware Negotiation, 30-year cybersecurity veteran Kurtis Minder delivers a fascinating exploration of real-world cyber espionage in some of the most dangerous places on the Internet.
-
🚀🤦♂️ Someone discovered Slack video embeds and thinks they've cracked the cyber espionage code by slipping messages through them. What’s next, Morse code over Excel spreadsheets? 📊💻
https://v1c.rocks/log/exploiting-slack-video/ #SlackVideoEmbeds #CyberEspionage #CodeCracking #DigitalCommunication #CreativeHacking #HackerNews #ngated -
The National Security Agency is reportedly using Anthropic's Mythos model, raising questions abot embedded engineer roles, classified target approval, and Pentagon access.
#AI #Mythos #Anthropic #NSA #Cybersecurity #AISecurity #CyberThreats #Cyberattacks #Cyberespionage #Claude
-
📰 Iranian APT 'Screening Serpens' Intensifies Espionage with New RATs Targeting US, Israel, and UAE
🇮🇷 Iranian APT 'Screening Serpens' escalates cyber-espionage against US, Israel & UAE. New RATs 'MiniUpdate' & 'MiniJunk V2' deployed. Group using advanced AppDomainManager hijacking for persistence. #APT #CyberEspionage #Iran #ThreatIntel
🌐 cyber[.]netsecops[.]io
-
📰 Iranian APT 'Screening Serpens' Intensifies Espionage with New RATs Targeting US, Israel, and UAE
🇮🇷 Iranian APT 'Screening Serpens' escalates cyber-espionage against US, Israel & UAE. New RATs 'MiniUpdate' & 'MiniJunk V2' deployed. Group using advanced AppDomainManager hijacking for persistence. #APT #CyberEspionage #Iran #ThreatIntel
🌐 cyber[.]netsecops[.]io
-
Xu Zewei was arrested at Milan Malpensa on July 3, 2025 and extradited from Italy to the United States on April 26, 2026. U.S. prosecutors accuse him of participating in cyber operations targeting universities, COVID-related research, and sensitive networks allegedly linked to Chinese state interests.
But beyond the legal case, another question may be more interesting.
This investigation began in a climate defined by strategic competition between Washington and Beijing. Today, however, U.S.-China relations appear to be entering a more complex phase, with renewed signals of dialogue and economic cooperation.
Will Xu remain a symbol of cyber conflict, or will his case gradually fade into the background as larger geopolitical priorities take over?
And one more question that deserves attention: is it really plausible that a Chinese citizen allegedly wanted by the United States since 2023 simply decided to spend a vacation in Italy? Or was there another reason behind that trip?
The unsealed U.S. court document in the Xu Zewei case can be read here:
https://ismg-cdn.nyc3.cdn.digitaloceanspaces.com/asset_files/external/indictmentxuzewei.pdfPerhaps Xu Zewei’s legal fate will be decided in a courtroom. The meaning of his story, however, may ultimately be decided somewhere else.
#CyberSecurity #China #Intelligence #CyberEspionage #Geopolitics
-
A 75-cent billing error. A hacker selling US secrets to the KGB. One astronomer who refused to look away. The Cuckoo's Egg is a true spy story like no other.
#CuckoosEgg #CliffordStoll #CyberEspionage #books #bookreviews
https://thisgrandpablogs.com/cuckoos-egg-book-review/