#cyberespionage — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #cyberespionage, aggregated by home.social.
-
https://www.europesays.com/ie/605109/ Hackers Hijack Hotel Wi-Fi to Steal Microsoft 365 Credentials #APT28 #Cyberespionage #Éire #Hacking #HackingNews #HotelWiFi #IE #InformationSecurityNews #Ireland #ITInformationSecurity #PierluigiPaganini #SecurityAffairs #SecurityNews #Technology
-
📰 China-Aligned APTs Use Public AI Tools in Espionage Campaigns
China-aligned APTs are now using public AI tools like Claude Code and DeepSeek in espionage campaigns. The attackers use the AI for scripting and command execution, targeting government and financial entities in Asia. #APT #CyberEspionage #AI #Threat...
🌐 cyber[.]netsecops[.]io
-
📰 China-Aligned APTs Use Public AI Tools in Espionage Campaigns
China-aligned APTs are now using public AI tools like Claude Code and DeepSeek in espionage campaigns. The attackers use the AI for scripting and command execution, targeting government and financial entities in Asia. #APT #CyberEspionage #AI #Threat...
🌐 cyber[.]netsecops[.]io
-
📰 China-Aligned APTs Use Public AI Tools in Espionage Campaigns
China-aligned APTs are now using public AI tools like Claude Code and DeepSeek in espionage campaigns. The attackers use the AI for scripting and command execution, targeting government and financial entities in Asia. #APT #CyberEspionage #AI #Threat...
🌐 cyber[.]netsecops[.]io
-
📰 China-Aligned APTs Use Public AI Tools in Espionage Campaigns
China-aligned APTs are now using public AI tools like Claude Code and DeepSeek in espionage campaigns. The attackers use the AI for scripting and command execution, targeting government and financial entities in Asia. #APT #CyberEspionage #AI #Threat...
🌐 cyber[.]netsecops[.]io
-
📰 China-Aligned APTs Use Public AI Tools in Espionage Campaigns
China-aligned APTs are now using public AI tools like Claude Code and DeepSeek in espionage campaigns. The attackers use the AI for scripting and command execution, targeting government and financial entities in Asia. #APT #CyberEspionage #AI #Threat...
🌐 cyber[.]netsecops[.]io
-
GoSerpent backdoor drives a patient cyber espionage campaign against Southeast Asian governments, stealing files and credentials since at least 2021.
#GoSerpent #CyberEspionage #Kaspersky #Backdoor #APT #SoutheastAsia #ThreatIntel
https://securityonline.info/goserpent-backdoor/?utm_source=mastodon&utm_medium=jetpack_social
-
GoSerpent backdoor drives a patient cyber espionage campaign against Southeast Asian governments, stealing files and credentials since at least 2021.
#GoSerpent #CyberEspionage #Kaspersky #Backdoor #APT #SoutheastAsia #ThreatIntel
https://securityonline.info/goserpent-backdoor/?utm_source=mastodon&utm_medium=jetpack_social
-
GoSerpent backdoor drives a patient cyber espionage campaign against Southeast Asian governments, stealing files and credentials since at least 2021.
#GoSerpent #CyberEspionage #Kaspersky #Backdoor #APT #SoutheastAsia #ThreatIntel
https://securityonline.info/goserpent-backdoor/?utm_source=mastodon&utm_medium=jetpack_social
-
GoSerpent backdoor drives a patient cyber espionage campaign against Southeast Asian governments, stealing files and credentials since at least 2021.
#GoSerpent #CyberEspionage #Kaspersky #Backdoor #APT #SoutheastAsia #ThreatIntel
https://securityonline.info/goserpent-backdoor/?utm_source=mastodon&utm_medium=jetpack_social
-
GoSerpent backdoor drives a patient cyber espionage campaign against Southeast Asian governments, stealing files and credentials since at least 2021.
#GoSerpent #CyberEspionage #Kaspersky #Backdoor #APT #SoutheastAsia #ThreatIntel
https://securityonline.info/goserpent-backdoor/?utm_source=mastodon&utm_medium=jetpack_social
-
Global Webmail Espionage
A persistent cyberespionage campaign tracked as CL-STA-1114, overlapping with Russian threat actor activity known as Void Blizzard and LAUNDRY BEAR, has been targeting Zimbra webmail in government, defense, transportation, and financial organizations. The campaign focuses on NATO member states, Ukraine, Commonwealth of Independent States countries, and Africa. Attackers exploit CVE-2025-66376, a vulnerability in Zimbra Collaboration Suite, using zero-click phishing emails that automatically inject malicious JavaScript payloads without user interaction. The payload exfiltrates sensitive data including login credentials, email archives, CSRF tokens, 2FA scratch codes, and 90 days of email history to command and control servers. Active since 2024, the campaign targeting Zimbra servers began in July 2025, utilizing HTML attachments with obfuscated Base64-encoded scripts that deploy SVG elements to inject the JavaScript into victims' browsers.
Pulse ID: 6a624073df6738006a6f6e5a
Pulse Link: https://otx.alienvault.com/pulse/6a624073df6738006a6f6e5a
Pulse Author: AlienVault
Created: 2026-07-23 16:25:23Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#2FA #Africa #Browser #CyberSecurity #Cyberespionage #Email #Espionage #Government #HTML #InfoSec #Java #JavaScript #NATO #OTX #OpenThreatExchange #Phishing #RAT #Russia #SVG #UK #Ukr #Ukraine #Vulnerability #Webmail #Zimbra #bot #AlienVault
-
Global Webmail Espionage
A persistent cyberespionage campaign tracked as CL-STA-1114, overlapping with Russian threat actor activity known as Void Blizzard and LAUNDRY BEAR, has been targeting Zimbra webmail in government, defense, transportation, and financial organizations. The campaign focuses on NATO member states, Ukraine, Commonwealth of Independent States countries, and Africa. Attackers exploit CVE-2025-66376, a vulnerability in Zimbra Collaboration Suite, using zero-click phishing emails that automatically inject malicious JavaScript payloads without user interaction. The payload exfiltrates sensitive data including login credentials, email archives, CSRF tokens, 2FA scratch codes, and 90 days of email history to command and control servers. Active since 2024, the campaign targeting Zimbra servers began in July 2025, utilizing HTML attachments with obfuscated Base64-encoded scripts that deploy SVG elements to inject the JavaScript into victims' browsers.
Pulse ID: 6a624073df6738006a6f6e5a
Pulse Link: https://otx.alienvault.com/pulse/6a624073df6738006a6f6e5a
Pulse Author: AlienVault
Created: 2026-07-23 16:25:23Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#2FA #Africa #Browser #CyberSecurity #Cyberespionage #Email #Espionage #Government #HTML #InfoSec #Java #JavaScript #NATO #OTX #OpenThreatExchange #Phishing #RAT #Russia #SVG #UK #Ukr #Ukraine #Vulnerability #Webmail #Zimbra #bot #AlienVault
-
Global Webmail Espionage
A persistent cyberespionage campaign tracked as CL-STA-1114, overlapping with Russian threat actor activity known as Void Blizzard and LAUNDRY BEAR, has been targeting Zimbra webmail in government, defense, transportation, and financial organizations. The campaign focuses on NATO member states, Ukraine, Commonwealth of Independent States countries, and Africa. Attackers exploit CVE-2025-66376, a vulnerability in Zimbra Collaboration Suite, using zero-click phishing emails that automatically inject malicious JavaScript payloads without user interaction. The payload exfiltrates sensitive data including login credentials, email archives, CSRF tokens, 2FA scratch codes, and 90 days of email history to command and control servers. Active since 2024, the campaign targeting Zimbra servers began in July 2025, utilizing HTML attachments with obfuscated Base64-encoded scripts that deploy SVG elements to inject the JavaScript into victims' browsers.
Pulse ID: 6a624073df6738006a6f6e5a
Pulse Link: https://otx.alienvault.com/pulse/6a624073df6738006a6f6e5a
Pulse Author: AlienVault
Created: 2026-07-23 16:25:23Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#2FA #Africa #Browser #CyberSecurity #Cyberespionage #Email #Espionage #Government #HTML #InfoSec #Java #JavaScript #NATO #OTX #OpenThreatExchange #Phishing #RAT #Russia #SVG #UK #Ukr #Ukraine #Vulnerability #Webmail #Zimbra #bot #AlienVault
-
Global Webmail Espionage
A persistent cyberespionage campaign tracked as CL-STA-1114, overlapping with Russian threat actor activity known as Void Blizzard and LAUNDRY BEAR, has been targeting Zimbra webmail in government, defense, transportation, and financial organizations. The campaign focuses on NATO member states, Ukraine, Commonwealth of Independent States countries, and Africa. Attackers exploit CVE-2025-66376, a vulnerability in Zimbra Collaboration Suite, using zero-click phishing emails that automatically inject malicious JavaScript payloads without user interaction. The payload exfiltrates sensitive data including login credentials, email archives, CSRF tokens, 2FA scratch codes, and 90 days of email history to command and control servers. Active since 2024, the campaign targeting Zimbra servers began in July 2025, utilizing HTML attachments with obfuscated Base64-encoded scripts that deploy SVG elements to inject the JavaScript into victims' browsers.
Pulse ID: 6a624073df6738006a6f6e5a
Pulse Link: https://otx.alienvault.com/pulse/6a624073df6738006a6f6e5a
Pulse Author: AlienVault
Created: 2026-07-23 16:25:23Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#2FA #Africa #Browser #CyberSecurity #Cyberespionage #Email #Espionage #Government #HTML #InfoSec #Java #JavaScript #NATO #OTX #OpenThreatExchange #Phishing #RAT #Russia #SVG #UK #Ukr #Ukraine #Vulnerability #Webmail #Zimbra #bot #AlienVault
-
Global Webmail Espionage
A persistent cyberespionage campaign tracked as CL-STA-1114, overlapping with Russian threat actor activity known as Void Blizzard and LAUNDRY BEAR, has been targeting Zimbra webmail in government, defense, transportation, and financial organizations. The campaign focuses on NATO member states, Ukraine, Commonwealth of Independent States countries, and Africa. Attackers exploit CVE-2025-66376, a vulnerability in Zimbra Collaboration Suite, using zero-click phishing emails that automatically inject malicious JavaScript payloads without user interaction. The payload exfiltrates sensitive data including login credentials, email archives, CSRF tokens, 2FA scratch codes, and 90 days of email history to command and control servers. Active since 2024, the campaign targeting Zimbra servers began in July 2025, utilizing HTML attachments with obfuscated Base64-encoded scripts that deploy SVG elements to inject the JavaScript into victims' browsers.
Pulse ID: 6a624073df6738006a6f6e5a
Pulse Link: https://otx.alienvault.com/pulse/6a624073df6738006a6f6e5a
Pulse Author: AlienVault
Created: 2026-07-23 16:25:23Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#2FA #Africa #Browser #CyberSecurity #Cyberespionage #Email #Espionage #Government #HTML #InfoSec #Java #JavaScript #NATO #OTX #OpenThreatExchange #Phishing #RAT #Russia #SVG #UK #Ukr #Ukraine #Vulnerability #Webmail #Zimbra #bot #AlienVault
-
🚨 SIGINT // Cybersecurity Watch — 2026-07-24
US agencies warn Iran-affiliated hackers are targeting Siemens, Schneider Electric & Rockwell ICS devices in critical infrastructure attacks.
https://www.securityweek.com/us-warns-of-iranian-hackers-targeting-siemens-schneider-and-rockwell-ics-devices/
#ICS #CriticalInfrastructure #CyberEspionage #InfoSec -
🚨 SIGINT // Cybersecurity Watch — 2026-07-24
US agencies warn Iran-affiliated hackers are targeting Siemens, Schneider Electric & Rockwell ICS devices in critical infrastructure attacks.
https://www.securityweek.com/us-warns-of-iranian-hackers-targeting-siemens-schneider-and-rockwell-ics-devices/
#ICS #CriticalInfrastructure #CyberEspionage #InfoSec -
🚨 SIGINT // Cybersecurity Watch — 2026-07-24
US agencies warn Iran-affiliated hackers are targeting Siemens, Schneider Electric & Rockwell ICS devices in critical infrastructure attacks.
https://www.securityweek.com/us-warns-of-iranian-hackers-targeting-siemens-schneider-and-rockwell-ics-devices/
#ICS #CriticalInfrastructure #CyberEspionage #InfoSec -
Discover how the HollowGraph malware exploits Microsoft 365 calendars for C2 communication and data exfiltration in targeted espionage attacks.
#HollowGraph #Microsoft365 #Malware #CyberEspionage #InfoSec #GroupIB
-
Discover how the HollowGraph malware exploits Microsoft 365 calendars for C2 communication and data exfiltration in targeted espionage attacks.
#HollowGraph #Microsoft365 #Malware #CyberEspionage #InfoSec #GroupIB
-
New Project CAV3RN .NET Native AOT communication module
Kaspersky identified a new .NET Native AOT communication module for Project CAV3RN, a sophisticated cyberespionage framework targeting Israel. This module replaces the previous HTTP/WebSocket component by exchanging commands through Outlook calendar events accessed via Microsoft Graph API. Commands and results are stored in a fixed time window (2050-05-13 22:00-23:00 UTC) using specific subject patterns to identify heartbeats, commands, and outputs. The module implements RSA and AES-GCM encryption for secure communications. If Microsoft Graph authentication fails, it retrieves replacement configuration settings through DNS AAAA record responses from actor-controlled nameservers. The infrastructure analysis and behavioral patterns suggest low-confidence attribution to OilRig (APT34), based on the use of Microsoft-hosted services for command and control and compromised regional infrastructure.
Pulse ID: 6a5f55d6d75eaa9d17122eea
Pulse Link: https://otx.alienvault.com/pulse/6a5f55d6d75eaa9d17122eea
Pulse Author: AlienVault
Created: 2026-07-21 11:19:50Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#APT34 #CyberSecurity #Cyberespionage #DNS #Encryption #Espionage #HTTP #InfoSec #Israel #Kaspersky #Microsoft #NET #OTX #OilRig #OpenThreatExchange #Outlook #RAT #Troll #bot #AlienVault
-
New Project CAV3RN .NET Native AOT communication module
Kaspersky identified a new .NET Native AOT communication module for Project CAV3RN, a sophisticated cyberespionage framework targeting Israel. This module replaces the previous HTTP/WebSocket component by exchanging commands through Outlook calendar events accessed via Microsoft Graph API. Commands and results are stored in a fixed time window (2050-05-13 22:00-23:00 UTC) using specific subject patterns to identify heartbeats, commands, and outputs. The module implements RSA and AES-GCM encryption for secure communications. If Microsoft Graph authentication fails, it retrieves replacement configuration settings through DNS AAAA record responses from actor-controlled nameservers. The infrastructure analysis and behavioral patterns suggest low-confidence attribution to OilRig (APT34), based on the use of Microsoft-hosted services for command and control and compromised regional infrastructure.
Pulse ID: 6a5f55d6d75eaa9d17122eea
Pulse Link: https://otx.alienvault.com/pulse/6a5f55d6d75eaa9d17122eea
Pulse Author: AlienVault
Created: 2026-07-21 11:19:50Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#APT34 #CyberSecurity #Cyberespionage #DNS #Encryption #Espionage #HTTP #InfoSec #Israel #Kaspersky #Microsoft #NET #OTX #OilRig #OpenThreatExchange #Outlook #RAT #Troll #bot #AlienVault
-
New Project CAV3RN .NET Native AOT communication module
Kaspersky identified a new .NET Native AOT communication module for Project CAV3RN, a sophisticated cyberespionage framework targeting Israel. This module replaces the previous HTTP/WebSocket component by exchanging commands through Outlook calendar events accessed via Microsoft Graph API. Commands and results are stored in a fixed time window (2050-05-13 22:00-23:00 UTC) using specific subject patterns to identify heartbeats, commands, and outputs. The module implements RSA and AES-GCM encryption for secure communications. If Microsoft Graph authentication fails, it retrieves replacement configuration settings through DNS AAAA record responses from actor-controlled nameservers. The infrastructure analysis and behavioral patterns suggest low-confidence attribution to OilRig (APT34), based on the use of Microsoft-hosted services for command and control and compromised regional infrastructure.
Pulse ID: 6a5f55d6d75eaa9d17122eea
Pulse Link: https://otx.alienvault.com/pulse/6a5f55d6d75eaa9d17122eea
Pulse Author: AlienVault
Created: 2026-07-21 11:19:50Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#APT34 #CyberSecurity #Cyberespionage #DNS #Encryption #Espionage #HTTP #InfoSec #Israel #Kaspersky #Microsoft #NET #OTX #OilRig #OpenThreatExchange #Outlook #RAT #Troll #bot #AlienVault
-
New Project CAV3RN .NET Native AOT communication module
Kaspersky identified a new .NET Native AOT communication module for Project CAV3RN, a sophisticated cyberespionage framework targeting Israel. This module replaces the previous HTTP/WebSocket component by exchanging commands through Outlook calendar events accessed via Microsoft Graph API. Commands and results are stored in a fixed time window (2050-05-13 22:00-23:00 UTC) using specific subject patterns to identify heartbeats, commands, and outputs. The module implements RSA and AES-GCM encryption for secure communications. If Microsoft Graph authentication fails, it retrieves replacement configuration settings through DNS AAAA record responses from actor-controlled nameservers. The infrastructure analysis and behavioral patterns suggest low-confidence attribution to OilRig (APT34), based on the use of Microsoft-hosted services for command and control and compromised regional infrastructure.
Pulse ID: 6a5f55d6d75eaa9d17122eea
Pulse Link: https://otx.alienvault.com/pulse/6a5f55d6d75eaa9d17122eea
Pulse Author: AlienVault
Created: 2026-07-21 11:19:50Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#APT34 #CyberSecurity #Cyberespionage #DNS #Encryption #Espionage #HTTP #InfoSec #Israel #Kaspersky #Microsoft #NET #OTX #OilRig #OpenThreatExchange #Outlook #RAT #Troll #bot #AlienVault
-
New Project CAV3RN .NET Native AOT communication module
Kaspersky identified a new .NET Native AOT communication module for Project CAV3RN, a sophisticated cyberespionage framework targeting Israel. This module replaces the previous HTTP/WebSocket component by exchanging commands through Outlook calendar events accessed via Microsoft Graph API. Commands and results are stored in a fixed time window (2050-05-13 22:00-23:00 UTC) using specific subject patterns to identify heartbeats, commands, and outputs. The module implements RSA and AES-GCM encryption for secure communications. If Microsoft Graph authentication fails, it retrieves replacement configuration settings through DNS AAAA record responses from actor-controlled nameservers. The infrastructure analysis and behavioral patterns suggest low-confidence attribution to OilRig (APT34), based on the use of Microsoft-hosted services for command and control and compromised regional infrastructure.
Pulse ID: 6a5f55d6d75eaa9d17122eea
Pulse Link: https://otx.alienvault.com/pulse/6a5f55d6d75eaa9d17122eea
Pulse Author: AlienVault
Created: 2026-07-21 11:19:50Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#APT34 #CyberSecurity #Cyberespionage #DNS #Encryption #Espionage #HTTP #InfoSec #Israel #Kaspersky #Microsoft #NET #OTX #OilRig #OpenThreatExchange #Outlook #RAT #Troll #bot #AlienVault
-
📰 China-Aligned APTs Use Public AI Tools in Espionage Campaigns
China-aligned APTs are now using public AI tools like Claude Code and DeepSeek in espionage campaigns. The attackers use the AI for scripting and command execution, targeting government and financial entities in Asia. #APT #CyberEspionage #AI #Threat...
🌐 cyber[.]netsecops[.]io
-
📰 China-Aligned APTs Use Public AI Tools in Espionage Campaigns
China-aligned APTs are now using public AI tools like Claude Code and DeepSeek in espionage campaigns. The attackers use the AI for scripting and command execution, targeting government and financial entities in Asia. #APT #CyberEspionage #AI #Threat...
🌐 cyber[.]netsecops[.]io
-
📰 China-Aligned APTs Use Public AI Tools in Espionage Campaigns
China-aligned APTs are now using public AI tools like Claude Code and DeepSeek in espionage campaigns. The attackers use the AI for scripting and command execution, targeting government and financial entities in Asia. #APT #CyberEspionage #AI #Threat...
🌐 cyber[.]netsecops[.]io
-
📰 China-Aligned APTs Use Public AI Tools in Espionage Campaigns
China-aligned APTs are now using public AI tools like Claude Code and DeepSeek in espionage campaigns. The attackers use the AI for scripting and command execution, targeting government and financial entities in Asia. #APT #CyberEspionage #AI #Threat...
🌐 cyber[.]netsecops[.]io
-
Kaspersky details Project CAV3RN, an OilRig-linked cyberespionage framework. Its new module hides C2 in Outlook calendar events, with DNS AAAA fallback.
#ProjectCAV3RN #OilRig #APT34 #Cyberespionage #Kaspersky #MicrosoftGraph #DNS
-
Kaspersky details Project CAV3RN, an OilRig-linked cyberespionage framework. Its new module hides C2 in Outlook calendar events, with DNS AAAA fallback.
#ProjectCAV3RN #OilRig #APT34 #Cyberespionage #Kaspersky #MicrosoftGraph #DNS
-
Dutch Intelligence Warns Russia Uses Hacked IP Cameras for Military Espionage
Dutch Intelligence Warns Russia Uses Hacked IP Cameras for Military Espionage Pierluigi Paganini July 20, 2026 Dutch intelligence…
#EuropeSays #Russia #cyberespionage #Hacking #hackingnews #informationsecuritynews #Intelligence #IPcameras #ITInformationSecurity #PierluigiPaganini #SecurityAffairs #SecurityNews
https://www.europesays.com/russia/41847/ -
HOLLOWGRAPH malware turns Microsoft 365 calendars into covert C2 through Microsoft Graph API abuse. Group-IB links it to the Cavern framework.
#HOLLOWGRAPH #MicrosoftGraph #Microsoft365 #Malware #C2 #DNSTunneling #Cavern #CyberEspionage
-
HOLLOWGRAPH malware turns Microsoft 365 calendars into covert C2 through Microsoft Graph API abuse. Group-IB links it to the Cavern framework.
#HOLLOWGRAPH #MicrosoftGraph #Microsoft365 #Malware #C2 #DNSTunneling #Cavern #CyberEspionage
-
GoSerpentMalware Targets GovermnentNetworks to Steal Classified Data
"A cyber-espionage campaign using the GoSerpentremote access Trojan targeted government and diplomatic organizations across Southeast Asia, silently collecting sensitive documents, dumping credentials, and staging stolen data for weeks before exfiltrating it through compromised network shares using an evolved toolchain.
Pulse ID: 6a5cbd8f107f8c3b9ebaf4d3
Pulse Link: https://otx.alienvault.com/pulse/6a5cbd8f107f8c3b9ebaf4d3
Pulse Author: cryptocti
Created: 2026-07-19 12:05:35Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Asia #CyberSecurity #Espionage #Government #InfoSec #Malware #OTX #OpenThreatExchange #RAT #RemoteAccessTrojan #Trojan #bot #cyberespionage #cryptocti
-
GoSerpentMalware Targets GovermnentNetworks to Steal Classified Data
"A cyber-espionage campaign using the GoSerpentremote access Trojan targeted government and diplomatic organizations across Southeast Asia, silently collecting sensitive documents, dumping credentials, and staging stolen data for weeks before exfiltrating it through compromised network shares using an evolved toolchain.
Pulse ID: 6a5cbd8f107f8c3b9ebaf4d3
Pulse Link: https://otx.alienvault.com/pulse/6a5cbd8f107f8c3b9ebaf4d3
Pulse Author: cryptocti
Created: 2026-07-19 12:05:35Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Asia #CyberSecurity #Espionage #Government #InfoSec #Malware #OTX #OpenThreatExchange #RAT #RemoteAccessTrojan #Trojan #bot #cyberespionage #cryptocti
-
GoSerpentMalware Targets GovermnentNetworks to Steal Classified Data
"A cyber-espionage campaign using the GoSerpentremote access Trojan targeted government and diplomatic organizations across Southeast Asia, silently collecting sensitive documents, dumping credentials, and staging stolen data for weeks before exfiltrating it through compromised network shares using an evolved toolchain.
Pulse ID: 6a5cbd8f107f8c3b9ebaf4d3
Pulse Link: https://otx.alienvault.com/pulse/6a5cbd8f107f8c3b9ebaf4d3
Pulse Author: cryptocti
Created: 2026-07-19 12:05:35Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Asia #CyberSecurity #Espionage #Government #InfoSec #Malware #OTX #OpenThreatExchange #RAT #RemoteAccessTrojan #Trojan #bot #cyberespionage #cryptocti
-
GoSerpentMalware Targets GovermnentNetworks to Steal Classified Data
"A cyber-espionage campaign using the GoSerpentremote access Trojan targeted government and diplomatic organizations across Southeast Asia, silently collecting sensitive documents, dumping credentials, and staging stolen data for weeks before exfiltrating it through compromised network shares using an evolved toolchain.
Pulse ID: 6a5cbd8f107f8c3b9ebaf4d3
Pulse Link: https://otx.alienvault.com/pulse/6a5cbd8f107f8c3b9ebaf4d3
Pulse Author: cryptocti
Created: 2026-07-19 12:05:35Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Asia #CyberSecurity #Espionage #Government #InfoSec #Malware #OTX #OpenThreatExchange #RAT #RemoteAccessTrojan #Trojan #bot #cyberespionage #cryptocti
-
GoSerpentMalware Targets GovermnentNetworks to Steal Classified Data
"A cyber-espionage campaign using the GoSerpentremote access Trojan targeted government and diplomatic organizations across Southeast Asia, silently collecting sensitive documents, dumping credentials, and staging stolen data for weeks before exfiltrating it through compromised network shares using an evolved toolchain.
Pulse ID: 6a5cbd8f107f8c3b9ebaf4d3
Pulse Link: https://otx.alienvault.com/pulse/6a5cbd8f107f8c3b9ebaf4d3
Pulse Author: cryptocti
Created: 2026-07-19 12:05:35Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Asia #CyberSecurity #Espionage #Government #InfoSec #Malware #OTX #OpenThreatExchange #RAT #RemoteAccessTrojan #Trojan #bot #cyberespionage #cryptocti
-
He was an astronomer. Not a spy. Not a cop. Just a curious man who found a 75-cent error and followed it all the way to the KGB. Read The Cuckoo's Egg.
#CuckoosEgg #CliffordStoll #CyberEspionage #books #bookreviews
https://thisgrandpablogs.com/cuckoos-egg-book-review/ -
He was an astronomer. Not a spy. Not a cop. Just a curious man who found a 75-cent error and followed it all the way to the KGB. Read The Cuckoo's Egg.
#CuckoosEgg #CliffordStoll #CyberEspionage #books #bookreviews
https://thisgrandpablogs.com/cuckoos-egg-book-review/ -
He was an astronomer. Not a spy. Not a cop. Just a curious man who found a 75-cent error and followed it all the way to the KGB. Read The Cuckoo's Egg.
#CuckoosEgg #CliffordStoll #CyberEspionage #books #bookreviews
https://thisgrandpablogs.com/cuckoos-egg-book-review/ -
He was an astronomer. Not a spy. Not a cop. Just a curious man who found a 75-cent error and followed it all the way to the KGB. Read The Cuckoo's Egg.
#CuckoosEgg #CliffordStoll #CyberEspionage #books #bookreviews
https://thisgrandpablogs.com/cuckoos-egg-book-review/ -
He was an astronomer. Not a spy. Not a cop. Just a curious man who found a 75-cent error and followed it all the way to the KGB. Read The Cuckoo's Egg.
#CuckoosEgg #CliffordStoll #CyberEspionage #books #bookreviews
https://thisgrandpablogs.com/cuckoos-egg-book-review/ -
Why is Finland accusing Russia of cyber espionage?
Finland has publicly accused Russia of conducting cyber espionage targeting Finnish institutions, critical infrastructure and organizations connected to…
#Finland #FI #Europe #Europa #EU #CyberEspionage #finland #Russia #Suomi #uutiset
https://www.europesays.com/3139222/ -
Why is Finland accusing Russia of cyber espionage?
Finland has publicly accused Russia of conducting cyber espionage targeting Finnish institutions, critical infrastructure and organizations connected to…
#EuropeSays #Russia #CyberEspionage #Finland
https://www.europesays.com/russia/41204/ -
Why is Finland accusing Russia of cyber espionage? https://www.byteseu.com/2207510/ #CyberEspionage #Finland #Russia
-
This is one of the first true accounts of cyber espionage ever written. It holds up after 35 years. Read why.
#books #bookreview #cyberespionage #coldwarspy
https://thisgrandpablogs.com/cuckoos-egg-book-review/ -
This is one of the first true accounts of cyber espionage ever written. It holds up after 35 years. Read why.
#books #bookreview #cyberespionage #coldwarspy
https://thisgrandpablogs.com/cuckoos-egg-book-review/