#cyberespionage — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #cyberespionage, aggregated by home.social.
-
Chinese hackers launch Chrome zero-day exploit chain attacks against NGOs. Learn how this Chrome zero-day exploit chain exploits patch gaps.
#ChromeZeroDay #JungleBamboo #UTA0560 #CyberEspionage #InfoSec #Malware
-
The ted backdoor is DPRK Linux malware hidden inside HAProxy. It pairs with curlRAT to spy on South Korean media and automotive firms, Rapid7 reports.
#TedBackdoor #curlRAT #DPRK #APT37 #LinuxMalware #HAProxy #SouthKorea #Cyberespionage #Rapid7 #InfoSec
http://securityonline.info/ted-backdoor-curlrat-dprk/?utm_source=mastodon&utm_medium=jetpack_social
-
Threat analysts reveal Kimsuky uses AI agent opencode to mass-produce phishing decoys. Discover how the group leverages AI to enhance its LNK attacks.
#Kimsuky #Opencode #AIAgent #CyberEspionage #Cybersecurity
https://securityonline.info/kimsuky-ai-agent-opencode/?utm_source=mastodon&utm_medium=jetpack_social
-
Threat analysts reveal Kimsuky uses AI agent opencode to mass-produce phishing decoys. Discover how the group leverages AI to enhance its LNK attacks.
#Kimsuky #Opencode #AIAgent #CyberEspionage #Cybersecurity
https://securityonline.info/kimsuky-ai-agent-opencode/?utm_source=mastodon&utm_medium=jetpack_social
-
Threat analysts reveal Kimsuky uses AI agent opencode to mass-produce phishing decoys. Discover how the group leverages AI to enhance its LNK attacks.
#Kimsuky #Opencode #AIAgent #CyberEspionage #Cybersecurity
https://securityonline.info/kimsuky-ai-agent-opencode/?utm_source=mastodon&utm_medium=jetpack_social
-
Threat analysts reveal Kimsuky uses AI agent opencode to mass-produce phishing decoys. Discover how the group leverages AI to enhance its LNK attacks.
#Kimsuky #Opencode #AIAgent #CyberEspionage #Cybersecurity
https://securityonline.info/kimsuky-ai-agent-opencode/?utm_source=mastodon&utm_medium=jetpack_social
-
Espionage groups use the BlueMoon exploit kit in new attacks. Discover how BlueMoon exploit kit campaigns exploit Chrome zero-days.
#BlueMoon #ExploitKit #Chrome #ZeroDay #CyberEspionage #InfoSec
-
Espionage groups use the BlueMoon exploit kit in new attacks. Discover how BlueMoon exploit kit campaigns exploit Chrome zero-days.
#BlueMoon #ExploitKit #Chrome #ZeroDay #CyberEspionage #InfoSec
-
Espionage groups use the BlueMoon exploit kit in new attacks. Discover how BlueMoon exploit kit campaigns exploit Chrome zero-days.
#BlueMoon #ExploitKit #Chrome #ZeroDay #CyberEspionage #InfoSec
-
Espionage groups use the BlueMoon exploit kit in new attacks. Discover how BlueMoon exploit kit campaigns exploit Chrome zero-days.
#BlueMoon #ExploitKit #Chrome #ZeroDay #CyberEspionage #InfoSec
-
The US Department of Justice seized domains linked to the Chinese QTFY hacker group, disrupting attacks against NASA and other critical infrastructure.
-
Fire Ant, a China-linked espionage group previously seen targeting #VMware, is now also attacking Cisco routers and authentication servers. Researchers say it collected credentials and traffic while manipulating logs to conceal its presence.
Listen/Read: https://hackread.com/china-fire-ant-hackers-cisco-routers-tacacs-espionage/
#CyberSecurity #CyberEspionage #Cisco #FireAnt #China #CyberCrime
-
Researchers detected the Dark Caracal GoCaracal malware in South America. Learn how this GoCaracal malware uses Ethereum smart contracts.
#DarkCaracal #GoCaracal #Malware #CyberEspionage #ThreatIntel
-
A Cambodia malware campaign hides SparkRAT in PNG files and abuses a vulnerable driver to kill antivirus, Acronis TRU reports.
#SparkRAT #BYOVD #Cambodia #Malware #CyberEspionage #SilverFox
-
The DOJ QTFY correction reframes NASA, the Fed and the Senate as targets, not victims, of the Chinese hacking group, narrowing confirmed breaches.
#QTFY #DOJ #ChinaHackers #CyberEspionage #NASA
https://meterpreter.org/doj-qtfy-correction/?utm_source=mastodon&utm_medium=jetpack_social
-
US Disrupts Chinese Cyber Espionage Proxy Network
The FBI has struck a major blow against Chinese cyber espionage, disrupting a proxy network used to sell reconnaissance and operational routing capabilities to malicious actors. This key takedown targeted a technical quartermaster tied to Nanjing Xinjiuwei Network Technology Company, a company linked to the notorious QTYF…
#ChineseCyberEspionage #CyberEspionage #Fbi #Qtyf #NanjingXinjiuweiNetworkTechnologyCompany
-
🚨 SIGINT // Cybersecurity Watch — 2026-08-29
US disrupts Chinese hacking platform used in attacks on military and critical infrastructure networks.
https://www.securityweek.com/us-disrupts-chinese-hacking-platform-used-in-military-and-critical-infrastructure-attacks/
#CyberEspionage #InfoSec #CriticalInfrastructure #China -
The DOJ and FBI seized QScan and QTRouter, platforms run by China state-sponsored hackers to hide attacks on U.S. critical infrastructure.
#QScan #QTRouter #QTFY #ChinaHackers #CyberEspionage #CriticalInfrastructure
-
SilkParasite APT ran China-nexus cyberespionage across Central Asia, using 7 custom RATs, DLL sideloading, and AI-assisted malware.
#SilkParasite #APT #CyberEspionage #Malware #ThreatIntel #InfoSec #Cybersecurity #ChinaNexus
-
Expands Toolset With New Backdoor, SSH Tunnel
An Iranian-linked cyber-espionage group known as Tortoiseshell has enhanced its malware arsenal with newly identified tools, including a reverse SSH tunneling utility and a C++ backdoor. The SSH tunnel, disguised as wtsapi32.dll, leverages Windows OpenSSH client to establish connections with command-and-control infrastructure. The backdoor, showing similarities to TWOSTROKE malware, supports file execution, shell commands, in-memory DLL execution, and file manipulation capabilities. Infrastructure analysis revealed domains with subdomains referencing UAE, Saudi Arabia, UK, Belgium, Canada, Australia, and Japan, suggesting expanded targeting beyond the group's traditional focus on defense, aerospace, IT service providers, and military organizations in the Middle East and United States. Active since 2018, the group continues operations with persistent infrastructure despite domain suspensions.
Pulse ID: 6a8f1fe0b63c473eb499fd00
Pulse Link: https://otx.alienvault.com/pulse/6a8f1fe0b63c473eb499fd00
Pulse Author: AlienVault
Created: 2026-08-26 17:18:24Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Australia #BackDoor #Canada #CyberSecurity #Espionage #InfoSec #Iran #Japan #Malware #MiddleEast #Military #OTX #OpenThreatExchange #RAT #SSH #SaudiArabia #TortoiseShell #UAE #UK #UnitedStates #Windows #bot #cyberespionage #AlienVault
-
FBI Disrupts Chinese Espionage Proxy Network
Kudos to the FBI and DOJ for taking down a Chinese cyber espionage proxy network that's been targeting US critical infrastructure - a huge win for national security. This disruption, made possible by Lumen Technologies' Black Lotus Labs' year-long tracking, has crippled the infrastructure used by Chinese hackers to spy on and gather…
#ChineseEspionage #CyberEspionage #NationState #EmergingThreats #UsCriticalInfrastructure
-
CoreRAT malware powers Core Werewolf attacks on Russian defense and government targets, using fake military PDFs and Telegram phishing.
-
Cybersecurity researchers warn that suspected Russian espionage groups are abusing legitimate WhatsApp, Google, and Microsoft authentication to target diplomats, academics, and defense personnel— even recording victims through fake calls. 🔐🎯 #Cybersecurity #WhatsApp #CyberEspionage https://cyberinsider.com/russian-hackers-abuse-whatsapp-device-linking-to-spy-on-high-value-targets/
-
T-Mobile security staff physically severed a network cable in 2024 to block Chinese state-linked Salt Typhoon hackers from reaching the carrier's infrastructure.
#SaltTyphoon #TMobile #ChinaHack #Telecommunications #CyberEspionage
-
Russian hackers hijack EU accounts via Google OAuth. Lock down auth flows!
-
SilkParasite: Tracking a China-Nexus APT Across Central Asia
SilkParasite is a cyberespionage operation assessed with medium confidence as China-nexus that targeted government bodies across Central Asia. Seven remote access tool families were deployed, five of which were previously undocumented: DriveSilkRAT, CookiETagRAT, NomadRAT, GoginRAT, and NodeEdgeRAT. The toolset is small, modular, and professionally engineered with traces of AI-assisted development. Initial access occurred through malicious Microsoft Office documents delivered via spear-phishing, using regionally tailored lures impersonating government ministries. The operation leveraged DLL sideloading as the primary delivery mechanism and used Google Drive for command-and-control communications to hide within trusted services. Infrastructure analysis identified connections to China Unicom's backbone network, and operational patterns suggest a functioning software organization with maintained build pipelines and careful operational security.
Pulse ID: 6a86a70eb8b57f155e62d4f7
Pulse Link: https://otx.alienvault.com/pulse/6a86a70eb8b57f155e62d4f7
Pulse Author: AlienVault
Created: 2026-08-20 07:04:46Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Asia #CentralAsia #China #CyberSecurity #Cyberespionage #DRat #Edge #Espionage #Google #Government #InfoSec #Microsoft #MicrosoftOffice #OTX #Office #OpenThreatExchange #Phishing #RAT #Rust #SideLoading #SpearPhishing #bot #AlienVault
-
Smile, You’re on Camera! Part 2: Lazarus IT Workers Exposed
Part 2: Hiring North Korean IT workers in a fake DeFi startup shows how the country’s infamous “Famous Chollima” cyber-espionage operation works.
Pulse ID: 6a8693c10ec0d620c77b5808
Pulse Link: https://otx.alienvault.com/pulse/6a8693c10ec0d620c77b5808
Pulse Author: Tr1sa111
Created: 2026-08-20 05:42:25Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #Espionage #InfoSec #Korea #Lazarus #NorthKorea #OTX #OpenThreatExchange #RAT #bot #cyberespionage #Tr1sa111
-
Jewelbug Chinese APT Linked to Hack-for-Hire Operations - https://www.redpacketsecurity.com/researchers-link-jewelbug-chinese-apt-to-hack-for-hire-operations/
-
Cavern C2 Uses DNS and Google Apps Script to Blend Into Legitimate Traffic
Indicators extracted from public reporting. Source: https://securelist.com/project-cav3rn-cyberespionage-framework-using-outlook-and-dns/120757/
Pulse ID: 6a8367506b41736758a8d45b
Pulse Link: https://otx.alienvault.com/pulse/6a8367506b41736758a8d45b
Pulse Author: CyberHunter_NL
Created: 2026-08-17 19:56:00Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #Cyberespionage #DNS #Espionage #Google #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #Outlook #RCE #SecureList #bot #CyberHunter_NL
-
Russia is targeting Ukraine using internet-connected cameras across Europe. The camera hacks facilitate the targeting of Ukrainian soldiers and materiel.
https://www.databreachtoday.com/russia-targeting-ukraine-using-internet-connected-cameras-a-32566 #cyberespionage -
New Armored Likho tools target Telegram and eavesdropping
In May 2026, a cyber-espionage campaign by the Armored Likho group (also known as Eagle Werewolf) targeted private individuals and organizations across Russia, including major corporations, public sector entities, IT companies, and educational institutions. The attackers employed fake donation service applications as initial infection vectors. The campaign introduced the Still Toolkit, comprising two Rust-based components: Still Sync, which steals Telegram session data and leverages the Telegram API to extract chat logs and media files, and Still Audio, an implant that conducts covert audio surveillance by detecting speech patterns and recording conversations. The toolkit demonstrates sophisticated capabilities including Dead Drop Resolver techniques, RMS-based voice activity detection, and gRPC-based C2 communications. The campaign shows significant code overlap with previous Armored Likho operations, particularly from February 2026, including identical dropper architecture, encryption algorithms, and inf...
Pulse ID: 6a7eef664b5b3aa69c6a38b3
Pulse Link: https://otx.alienvault.com/pulse/6a7eef664b5b3aa69c6a38b3
Pulse Author: AlienVault
Created: 2026-08-14 10:35:18Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #Education #Encryption #Espionage #InfoSec #OTX #OpenThreatExchange #RAT #RPC #Russia #Rust #Telegram #bot #cyberespionage #AlienVault
-
New Armored Likho tools target Telegram and eavesdropping
In May 2026, a new cyber-espionage campaign by the Armored Likho group targeted private individuals and organizations across Russia, including major corporations, public sector entities, IT companies, and educational institutions. The operation used fake donation service applications as initial infection vectors. The attackers deployed a new toolkit called Still Toolkit, written in Rust, comprising two components: Still Sync steals Telegram session data enabling automated extraction of chat logs, media files and account information through Telegram API; Still Audio performs covert audio surveillance by analyzing incoming audio streams, automatically detecting speech patterns, recording conversations and transmitting them to command-and-control servers. The campaign demonstrates significant evolution in the group's capabilities, utilizing shared infrastructure patterns and encryption techniques consistent with previous operations.
Pulse ID: 6a7da6ccbbdd8552713c76a1
Pulse Link: https://otx.alienvault.com/pulse/6a7da6ccbbdd8552713c76a1
Pulse Author: AlienVault
Created: 2026-08-13 11:13:16Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #Education #Encryption #Espionage #InfoSec #OTX #OpenThreatExchange #RAT #Russia #Rust #Telegram #bot #cyberespionage #AlienVault
-
Armored Likho expands its cyber-espionage toolkit
Indicators extracted from public reporting. Source: https://securelist.com/armored-likho-still-toolkit/121033/
Pulse ID: 6a7d8697e0bd510e87086185
Pulse Link: https://otx.alienvault.com/pulse/6a7d8697e0bd510e87086185
Pulse Author: CyberHunter_NL
Created: 2026-08-13 08:55:51Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #Espionage #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RCE #SecureList #bot #cyberespionage #CyberHunter_NL
-
A massive Chinese hacking campaign was exposed after attackers left their server directories open, revealing SNOWLIGHT malware and thousands of global targets.
#Cybersecurity #Malware #SNOWLIGHT #CyberEspionage #TechNews
https://meterpreter.org/snowlight-malware-exposed/?utm_source=mastodon&utm_medium=jetpack_social
-
Mirage Kitten malware, tied to the UNC1549 APT, hit aviation and telecom targets across the Middle East and Africa with new backdoors and tunnelers.
#MirageKitten #UNC1549 #APT #CyberEspionage #NightLedger #Iran #ThreatIntel #InfoSec #CyberSecurity
http://securityonline.info/mirage-kitten-malware/?utm_source=mastodon&utm_medium=jetpack_social
-
Humanoid robot found vulnerable to Bluetooth hack, data leaks to China https://www.helpnetsecurity.com/2025/10/16/unitree-g1-humanoid-robot-vulnerability/ #industrialrobots #cyberespionage #cybersecurity #vulnerability #Don'tmiss #hardware #research #privacy #News
-
OilRig Hackers Attacking Individuals And Organizations In The Middle East https://gbhackers.com/oilrig-hackers-middle-east-attacks/ #AdvancedPersistentThreat(APT) #MiddleEastCyberAttacks #CyberSecurityNews #CyberEspionage #spearPhishing #oilRighackers #CyberAttack #Malware
-
Microsoft reported that APT28 (Fancy Bear, Forest Blizzard) used a custom tool to elevate privileges and steal credentials in compromised networks. This GooseEgg tool leveraged CVE-2022-38028 (7.8 high, disclosed 11 October 2022 by Microsoft; Windows Print Spooler Elevation of Privilege Vulnerability) as a zero-day since at least June 2020 (possibly as early as April 2019) which was 2 years 4 months. APT28 is publicly attributed to Russian General Staff Main Intelligence Directorate (GRU). IOC provided. 🔗 https://www.microsoft.com/en-us/security/blog/2024/04/22/analyzing-forest-blizzards-custom-post-compromise-tool-for-exploiting-cve-2022-38028-to-obtain-credentials/
cc: @serghei @campuscodi @briankrebs @jwarminsky
#APT28 #cyberespionage #Russia #FancyBear #ForestBlizzard #CVE_2022_38028 #eitw #activeexploitation #GooseEgg
-
I buried the lede in not mentioning that UNC5291 is assessed with medium confidence to be associated with Volt Typhoon, a Chinese state-sponsored Advanced Persistent Threat (APT). See related The Record reporting: Volt Typhoon and 4 other groups targeting US energy and defense sectors through Ivanti bugs
#Ivanti #ConnectSecure #vulnerability #cyberespionage #China #activeexploitation #eitw #zeroday #KEV #CISA #CVE_2023_46805 #CVE_2024_21887 #CVE_2024_21893 #UNC5221 #UNC5266 #UNC5330 #UNC5337 #UNC5291
-
Mandiant releases part 4 of the Ivanti Connect Secure incident response investigation. They detail different types of post-exploitation activity across their IR engagements. Chinese threat actors have a growing knowledge of Ivanti Connect Secure in abusing appliance-specific functionality to perform actions on objective. They highlight FIVE Chinese threat actors: UNC5221, UNC5266, UNC5330, UNC5337, and UNC5291 abusing a mix of CVE-2023-46805, CVE-2024-21887, and CVE-2024-21893. New TTPs, new malware families and new IOC: 🔗 https://cloud.google.com/blog/topics/threat-intelligence/ivanti-post-exploitation-lateral-movement
EDIT: For your situational awareness, it's my understanding that future Mandiant articles will be located at https://cloud.google.com/blog/topics/threat-intelligence/
#Ivanti #ConnectSecure #vulnerability #cyberespionage #China #activeexploitation #eitw #zeroday #KEV #CISA #CVE_2023_46805 #CVE_2024_21887 #CVE_2024_21893 #UNC5221 #UNC5266 #UNC5330 #UNC5337 #UNC5291
-
New Zealand shares their own Chinese #cyberespionage problems: “The GCSB’s National Cyber Security Centre (NCSC) completed a robust technical assessment following a compromise of the Parliamentary Counsel Office and the Parliamentary Service in 2021, and has attributed this activity to a PRC state-sponsored group known as APT40" 🔗 https://www.beehive.govt.nz/release/parliamentary-network-breached-prc
APT40—aka BRONZE MOHAWK, FEVERDREAM, G0065, Gadolinium, GreenCrash, Hellsing, Kryptonite Panda, Leviathan, MUDCARP, Periscope, Temp.Periscope, and Temp.Jumper is a Chinese Advanced Persistent Threat (APT) group associated with China’s MSS Hainan State Security Department. On July 19, 2021, the U.S. Department of Justice (DOJ) unsealed an indictment against four APT40 cyber actors for their illicit computer network exploitation (CNE) activities via front company Hainan Xiandun Technology Development Company (Hainan Xiandun).
-
Continuing with the dogpile on APT31: Finland's National Bureau of Investigation published a press release into the ongoing criminal investigation into APT31's connection with the hacking of their Parliament between autumn 2020 and early 2021."These connections have now been confirmed by the investigation, and the police have also identified one suspect." 🔗 https://poliisi.fi/en/-/investigation-into-hacking-of-parliament-s-information-systems-has-been-ongoing
-
BBC:China hits out at US and UK over cyber hack claims 🔗 https://www.bbc.com/news/world-asia-china-68655786 China's Foreign Ministry spokesperson Lin Jian:
"We urge the US and UK to stop politicising cyber security issues. Stop smearing China and stop imposing unilateral sanctions on China. Stop their cyber attack against China. The Chinese side has already made technical clarifications and response to the APT 31-related Information submitted by the UK side, which made clear that the evidence provided by the UK was inadequate. Unfortunately, we haven't heard from the UK side."
-
U.S. State Department Rewards for Justice (RFJ) program is offering a reward of up to $10 million for information leading to the identification or location of APT31, a collection of Chinese state-sponsored intelligence officers, contract hackers, and support staff that conduct malicious cyber operations on behalf of the Hubei State Security Department (HSSD), a provincial branch of the Ministry of State Security. 🔗 https://rewardsforjustice.net/rewards/apt31-wuhan-xiaoruizhi-science-technology-company-ltd/
#China #cyberespionage #StateDept #RewardsforJustice #APT31 #threatintel