home.social

#cyberespionage — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #cyberespionage, aggregated by home.social.

fetched live
  1. 📰 China-Aligned APTs Use Public AI Tools in Espionage Campaigns

    China-aligned APTs are now using public AI tools like Claude Code and DeepSeek in espionage campaigns. The attackers use the AI for scripting and command execution, targeting government and financial entities in Asia. #APT #CyberEspionage #AI #Threat...

    🌐 cyber[.]netsecops[.]io

    🔗 cyber.netsecops.io/articles/ch

  2. Global Webmail Espionage

    A persistent cyberespionage campaign tracked as CL-STA-1114, overlapping with Russian threat actor activity known as Void Blizzard and LAUNDRY BEAR, has been targeting Zimbra webmail in government, defense, transportation, and financial organizations. The campaign focuses on NATO member states, Ukraine, Commonwealth of Independent States countries, and Africa. Attackers exploit CVE-2025-66376, a vulnerability in Zimbra Collaboration Suite, using zero-click phishing emails that automatically inject malicious JavaScript payloads without user interaction. The payload exfiltrates sensitive data including login credentials, email archives, CSRF tokens, 2FA scratch codes, and 90 days of email history to command and control servers. Active since 2024, the campaign targeting Zimbra servers began in July 2025, utilizing HTML attachments with obfuscated Base64-encoded scripts that deploy SVG elements to inject the JavaScript into victims' browsers.

    Pulse ID: 6a624073df6738006a6f6e5a
    Pulse Link: otx.alienvault.com/pulse/6a624
    Pulse Author: AlienVault
    Created: 2026-07-23 16:25:23

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #2FA #Africa #Browser #CyberSecurity #Cyberespionage #Email #Espionage #Government #HTML #InfoSec #Java #JavaScript #NATO #OTX #OpenThreatExchange #Phishing #RAT #Russia #SVG #UK #Ukr #Ukraine #Vulnerability #Webmail #Zimbra #bot #AlienVault

  3. 🚨 SIGINT // Cybersecurity Watch — 2026-07-24
    US agencies warn Iran-affiliated hackers are targeting Siemens, Schneider Electric & Rockwell ICS devices in critical infrastructure attacks.
    securityweek.com/us-warns-of-i

  4. New Project CAV3RN .NET Native AOT communication module

    Kaspersky identified a new .NET Native AOT communication module for Project CAV3RN, a sophisticated cyberespionage framework targeting Israel. This module replaces the previous HTTP/WebSocket component by exchanging commands through Outlook calendar events accessed via Microsoft Graph API. Commands and results are stored in a fixed time window (2050-05-13 22:00-23:00 UTC) using specific subject patterns to identify heartbeats, commands, and outputs. The module implements RSA and AES-GCM encryption for secure communications. If Microsoft Graph authentication fails, it retrieves replacement configuration settings through DNS AAAA record responses from actor-controlled nameservers. The infrastructure analysis and behavioral patterns suggest low-confidence attribution to OilRig (APT34), based on the use of Microsoft-hosted services for command and control and compromised regional infrastructure.

    Pulse ID: 6a5f55d6d75eaa9d17122eea
    Pulse Link: otx.alienvault.com/pulse/6a5f5
    Pulse Author: AlienVault
    Created: 2026-07-21 11:19:50

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #APT34 #CyberSecurity #Cyberespionage #DNS #Encryption #Espionage #HTTP #InfoSec #Israel #Kaspersky #Microsoft #NET #OTX #OilRig #OpenThreatExchange #Outlook #RAT #Troll #bot #AlienVault

  5. 📰 China-Aligned APTs Use Public AI Tools in Espionage Campaigns

    China-aligned APTs are now using public AI tools like Claude Code and DeepSeek in espionage campaigns. The attackers use the AI for scripting and command execution, targeting government and financial entities in Asia. #APT #CyberEspionage #AI #Threat...

    🌐 cyber[.]netsecops[.]io

    🔗 cyber.netsecops.io/articles/ch

  6. GoSerpentMalware Targets GovermnentNetworks to Steal Classified Data

    "A cyber-espionage campaign using the GoSerpentremote access Trojan targeted government and diplomatic organizations across Southeast Asia, silently collecting sensitive documents, dumping credentials, and staging stolen data for weeks before exfiltrating it through compromised network shares using an evolved toolchain.

    Pulse ID: 6a5cbd8f107f8c3b9ebaf4d3
    Pulse Link: otx.alienvault.com/pulse/6a5cb
    Pulse Author: cryptocti
    Created: 2026-07-19 12:05:35

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Asia #CyberSecurity #Espionage #Government #InfoSec #Malware #OTX #OpenThreatExchange #RAT #RemoteAccessTrojan #Trojan #bot #cyberespionage #cryptocti

  7. He was an astronomer. Not a spy. Not a cop. Just a curious man who found a 75-cent error and followed it all the way to the KGB. Read The Cuckoo's Egg.
    #CuckoosEgg #CliffordStoll #CyberEspionage #books #bookreviews
    thisgrandpablogs.com/cuckoos-e

  8. CRITICAL threat: Russian FSB-linked cyber espionage & sabotage campaign hits gov & infrastructure across Europe since 2010. No CVE, but big impact on power, heating, transport. Follow national guidance; boost vigilance. radar.offseq.com/threat/eu-tar #OffSeq #CyberEspionage #FSB #EU

  9. One Target, Two Flags | Rival Espionage Actors Converge On Pakistani Law Enforcement

    Between February 2024 and April 2026, multiple cyberespionage actors, suspected to be China-nexus and India-nexus threat groups, conducted sustained intrusions into Pakistani law enforcement organizations, particularly Balochistan Police. The compromised infrastructure included network appliances and servers hosting web applications managing criminal records, biometric data, hotel registrations, and citizen complaints. A suspected China-nexus actor weaponized the Complaint Management System web application by deploying custom implants disguised as portal updates, targeting both police personnel and citizens. China's likely motivation stems from concerns over the safety of Chinese nationals in Pakistan, particularly regarding attacks by separatist groups. India's suspected interest relates to its adversarial relationship with Pakistan, with Balochistan Police offering intelligence on security operations in a strategically sensitive province. The attackers deployed PlugX, ShadowPad, Cobalt Strike, Remcos, an...

    Pulse ID: 6a501da43fb3cb230cc9a9b9
    Pulse Link: otx.alienvault.com/pulse/6a501
    Pulse Author: AlienVault
    Created: 2026-07-09 22:16:04

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Biometric #China #Chinese #CobaltStrike #CyberSecurity #Cyberespionage #Espionage #India #InfoSec #LawEnforcement #OTX #OpenThreatExchange #Pakistan #PlugX #RAT #RCE #Remcos #ShadowPad #bot #AlienVault

  10. 🚨 A newly identified APT dubbed #ArmoredLikho is targeting government agencies and energy organizations with #BusySnake Stealer, a Python-based infostealer delivered through AI-generated loaders and spear-phishing campaigns.

    The malware steals credentials, Telegram sessions, cryptocurrency wallets, and more, while built-in reverse SSH tunneling gives attackers long-term remote access.

    Listen/Read: hackread.com/armored-likho-gov

    #CyberSecurity #InfoSec #APT #Malware #Phishing #CyberEspionage

  11. 2/3
    GTG-1002: Anthropic's own disclosed report on a Chinese state-sponsored group that jailbroke Claude Code by claiming to be a legitimate security firm, then ran ~80-90% of a 30-target espionage campaign autonomously. Five months before contested (unconfirmed) covert China-proxy detection code turned up in Claude Code. The timing isn't abstract.

    #CyberEspionage #Claude #Sovereignty

  12. APT group targeting governmental agencies in East Asia

    A Chinese-speaking cyber-espionage group known as LuckyMouse is behind a new campaign targeting government institutions in East Asia, according to research by Avast and the Kaspersky Labs security team.

    Pulse ID: 6a449938480820de2d1f55b6
    Pulse Link: otx.alienvault.com/pulse/6a449
    Pulse Author: Tr1sa111
    Created: 2026-07-01 04:36:08

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Asia #Chinese #CyberSecurity #Espionage #Government #InfoSec #Kaspersky #OTX #OpenThreatExchange #bot #cyberespionage #Tr1sa111

  13. MuddyWater Exploits Ransomware Disguise for Cyber Espionage

    The line between ransomware attacks and nation-state espionage is rapidly blurring, as cyber groups like MuddyWater now disguise their operations as financially motivated ransomware attacks to further their strategic objectives. MuddyWater, linked to Iran's Ministry of Intelligence and Security, has been caught posing as the Chaos ransomware group in…

    osintsights.com/muddywater-exp

    #Muddywater #CyberEspionage #NationState #Ransomware #Iran

  14. During June 1-15 2026 I collected 80 incidents: #cybercrime 68.8%, #malware 40%, #cyberespionage 25%. #Supplychain worms hit npm/PyPI/GitHub. ShinyHunters, Qilin & Volt Typhoon most active.#Infographic below, full data 👉 hackmageddon.com/2026/06/23/1-

    #CyberSecurity #ThreatIntel

  15. Cyber Recon: My Life in Cyber Espionage and Ransomware Negotiation by Kurtis Minder, 2025

    An up close and personal look at cyber espionage and digital spycraft In Cyber Recon: My Life in Cyber Espionage and Ransomware Negotiation, 30-year cybersecurity veteran Kurtis Minder delivers a fascinating exploration of real-world cyber espionage in some of the most dangerous places on the Internet.

    #books
    #nonfiction
    #CyberCrime
    #CyberEspionage
    #Ransomware

  16. 🚀🤦‍♂️ Someone discovered Slack video embeds and thinks they've cracked the cyber espionage code by slipping messages through them. What’s next, Morse code over Excel spreadsheets? 📊💻
    v1c.rocks/log/exploiting-slack #SlackVideoEmbeds #CyberEspionage #CodeCracking #DigitalCommunication #CreativeHacking #HackerNews #ngated

  17. 📰 Iranian APT 'Screening Serpens' Intensifies Espionage with New RATs Targeting US, Israel, and UAE

    🇮🇷 Iranian APT 'Screening Serpens' escalates cyber-espionage against US, Israel & UAE. New RATs 'MiniUpdate' & 'MiniJunk V2' deployed. Group using advanced AppDomainManager hijacking for persistence. #APT #CyberEspionage #Iran #ThreatIntel

    🌐 cyber[.]netsecops[.]io

    🔗 cyber.netsecops.io/articles/ir

  18. 📰 Iranian APT 'Screening Serpens' Intensifies Espionage with New RATs Targeting US, Israel, and UAE

    🇮🇷 Iranian APT 'Screening Serpens' escalates cyber-espionage against US, Israel & UAE. New RATs 'MiniUpdate' & 'MiniJunk V2' deployed. Group using advanced AppDomainManager hijacking for persistence. #APT #CyberEspionage #Iran #ThreatIntel

    🌐 cyber[.]netsecops[.]io

    🔗 cyber.netsecops.io/articles/ir

  19. Xu Zewei was arrested at Milan Malpensa on July 3, 2025 and extradited from Italy to the United States on April 26, 2026. U.S. prosecutors accuse him of participating in cyber operations targeting universities, COVID-related research, and sensitive networks allegedly linked to Chinese state interests.

    But beyond the legal case, another question may be more interesting.

    This investigation began in a climate defined by strategic competition between Washington and Beijing. Today, however, U.S.-China relations appear to be entering a more complex phase, with renewed signals of dialogue and economic cooperation.

    Will Xu remain a symbol of cyber conflict, or will his case gradually fade into the background as larger geopolitical priorities take over?

    And one more question that deserves attention: is it really plausible that a Chinese citizen allegedly wanted by the United States since 2023 simply decided to spend a vacation in Italy? Or was there another reason behind that trip?

    The unsealed U.S. court document in the Xu Zewei case can be read here:
    ismg-cdn.nyc3.cdn.digitalocean

    Perhaps Xu Zewei’s legal fate will be decided in a courtroom. The meaning of his story, however, may ultimately be decided somewhere else.

    #CyberSecurity #China #Intelligence #CyberEspionage #Geopolitics

  20. A 75-cent billing error. A hacker selling US secrets to the KGB. One astronomer who refused to look away. The Cuckoo's Egg is a true spy story like no other.
    #CuckoosEgg #CliffordStoll #CyberEspionage #books #bookreviews
    thisgrandpablogs.com/cuckoos-e