home.social

#cyberespionage — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #cyberespionage, aggregated by home.social.

fetched live
  1. New Armored Likho tools target Telegram and eavesdropping

    In May 2026, a cyber-espionage campaign by the Armored Likho group (also known as Eagle Werewolf) targeted private individuals and organizations across Russia, including major corporations, public sector entities, IT companies, and educational institutions. The attackers employed fake donation service applications as initial infection vectors. The campaign introduced the Still Toolkit, comprising two Rust-based components: Still Sync, which steals Telegram session data and leverages the Telegram API to extract chat logs and media files, and Still Audio, an implant that conducts covert audio surveillance by detecting speech patterns and recording conversations. The toolkit demonstrates sophisticated capabilities including Dead Drop Resolver techniques, RMS-based voice activity detection, and gRPC-based C2 communications. The campaign shows significant code overlap with previous Armored Likho operations, particularly from February 2026, including identical dropper architecture, encryption algorithms, and inf...

    Pulse ID: 6a7eef664b5b3aa69c6a38b3
    Pulse Link: otx.alienvault.com/pulse/6a7ee
    Pulse Author: AlienVault
    Created: 2026-08-14 10:35:18

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #Education #Encryption #Espionage #InfoSec #OTX #OpenThreatExchange #RAT #RPC #Russia #Rust #Telegram #bot #cyberespionage #AlienVault

  2. New Armored Likho tools target Telegram and eavesdropping

    In May 2026, a cyber-espionage campaign by the Armored Likho group (also known as Eagle Werewolf) targeted private individuals and organizations across Russia, including major corporations, public sector entities, IT companies, and educational institutions. The attackers employed fake donation service applications as initial infection vectors. The campaign introduced the Still Toolkit, comprising two Rust-based components: Still Sync, which steals Telegram session data and leverages the Telegram API to extract chat logs and media files, and Still Audio, an implant that conducts covert audio surveillance by detecting speech patterns and recording conversations. The toolkit demonstrates sophisticated capabilities including Dead Drop Resolver techniques, RMS-based voice activity detection, and gRPC-based C2 communications. The campaign shows significant code overlap with previous Armored Likho operations, particularly from February 2026, including identical dropper architecture, encryption algorithms, and inf...

    Pulse ID: 6a7eef664b5b3aa69c6a38b3
    Pulse Link: otx.alienvault.com/pulse/6a7ee
    Pulse Author: AlienVault
    Created: 2026-08-14 10:35:18

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #Education #Encryption #Espionage #InfoSec #OTX #OpenThreatExchange #RAT #RPC #Russia #Rust #Telegram #bot #cyberespionage #AlienVault

  3. New Armored Likho tools target Telegram and eavesdropping

    In May 2026, a cyber-espionage campaign by the Armored Likho group (also known as Eagle Werewolf) targeted private individuals and organizations across Russia, including major corporations, public sector entities, IT companies, and educational institutions. The attackers employed fake donation service applications as initial infection vectors. The campaign introduced the Still Toolkit, comprising two Rust-based components: Still Sync, which steals Telegram session data and leverages the Telegram API to extract chat logs and media files, and Still Audio, an implant that conducts covert audio surveillance by detecting speech patterns and recording conversations. The toolkit demonstrates sophisticated capabilities including Dead Drop Resolver techniques, RMS-based voice activity detection, and gRPC-based C2 communications. The campaign shows significant code overlap with previous Armored Likho operations, particularly from February 2026, including identical dropper architecture, encryption algorithms, and inf...

    Pulse ID: 6a7eef664b5b3aa69c6a38b3
    Pulse Link: otx.alienvault.com/pulse/6a7ee
    Pulse Author: AlienVault
    Created: 2026-08-14 10:35:18

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #Education #Encryption #Espionage #InfoSec #OTX #OpenThreatExchange #RAT #RPC #Russia #Rust #Telegram #bot #cyberespionage #AlienVault

  4. New Armored Likho tools target Telegram and eavesdropping

    In May 2026, a cyber-espionage campaign by the Armored Likho group (also known as Eagle Werewolf) targeted private individuals and organizations across Russia, including major corporations, public sector entities, IT companies, and educational institutions. The attackers employed fake donation service applications as initial infection vectors. The campaign introduced the Still Toolkit, comprising two Rust-based components: Still Sync, which steals Telegram session data and leverages the Telegram API to extract chat logs and media files, and Still Audio, an implant that conducts covert audio surveillance by detecting speech patterns and recording conversations. The toolkit demonstrates sophisticated capabilities including Dead Drop Resolver techniques, RMS-based voice activity detection, and gRPC-based C2 communications. The campaign shows significant code overlap with previous Armored Likho operations, particularly from February 2026, including identical dropper architecture, encryption algorithms, and inf...

    Pulse ID: 6a7eef664b5b3aa69c6a38b3
    Pulse Link: otx.alienvault.com/pulse/6a7ee
    Pulse Author: AlienVault
    Created: 2026-08-14 10:35:18

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #Education #Encryption #Espionage #InfoSec #OTX #OpenThreatExchange #RAT #RPC #Russia #Rust #Telegram #bot #cyberespionage #AlienVault

  5. New Armored Likho tools target Telegram and eavesdropping

    In May 2026, a cyber-espionage campaign by the Armored Likho group (also known as Eagle Werewolf) targeted private individuals and organizations across Russia, including major corporations, public sector entities, IT companies, and educational institutions. The attackers employed fake donation service applications as initial infection vectors. The campaign introduced the Still Toolkit, comprising two Rust-based components: Still Sync, which steals Telegram session data and leverages the Telegram API to extract chat logs and media files, and Still Audio, an implant that conducts covert audio surveillance by detecting speech patterns and recording conversations. The toolkit demonstrates sophisticated capabilities including Dead Drop Resolver techniques, RMS-based voice activity detection, and gRPC-based C2 communications. The campaign shows significant code overlap with previous Armored Likho operations, particularly from February 2026, including identical dropper architecture, encryption algorithms, and inf...

    Pulse ID: 6a7eef664b5b3aa69c6a38b3
    Pulse Link: otx.alienvault.com/pulse/6a7ee
    Pulse Author: AlienVault
    Created: 2026-08-14 10:35:18

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #Education #Encryption #Espionage #InfoSec #OTX #OpenThreatExchange #RAT #RPC #Russia #Rust #Telegram #bot #cyberespionage #AlienVault

  6. New Armored Likho tools target Telegram and eavesdropping

    In May 2026, a new cyber-espionage campaign by the Armored Likho group targeted private individuals and organizations across Russia, including major corporations, public sector entities, IT companies, and educational institutions. The operation used fake donation service applications as initial infection vectors. The attackers deployed a new toolkit called Still Toolkit, written in Rust, comprising two components: Still Sync steals Telegram session data enabling automated extraction of chat logs, media files and account information through Telegram API; Still Audio performs covert audio surveillance by analyzing incoming audio streams, automatically detecting speech patterns, recording conversations and transmitting them to command-and-control servers. The campaign demonstrates significant evolution in the group's capabilities, utilizing shared infrastructure patterns and encryption techniques consistent with previous operations.

    Pulse ID: 6a7da6ccbbdd8552713c76a1
    Pulse Link: otx.alienvault.com/pulse/6a7da
    Pulse Author: AlienVault
    Created: 2026-08-13 11:13:16

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #Education #Encryption #Espionage #InfoSec #OTX #OpenThreatExchange #RAT #Russia #Rust #Telegram #bot #cyberespionage #AlienVault

  7. New Armored Likho tools target Telegram and eavesdropping

    In May 2026, a new cyber-espionage campaign by the Armored Likho group targeted private individuals and organizations across Russia, including major corporations, public sector entities, IT companies, and educational institutions. The operation used fake donation service applications as initial infection vectors. The attackers deployed a new toolkit called Still Toolkit, written in Rust, comprising two components: Still Sync steals Telegram session data enabling automated extraction of chat logs, media files and account information through Telegram API; Still Audio performs covert audio surveillance by analyzing incoming audio streams, automatically detecting speech patterns, recording conversations and transmitting them to command-and-control servers. The campaign demonstrates significant evolution in the group's capabilities, utilizing shared infrastructure patterns and encryption techniques consistent with previous operations.

    Pulse ID: 6a7da6ccbbdd8552713c76a1
    Pulse Link: otx.alienvault.com/pulse/6a7da
    Pulse Author: AlienVault
    Created: 2026-08-13 11:13:16

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #Education #Encryption #Espionage #InfoSec #OTX #OpenThreatExchange #RAT #Russia #Rust #Telegram #bot #cyberespionage #AlienVault

  8. New Armored Likho tools target Telegram and eavesdropping

    In May 2026, a new cyber-espionage campaign by the Armored Likho group targeted private individuals and organizations across Russia, including major corporations, public sector entities, IT companies, and educational institutions. The operation used fake donation service applications as initial infection vectors. The attackers deployed a new toolkit called Still Toolkit, written in Rust, comprising two components: Still Sync steals Telegram session data enabling automated extraction of chat logs, media files and account information through Telegram API; Still Audio performs covert audio surveillance by analyzing incoming audio streams, automatically detecting speech patterns, recording conversations and transmitting them to command-and-control servers. The campaign demonstrates significant evolution in the group's capabilities, utilizing shared infrastructure patterns and encryption techniques consistent with previous operations.

    Pulse ID: 6a7da6ccbbdd8552713c76a1
    Pulse Link: otx.alienvault.com/pulse/6a7da
    Pulse Author: AlienVault
    Created: 2026-08-13 11:13:16

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #Education #Encryption #Espionage #InfoSec #OTX #OpenThreatExchange #RAT #Russia #Rust #Telegram #bot #cyberespionage #AlienVault

  9. New Armored Likho tools target Telegram and eavesdropping

    In May 2026, a new cyber-espionage campaign by the Armored Likho group targeted private individuals and organizations across Russia, including major corporations, public sector entities, IT companies, and educational institutions. The operation used fake donation service applications as initial infection vectors. The attackers deployed a new toolkit called Still Toolkit, written in Rust, comprising two components: Still Sync steals Telegram session data enabling automated extraction of chat logs, media files and account information through Telegram API; Still Audio performs covert audio surveillance by analyzing incoming audio streams, automatically detecting speech patterns, recording conversations and transmitting them to command-and-control servers. The campaign demonstrates significant evolution in the group's capabilities, utilizing shared infrastructure patterns and encryption techniques consistent with previous operations.

    Pulse ID: 6a7da6ccbbdd8552713c76a1
    Pulse Link: otx.alienvault.com/pulse/6a7da
    Pulse Author: AlienVault
    Created: 2026-08-13 11:13:16

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #Education #Encryption #Espionage #InfoSec #OTX #OpenThreatExchange #RAT #Russia #Rust #Telegram #bot #cyberespionage #AlienVault

  10. New Armored Likho tools target Telegram and eavesdropping

    In May 2026, a new cyber-espionage campaign by the Armored Likho group targeted private individuals and organizations across Russia, including major corporations, public sector entities, IT companies, and educational institutions. The operation used fake donation service applications as initial infection vectors. The attackers deployed a new toolkit called Still Toolkit, written in Rust, comprising two components: Still Sync steals Telegram session data enabling automated extraction of chat logs, media files and account information through Telegram API; Still Audio performs covert audio surveillance by analyzing incoming audio streams, automatically detecting speech patterns, recording conversations and transmitting them to command-and-control servers. The campaign demonstrates significant evolution in the group's capabilities, utilizing shared infrastructure patterns and encryption techniques consistent with previous operations.

    Pulse ID: 6a7da6ccbbdd8552713c76a1
    Pulse Link: otx.alienvault.com/pulse/6a7da
    Pulse Author: AlienVault
    Created: 2026-08-13 11:13:16

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #Education #Encryption #Espionage #InfoSec #OTX #OpenThreatExchange #RAT #Russia #Rust #Telegram #bot #cyberespionage #AlienVault

  11. Armored Likho expands its cyber-espionage toolkit

    Indicators extracted from public reporting. Source: securelist.com/armored-likho-s

    Pulse ID: 6a7d8697e0bd510e87086185
    Pulse Link: otx.alienvault.com/pulse/6a7d8
    Pulse Author: CyberHunter_NL
    Created: 2026-08-13 08:55:51

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #Espionage #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RCE #SecureList #bot #cyberespionage #CyberHunter_NL

  12. Armored Likho expands its cyber-espionage toolkit

    Indicators extracted from public reporting. Source: securelist.com/armored-likho-s

    Pulse ID: 6a7d8697e0bd510e87086185
    Pulse Link: otx.alienvault.com/pulse/6a7d8
    Pulse Author: CyberHunter_NL
    Created: 2026-08-13 08:55:51

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #Espionage #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RCE #SecureList #bot #cyberespionage #CyberHunter_NL

  13. Armored Likho expands its cyber-espionage toolkit

    Indicators extracted from public reporting. Source: securelist.com/armored-likho-s

    Pulse ID: 6a7d8697e0bd510e87086185
    Pulse Link: otx.alienvault.com/pulse/6a7d8
    Pulse Author: CyberHunter_NL
    Created: 2026-08-13 08:55:51

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #Espionage #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RCE #SecureList #bot #cyberespionage #CyberHunter_NL

  14. Armored Likho expands its cyber-espionage toolkit

    Indicators extracted from public reporting. Source: securelist.com/armored-likho-s

    Pulse ID: 6a7d8697e0bd510e87086185
    Pulse Link: otx.alienvault.com/pulse/6a7d8
    Pulse Author: CyberHunter_NL
    Created: 2026-08-13 08:55:51

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #Espionage #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RCE #SecureList #bot #cyberespionage #CyberHunter_NL

  15. Armored Likho expands its cyber-espionage toolkit

    Indicators extracted from public reporting. Source: securelist.com/armored-likho-s

    Pulse ID: 6a7d8697e0bd510e87086185
    Pulse Link: otx.alienvault.com/pulse/6a7d8
    Pulse Author: CyberHunter_NL
    Created: 2026-08-13 08:55:51

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #Espionage #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RCE #SecureList #bot #cyberespionage #CyberHunter_NL

  16. NightLedger Backdoor Deployed in Espionage Campaign Targeting the Middle East and Africa

    An advanced persistent threat group, Mirage Kitten, is conducting cyber-espionage operations across the Middle East and Africa using three previously undocumented malware families: NightLedger, BridgeHead, and ArcBridge. These tools provide reconnaissance, command execution, covert tunneling, and persistent access capabilities. The campaign targets organizations in Egypt, Jordan, Tanzania, Pakistan, Ethiopia, and Burkina Faso across aerospace, aviation, defense, telecommunications, government, financial services, and SMB sectors. Initial access is gained through targeted spear-phishing with recruitment-themed lures and fake videoconferencing pages. The malware demonstrates sophisticated operational security features including victim-specific execution controls, WebSocket-based tunneling, and Cloudflare-backed infrastructure, reflecting the group's investment in bespoke tooling for long-term intelligence collection.

    Pulse ID: 6a71aa488c89bfcbd2814692
    Pulse Link: otx.alienvault.com/pulse/6a71a
    Pulse Author: AlienVault
    Created: 2026-08-04 09:00:56

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Africa #BackDoor #Cloud #CyberSecurity #Edge #Espionage #Government #InfoSec #Malware #MiddleEast #OTX #OpenThreatExchange #Pakistan #Phishing #RAT #SMB #SpearPhishing #Telecom #Telecommunication #bot #cyberespionage #AlienVault

  17. NightLedger Backdoor Deployed in Espionage Campaign Targeting the Middle East and Africa

    An advanced persistent threat group, Mirage Kitten, is conducting cyber-espionage operations across the Middle East and Africa using three previously undocumented malware families: NightLedger, BridgeHead, and ArcBridge. These tools provide reconnaissance, command execution, covert tunneling, and persistent access capabilities. The campaign targets organizations in Egypt, Jordan, Tanzania, Pakistan, Ethiopia, and Burkina Faso across aerospace, aviation, defense, telecommunications, government, financial services, and SMB sectors. Initial access is gained through targeted spear-phishing with recruitment-themed lures and fake videoconferencing pages. The malware demonstrates sophisticated operational security features including victim-specific execution controls, WebSocket-based tunneling, and Cloudflare-backed infrastructure, reflecting the group's investment in bespoke tooling for long-term intelligence collection.

    Pulse ID: 6a71aa488c89bfcbd2814692
    Pulse Link: otx.alienvault.com/pulse/6a71a
    Pulse Author: AlienVault
    Created: 2026-08-04 09:00:56

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Africa #BackDoor #Cloud #CyberSecurity #Edge #Espionage #Government #InfoSec #Malware #MiddleEast #OTX #OpenThreatExchange #Pakistan #Phishing #RAT #SMB #SpearPhishing #Telecom #Telecommunication #bot #cyberespionage #AlienVault

  18. NightLedger Backdoor Deployed in Espionage Campaign Targeting the Middle East and Africa

    An advanced persistent threat group, Mirage Kitten, is conducting cyber-espionage operations across the Middle East and Africa using three previously undocumented malware families: NightLedger, BridgeHead, and ArcBridge. These tools provide reconnaissance, command execution, covert tunneling, and persistent access capabilities. The campaign targets organizations in Egypt, Jordan, Tanzania, Pakistan, Ethiopia, and Burkina Faso across aerospace, aviation, defense, telecommunications, government, financial services, and SMB sectors. Initial access is gained through targeted spear-phishing with recruitment-themed lures and fake videoconferencing pages. The malware demonstrates sophisticated operational security features including victim-specific execution controls, WebSocket-based tunneling, and Cloudflare-backed infrastructure, reflecting the group's investment in bespoke tooling for long-term intelligence collection.

    Pulse ID: 6a71aa488c89bfcbd2814692
    Pulse Link: otx.alienvault.com/pulse/6a71a
    Pulse Author: AlienVault
    Created: 2026-08-04 09:00:56

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Africa #BackDoor #Cloud #CyberSecurity #Edge #Espionage #Government #InfoSec #Malware #MiddleEast #OTX #OpenThreatExchange #Pakistan #Phishing #RAT #SMB #SpearPhishing #Telecom #Telecommunication #bot #cyberespionage #AlienVault

  19. NightLedger Backdoor Deployed in Espionage Campaign Targeting the Middle East and Africa

    An advanced persistent threat group, Mirage Kitten, is conducting cyber-espionage operations across the Middle East and Africa using three previously undocumented malware families: NightLedger, BridgeHead, and ArcBridge. These tools provide reconnaissance, command execution, covert tunneling, and persistent access capabilities. The campaign targets organizations in Egypt, Jordan, Tanzania, Pakistan, Ethiopia, and Burkina Faso across aerospace, aviation, defense, telecommunications, government, financial services, and SMB sectors. Initial access is gained through targeted spear-phishing with recruitment-themed lures and fake videoconferencing pages. The malware demonstrates sophisticated operational security features including victim-specific execution controls, WebSocket-based tunneling, and Cloudflare-backed infrastructure, reflecting the group's investment in bespoke tooling for long-term intelligence collection.

    Pulse ID: 6a71aa488c89bfcbd2814692
    Pulse Link: otx.alienvault.com/pulse/6a71a
    Pulse Author: AlienVault
    Created: 2026-08-04 09:00:56

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Africa #BackDoor #Cloud #CyberSecurity #Edge #Espionage #Government #InfoSec #Malware #MiddleEast #OTX #OpenThreatExchange #Pakistan #Phishing #RAT #SMB #SpearPhishing #Telecom #Telecommunication #bot #cyberespionage #AlienVault

  20. NightLedger Backdoor Deployed in Espionage Campaign Targeting the Middle East and Africa

    An advanced persistent threat group, Mirage Kitten, is conducting cyber-espionage operations across the Middle East and Africa using three previously undocumented malware families: NightLedger, BridgeHead, and ArcBridge. These tools provide reconnaissance, command execution, covert tunneling, and persistent access capabilities. The campaign targets organizations in Egypt, Jordan, Tanzania, Pakistan, Ethiopia, and Burkina Faso across aerospace, aviation, defense, telecommunications, government, financial services, and SMB sectors. Initial access is gained through targeted spear-phishing with recruitment-themed lures and fake videoconferencing pages. The malware demonstrates sophisticated operational security features including victim-specific execution controls, WebSocket-based tunneling, and Cloudflare-backed infrastructure, reflecting the group's investment in bespoke tooling for long-term intelligence collection.

    Pulse ID: 6a71aa488c89bfcbd2814692
    Pulse Link: otx.alienvault.com/pulse/6a71a
    Pulse Author: AlienVault
    Created: 2026-08-04 09:00:56

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Africa #BackDoor #Cloud #CyberSecurity #Edge #Espionage #Government #InfoSec #Malware #MiddleEast #OTX #OpenThreatExchange #Pakistan #Phishing #RAT #SMB #SpearPhishing #Telecom #Telecommunication #bot #cyberespionage #AlienVault

  21. A Leaked Memo Ties Cyberattacks on Minnesota Water Utilities to Iran

    In its report on the Minnesota water cyberattacks, Tenable pointed to an advisory from CISA that was initially…
    #NewsBeep #News #BreakingNews #affiliate-disclaimer-disable #breakingnews #cyberattacksandhacks #cyberespionage #cybersecurity #cyberwar #hacking #Iran #malware #Security #splitscreenimagerightinset #War #web
    newsbeep.com/670846/

  22. 📰 Russian APT28 Hijacks Routers in DNS Poisoning Campaign

    Russian APT group Forest Blizzard (APT28) is behind the 'FrostArmada' campaign, hijacking routers in hotels to steal Microsoft credentials via DNS poisoning. The attack targets users on hospitality Wi-Fi. #APT28 #CyberEspionage #DNS

    🌐 cyber[.]netsecops[.]io

    🔗 cyber.netsecops.io/articles/ru

  23. 📰 China-Aligned APTs Use Public AI Tools in Espionage Campaigns

    China-aligned APTs are now using public AI tools like Claude Code and DeepSeek in espionage campaigns. The attackers use the AI for scripting and command execution, targeting government and financial entities in Asia. #APT #CyberEspionage #AI #Threat...

    🌐 cyber[.]netsecops[.]io

    🔗 cyber.netsecops.io/articles/ch

  24. 📰 China-Aligned APTs Use Public AI Tools in Espionage Campaigns

    China-aligned APTs are now using public AI tools like Claude Code and DeepSeek in espionage campaigns. The attackers use the AI for scripting and command execution, targeting government and financial entities in Asia. #APT #CyberEspionage #AI #Threat...

    🌐 cyber[.]netsecops[.]io

    🔗 cyber.netsecops.io/articles/ch

  25. 📰 China-Aligned APTs Use Public AI Tools in Espionage Campaigns

    China-aligned APTs are now using public AI tools like Claude Code and DeepSeek in espionage campaigns. The attackers use the AI for scripting and command execution, targeting government and financial entities in Asia. #APT #CyberEspionage #AI #Threat...

    🌐 cyber[.]netsecops[.]io

    🔗 cyber.netsecops.io/articles/ch

  26. 📰 China-Aligned APTs Use Public AI Tools in Espionage Campaigns

    China-aligned APTs are now using public AI tools like Claude Code and DeepSeek in espionage campaigns. The attackers use the AI for scripting and command execution, targeting government and financial entities in Asia. #APT #CyberEspionage #AI #Threat...

    🌐 cyber[.]netsecops[.]io

    🔗 cyber.netsecops.io/articles/ch

  27. 📰 China-Aligned APTs Use Public AI Tools in Espionage Campaigns

    China-aligned APTs are now using public AI tools like Claude Code and DeepSeek in espionage campaigns. The attackers use the AI for scripting and command execution, targeting government and financial entities in Asia. #APT #CyberEspionage #AI #Threat...

    🌐 cyber[.]netsecops[.]io

    🔗 cyber.netsecops.io/articles/ch

  28. Global Webmail Espionage

    A persistent cyberespionage campaign tracked as CL-STA-1114, overlapping with Russian threat actor activity known as Void Blizzard and LAUNDRY BEAR, has been targeting Zimbra webmail in government, defense, transportation, and financial organizations. The campaign focuses on NATO member states, Ukraine, Commonwealth of Independent States countries, and Africa. Attackers exploit CVE-2025-66376, a vulnerability in Zimbra Collaboration Suite, using zero-click phishing emails that automatically inject malicious JavaScript payloads without user interaction. The payload exfiltrates sensitive data including login credentials, email archives, CSRF tokens, 2FA scratch codes, and 90 days of email history to command and control servers. Active since 2024, the campaign targeting Zimbra servers began in July 2025, utilizing HTML attachments with obfuscated Base64-encoded scripts that deploy SVG elements to inject the JavaScript into victims' browsers.

    Pulse ID: 6a624073df6738006a6f6e5a
    Pulse Link: otx.alienvault.com/pulse/6a624
    Pulse Author: AlienVault
    Created: 2026-07-23 16:25:23

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #2FA #Africa #Browser #CyberSecurity #Cyberespionage #Email #Espionage #Government #HTML #InfoSec #Java #JavaScript #NATO #OTX #OpenThreatExchange #Phishing #RAT #Russia #SVG #UK #Ukr #Ukraine #Vulnerability #Webmail #Zimbra #bot #AlienVault

  29. Global Webmail Espionage

    A persistent cyberespionage campaign tracked as CL-STA-1114, overlapping with Russian threat actor activity known as Void Blizzard and LAUNDRY BEAR, has been targeting Zimbra webmail in government, defense, transportation, and financial organizations. The campaign focuses on NATO member states, Ukraine, Commonwealth of Independent States countries, and Africa. Attackers exploit CVE-2025-66376, a vulnerability in Zimbra Collaboration Suite, using zero-click phishing emails that automatically inject malicious JavaScript payloads without user interaction. The payload exfiltrates sensitive data including login credentials, email archives, CSRF tokens, 2FA scratch codes, and 90 days of email history to command and control servers. Active since 2024, the campaign targeting Zimbra servers began in July 2025, utilizing HTML attachments with obfuscated Base64-encoded scripts that deploy SVG elements to inject the JavaScript into victims' browsers.

    Pulse ID: 6a624073df6738006a6f6e5a
    Pulse Link: otx.alienvault.com/pulse/6a624
    Pulse Author: AlienVault
    Created: 2026-07-23 16:25:23

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #2FA #Africa #Browser #CyberSecurity #Cyberespionage #Email #Espionage #Government #HTML #InfoSec #Java #JavaScript #NATO #OTX #OpenThreatExchange #Phishing #RAT #Russia #SVG #UK #Ukr #Ukraine #Vulnerability #Webmail #Zimbra #bot #AlienVault

  30. Global Webmail Espionage

    A persistent cyberespionage campaign tracked as CL-STA-1114, overlapping with Russian threat actor activity known as Void Blizzard and LAUNDRY BEAR, has been targeting Zimbra webmail in government, defense, transportation, and financial organizations. The campaign focuses on NATO member states, Ukraine, Commonwealth of Independent States countries, and Africa. Attackers exploit CVE-2025-66376, a vulnerability in Zimbra Collaboration Suite, using zero-click phishing emails that automatically inject malicious JavaScript payloads without user interaction. The payload exfiltrates sensitive data including login credentials, email archives, CSRF tokens, 2FA scratch codes, and 90 days of email history to command and control servers. Active since 2024, the campaign targeting Zimbra servers began in July 2025, utilizing HTML attachments with obfuscated Base64-encoded scripts that deploy SVG elements to inject the JavaScript into victims' browsers.

    Pulse ID: 6a624073df6738006a6f6e5a
    Pulse Link: otx.alienvault.com/pulse/6a624
    Pulse Author: AlienVault
    Created: 2026-07-23 16:25:23

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #2FA #Africa #Browser #CyberSecurity #Cyberespionage #Email #Espionage #Government #HTML #InfoSec #Java #JavaScript #NATO #OTX #OpenThreatExchange #Phishing #RAT #Russia #SVG #UK #Ukr #Ukraine #Vulnerability #Webmail #Zimbra #bot #AlienVault

  31. Global Webmail Espionage

    A persistent cyberespionage campaign tracked as CL-STA-1114, overlapping with Russian threat actor activity known as Void Blizzard and LAUNDRY BEAR, has been targeting Zimbra webmail in government, defense, transportation, and financial organizations. The campaign focuses on NATO member states, Ukraine, Commonwealth of Independent States countries, and Africa. Attackers exploit CVE-2025-66376, a vulnerability in Zimbra Collaboration Suite, using zero-click phishing emails that automatically inject malicious JavaScript payloads without user interaction. The payload exfiltrates sensitive data including login credentials, email archives, CSRF tokens, 2FA scratch codes, and 90 days of email history to command and control servers. Active since 2024, the campaign targeting Zimbra servers began in July 2025, utilizing HTML attachments with obfuscated Base64-encoded scripts that deploy SVG elements to inject the JavaScript into victims' browsers.

    Pulse ID: 6a624073df6738006a6f6e5a
    Pulse Link: otx.alienvault.com/pulse/6a624
    Pulse Author: AlienVault
    Created: 2026-07-23 16:25:23

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #2FA #Africa #Browser #CyberSecurity #Cyberespionage #Email #Espionage #Government #HTML #InfoSec #Java #JavaScript #NATO #OTX #OpenThreatExchange #Phishing #RAT #Russia #SVG #UK #Ukr #Ukraine #Vulnerability #Webmail #Zimbra #bot #AlienVault