home.social

#cyberespionage — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #cyberespionage, aggregated by home.social.

  1. Fire Ant, a China-linked espionage group previously seen targeting #VMware, is now also attacking Cisco routers and authentication servers. Researchers say it collected credentials and traffic while manipulating logs to conceal its presence.

    Listen/Read: hackread.com/china-fire-ant-ha

    #CyberSecurity #CyberEspionage #Cisco #FireAnt #China #CyberCrime

  2. The DOJ QTFY correction reframes NASA, the Fed and the Senate as targets, not victims, of the Chinese hacking group, narrowing confirmed breaches.

    #QTFY #DOJ #ChinaHackers #CyberEspionage #NASA

    meterpreter.org/doj-qtfy-corre

  3. US Disrupts Chinese Cyber Espionage Proxy Network

    The FBI has struck a major blow against Chinese cyber espionage, disrupting a proxy network used to sell reconnaissance and operational routing capabilities to malicious actors. This key takedown targeted a technical quartermaster tied to Nanjing Xinjiuwei Network Technology Company, a company linked to the notorious QTYF…

    osintsights.com/us-disrupts-ch

    #ChineseCyberEspionage #CyberEspionage #Fbi #Qtyf #NanjingXinjiuweiNetworkTechnologyCompany

  4. هجوم اختراق حسابات البريد الإلكتروني لصندوق النقد الدولي

    تاريخ الهجوم: فبراير 2024 الجهة المستهدفة: صندوق النقد الدولي (International Monetary Fund - IMF) نوع الهجوم: اختراق حسابات بريد إلكتروني / Cyberattack الهجوم:تعرض صندوق النقد الدولي (IMF) لهجوم سيبراني تم اكتشافه في 16 فبراير 2024، حيث تمكن مهاجمون مجهولون من اختراق 11 حساب بريد إلكتروني تابعًا […]

    cybercases8.wordpress.com/2026

  5. Expands Toolset With New Backdoor, SSH Tunnel

    An Iranian-linked cyber-espionage group known as Tortoiseshell has enhanced its malware arsenal with newly identified tools, including a reverse SSH tunneling utility and a C++ backdoor. The SSH tunnel, disguised as wtsapi32.dll, leverages Windows OpenSSH client to establish connections with command-and-control infrastructure. The backdoor, showing similarities to TWOSTROKE malware, supports file execution, shell commands, in-memory DLL execution, and file manipulation capabilities. Infrastructure analysis revealed domains with subdomains referencing UAE, Saudi Arabia, UK, Belgium, Canada, Australia, and Japan, suggesting expanded targeting beyond the group's traditional focus on defense, aerospace, IT service providers, and military organizations in the Middle East and United States. Active since 2018, the group continues operations with persistent infrastructure despite domain suspensions.

    Pulse ID: 6a8f1fe0b63c473eb499fd00
    Pulse Link: otx.alienvault.com/pulse/6a8f1
    Pulse Author: AlienVault
    Created: 2026-08-26 17:18:24

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Australia #BackDoor #Canada #CyberSecurity #Espionage #InfoSec #Iran #Japan #Malware #MiddleEast #Military #OTX #OpenThreatExchange #RAT #SSH #SaudiArabia #TortoiseShell #UAE #UK #UnitedStates #Windows #bot #cyberespionage #AlienVault

  6. FBI Disrupts Chinese Espionage Proxy Network

    Kudos to the FBI and DOJ for taking down a Chinese cyber espionage proxy network that's been targeting US critical infrastructure - a huge win for national security. This disruption, made possible by Lumen Technologies' Black Lotus Labs' year-long tracking, has crippled the infrastructure used by Chinese hackers to spy on and gather…

    osintsights.com/fbi-disrupts-c

    #ChineseEspionage #CyberEspionage #NationState #EmergingThreats #UsCriticalInfrastructure

  7. Cybersecurity researchers warn that suspected Russian espionage groups are abusing legitimate WhatsApp, Google, and Microsoft authentication to target diplomats, academics, and defense personnel— even recording victims through fake calls. 🔐🎯 #Cybersecurity #WhatsApp #CyberEspionage cyberinsider.com/russian-hacke

  8. Russian hackers hijack EU accounts via Google OAuth. Lock down auth flows!

    #OAuth #CyberEspionage #EU

  9. SilkParasite: Tracking a China-Nexus APT Across Central Asia

    SilkParasite is a cyberespionage operation assessed with medium confidence as China-nexus that targeted government bodies across Central Asia. Seven remote access tool families were deployed, five of which were previously undocumented: DriveSilkRAT, CookiETagRAT, NomadRAT, GoginRAT, and NodeEdgeRAT. The toolset is small, modular, and professionally engineered with traces of AI-assisted development. Initial access occurred through malicious Microsoft Office documents delivered via spear-phishing, using regionally tailored lures impersonating government ministries. The operation leveraged DLL sideloading as the primary delivery mechanism and used Google Drive for command-and-control communications to hide within trusted services. Infrastructure analysis identified connections to China Unicom's backbone network, and operational patterns suggest a functioning software organization with maintained build pipelines and careful operational security.

    Pulse ID: 6a86a70eb8b57f155e62d4f7
    Pulse Link: otx.alienvault.com/pulse/6a86a
    Pulse Author: AlienVault
    Created: 2026-08-20 07:04:46

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Asia #CentralAsia #China #CyberSecurity #Cyberespionage #DRat #Edge #Espionage #Google #Government #InfoSec #Microsoft #MicrosoftOffice #OTX #Office #OpenThreatExchange #Phishing #RAT #Rust #SideLoading #SpearPhishing #bot #AlienVault

  10. Smile, You’re on Camera! Part 2: Lazarus IT Workers Exposed

    Part 2: Hiring North Korean IT workers in a fake DeFi startup shows how the country’s infamous “Famous Chollima” cyber-espionage operation works.

    Pulse ID: 6a8693c10ec0d620c77b5808
    Pulse Link: otx.alienvault.com/pulse/6a869
    Pulse Author: Tr1sa111
    Created: 2026-08-20 05:42:25

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #Espionage #InfoSec #Korea #Lazarus #NorthKorea #OTX #OpenThreatExchange #RAT #bot #cyberespionage #Tr1sa111

  11. Cavern C2 Uses DNS and Google Apps Script to Blend Into Legitimate Traffic

    Indicators extracted from public reporting. Source: securelist.com/project-cav3rn-

    Pulse ID: 6a8367506b41736758a8d45b
    Pulse Link: otx.alienvault.com/pulse/6a836
    Pulse Author: CyberHunter_NL
    Created: 2026-08-17 19:56:00

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #Cyberespionage #DNS #Espionage #Google #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #Outlook #RCE #SecureList #bot #CyberHunter_NL

  12. Russia is targeting Ukraine using internet-connected cameras across Europe. The camera hacks facilitate the targeting of Ukrainian soldiers and materiel.
    databreachtoday.com/russia-tar #cyberespionage

  13. New Armored Likho tools target Telegram and eavesdropping

    In May 2026, a cyber-espionage campaign by the Armored Likho group (also known as Eagle Werewolf) targeted private individuals and organizations across Russia, including major corporations, public sector entities, IT companies, and educational institutions. The attackers employed fake donation service applications as initial infection vectors. The campaign introduced the Still Toolkit, comprising two Rust-based components: Still Sync, which steals Telegram session data and leverages the Telegram API to extract chat logs and media files, and Still Audio, an implant that conducts covert audio surveillance by detecting speech patterns and recording conversations. The toolkit demonstrates sophisticated capabilities including Dead Drop Resolver techniques, RMS-based voice activity detection, and gRPC-based C2 communications. The campaign shows significant code overlap with previous Armored Likho operations, particularly from February 2026, including identical dropper architecture, encryption algorithms, and inf...

    Pulse ID: 6a7eef664b5b3aa69c6a38b3
    Pulse Link: otx.alienvault.com/pulse/6a7ee
    Pulse Author: AlienVault
    Created: 2026-08-14 10:35:18

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #Education #Encryption #Espionage #InfoSec #OTX #OpenThreatExchange #RAT #RPC #Russia #Rust #Telegram #bot #cyberespionage #AlienVault

  14. New Armored Likho tools target Telegram and eavesdropping

    In May 2026, a new cyber-espionage campaign by the Armored Likho group targeted private individuals and organizations across Russia, including major corporations, public sector entities, IT companies, and educational institutions. The operation used fake donation service applications as initial infection vectors. The attackers deployed a new toolkit called Still Toolkit, written in Rust, comprising two components: Still Sync steals Telegram session data enabling automated extraction of chat logs, media files and account information through Telegram API; Still Audio performs covert audio surveillance by analyzing incoming audio streams, automatically detecting speech patterns, recording conversations and transmitting them to command-and-control servers. The campaign demonstrates significant evolution in the group's capabilities, utilizing shared infrastructure patterns and encryption techniques consistent with previous operations.

    Pulse ID: 6a7da6ccbbdd8552713c76a1
    Pulse Link: otx.alienvault.com/pulse/6a7da
    Pulse Author: AlienVault
    Created: 2026-08-13 11:13:16

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #Education #Encryption #Espionage #InfoSec #OTX #OpenThreatExchange #RAT #Russia #Rust #Telegram #bot #cyberespionage #AlienVault

  15. Armored Likho expands its cyber-espionage toolkit

    Indicators extracted from public reporting. Source: securelist.com/armored-likho-s

    Pulse ID: 6a7d8697e0bd510e87086185
    Pulse Link: otx.alienvault.com/pulse/6a7d8
    Pulse Author: CyberHunter_NL
    Created: 2026-08-13 08:55:51

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #Espionage #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RCE #SecureList #bot #cyberespionage #CyberHunter_NL

  16. A Leaked Memo Ties Cyberattacks on Minnesota Water Utilities to Iran

    In its report on the Minnesota water cyberattacks, Tenable pointed to an advisory from CISA that was initially…
    #NewsBeep #News #BreakingNews #affiliate-disclaimer-disable #breakingnews #cyberattacksandhacks #cyberespionage #cybersecurity #cyberwar #hacking #Iran #malware #Security #splitscreenimagerightinset #War #web
    newsbeep.com/670846/

  17. 📰 China-Aligned APTs Use Public AI Tools in Espionage Campaigns

    China-aligned APTs are now using public AI tools like Claude Code and DeepSeek in espionage campaigns. The attackers use the AI for scripting and command execution, targeting government and financial entities in Asia. #APT #CyberEspionage #AI #Threat...

    🌐 cyber[.]netsecops[.]io

    🔗 cyber.netsecops.io/articles/ch

  18. CRITICAL threat: Russian FSB-linked cyber espionage & sabotage campaign hits gov & infrastructure across Europe since 2010. No CVE, but big impact on power, heating, transport. Follow national guidance; boost vigilance. radar.offseq.com/threat/eu-tar #OffSeq #CyberEspionage #FSB #EU

  19. 🇰🇵 300+ Fortune 500 companies hired a North Korean engineer.

    None of them knew it at the time.

    In 2024-2025, DPRK operators used stolen US identities, AI-modified avatars and real-time#Deepfake interviews to infiltrate Fortune 500 and mid-market tech companies.

    → Stolen US identity + AI-generated profile
    → Live #AI assisted interview manipulation
    → Domestic facilitator handling onboarding
    → Corporate laptop sent to a US “laptop farm”
    → KVM/VPN tunnel from Pyongyang via Russian or Chinese relays
    → Salaries redirected through facilitator accounts → ~90% skimmed to the DPRK regime

    More than 300 companies impacted. Estimated revenue stream: ~$600M/year.

    Funds allegedly routed to DPRK Bureau 39 and the ballistic missile programme.

    $17.8M traced in facilitator accounts in the Christina Chapman case alone. Detection took months, not minutes. Traditional monitoring and standard #SOC visibility would likely not have detected the operation. Mandiant tracks the cluster as #UNC5267.

    This is no longer simple cybercrime. It is state-sponsored infiltration blending #CyberSecurity, #IdentityFraud, #OSINT, remote work infrastructure abuse and AI-powered social engineering.

    The future of #CTI and insider-threat detection is already here.

    cidu.io/articles/dprk-it-worke

    #NorthKorea #DPRK #CyberThreatIntelligence #CyberEspionage #CyberWarfare #Infosec #BlueTeam #ThreatIntel #Geopolitics #RemoteWork #VPN #KVM #Fortune500

  20. 🇰🇵 300+ Fortune 500 companies hired a North Korean engineer.

    None of them knew it at the time.

    In 2024-2025, DPRK operators used stolen US identities, AI-modified avatars and real-time#Deepfake interviews to infiltrate Fortune 500 and mid-market tech companies.

    → Stolen US identity + AI-generated profile
    → Live #AI assisted interview manipulation
    → Domestic facilitator handling onboarding
    → Corporate laptop sent to a US “laptop farm”
    → KVM/VPN tunnel from Pyongyang via Russian or Chinese relays
    → Salaries redirected through facilitator accounts → ~90% skimmed to the DPRK regime

    More than 300 companies impacted. Estimated revenue stream: ~$600M/year.

    Funds allegedly routed to DPRK Bureau 39 and the ballistic missile programme.

    $17.8M traced in facilitator accounts in the Christina Chapman case alone. Detection took months, not minutes. Traditional monitoring and standard #SOC visibility would likely not have detected the operation. Mandiant tracks the cluster as #UNC5267.

    This is no longer simple cybercrime. It is state-sponsored infiltration blending #CyberSecurity, #IdentityFraud, #OSINT, remote work infrastructure abuse and AI-powered social engineering.

    The future of #CTI and insider-threat detection is already here.

    cidu.io/articles/dprk-it-worke

    #NorthKorea #DPRK #CyberThreatIntelligence #CyberEspionage #CyberWarfare #Infosec #BlueTeam #ThreatIntel #Geopolitics #RemoteWork #VPN #KVM #Fortune500

  21. In 2024, a group known as DarkCasino emerged as a cyber threat entity. This group has been linked to exploiting a vulnerability in WinRAR, specifically identified as CVE 2023 38831. DarkCasino has been using this security loophole to carry out phishing attacks targeting users in industries such as casinos, financial services, and government sectors across countries. Their strategy involves sending emails containing manipulated archives to distribute malicious software and gather sensitive information.

    DarkCasino, while sharing similarities with other cyber threat groups, stands out for its sophisticated techniques and primarily financial motivation. Their use of Visual Basic-based Trojan horse programs is a testament to their advanced capabilities. Their activities underscore the ever-evolving landscape of risks and the critical need for robust cybersecurity measures. Ongoing surveillance and analysis by cybersecurity firms like NSFOCUS and Group IB have provided insights into DarkCasino's operations, but many specifics regarding their targets and the complete extent of their actions remain undisclosed, adding to the complexity of the challenge.

    #DarkCasino #APT #CyberSecurity #WinRAR #ZeroDay #PhishingAttacks #CyberThreats #DataExfiltration #Malware #AdvancedThreats #VisualBasic #TrojanHorse #FinancialServices #GovernmentSecurity #NSFOCUS #GroupIB #CyberEspionage #ThreatDetection #InformationSecurity #EconomicMotivation

  22. The Computer Emergency Response Team of Ukraine (CERT-UA) reports that the threat actor group UAC-0184 is increasingly using popular messengers and social engineering in 2024 to target the Ukrainian military, and steal documents/messenger data (e.g. Signal). Malware delivered include IDAT, RemcosRAT, VIOTTOKEYLOGGER, XWorm, SIGTOP and TUSC. A lot of IOC provided, and images depict infection chains or lure messages. 🔗 (Ukrainian language) cert.gov.ua/article/6278521

    #CERTUA #UAC0184 #Ukraine #cyberespionage #threatintel #IOC #RemcosRAT #IDAT #xworm