#cyberespionage — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #cyberespionage, aggregated by home.social.
-
Cybersecurity researchers warn that suspected Russian espionage groups are abusing legitimate WhatsApp, Google, and Microsoft authentication to target diplomats, academics, and defense personnel— even recording victims through fake calls. 🔐🎯 #Cybersecurity #WhatsApp #CyberEspionage https://cyberinsider.com/russian-hackers-abuse-whatsapp-device-linking-to-spy-on-high-value-targets/
-
T-Mobile security staff physically severed a network cable in 2024 to block Chinese state-linked Salt Typhoon hackers from reaching the carrier's infrastructure.
#SaltTyphoon #TMobile #ChinaHack #Telecommunications #CyberEspionage
-
Russian hackers hijack EU accounts via Google OAuth. Lock down auth flows!
-
SilkParasite: Tracking a China-Nexus APT Across Central Asia
SilkParasite is a cyberespionage operation assessed with medium confidence as China-nexus that targeted government bodies across Central Asia. Seven remote access tool families were deployed, five of which were previously undocumented: DriveSilkRAT, CookiETagRAT, NomadRAT, GoginRAT, and NodeEdgeRAT. The toolset is small, modular, and professionally engineered with traces of AI-assisted development. Initial access occurred through malicious Microsoft Office documents delivered via spear-phishing, using regionally tailored lures impersonating government ministries. The operation leveraged DLL sideloading as the primary delivery mechanism and used Google Drive for command-and-control communications to hide within trusted services. Infrastructure analysis identified connections to China Unicom's backbone network, and operational patterns suggest a functioning software organization with maintained build pipelines and careful operational security.
Pulse ID: 6a86a70eb8b57f155e62d4f7
Pulse Link: https://otx.alienvault.com/pulse/6a86a70eb8b57f155e62d4f7
Pulse Author: AlienVault
Created: 2026-08-20 07:04:46Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Asia #CentralAsia #China #CyberSecurity #Cyberespionage #DRat #Edge #Espionage #Google #Government #InfoSec #Microsoft #MicrosoftOffice #OTX #Office #OpenThreatExchange #Phishing #RAT #Rust #SideLoading #SpearPhishing #bot #AlienVault
-
Smile, You’re on Camera! Part 2: Lazarus IT Workers Exposed
Part 2: Hiring North Korean IT workers in a fake DeFi startup shows how the country’s infamous “Famous Chollima” cyber-espionage operation works.
Pulse ID: 6a8693c10ec0d620c77b5808
Pulse Link: https://otx.alienvault.com/pulse/6a8693c10ec0d620c77b5808
Pulse Author: Tr1sa111
Created: 2026-08-20 05:42:25Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #Espionage #InfoSec #Korea #Lazarus #NorthKorea #OTX #OpenThreatExchange #RAT #bot #cyberespionage #Tr1sa111
-
Jewelbug Chinese APT Linked to Hack-for-Hire Operations - https://www.redpacketsecurity.com/researchers-link-jewelbug-chinese-apt-to-hack-for-hire-operations/
-
Cavern C2 Uses DNS and Google Apps Script to Blend Into Legitimate Traffic
Indicators extracted from public reporting. Source: https://securelist.com/project-cav3rn-cyberespionage-framework-using-outlook-and-dns/120757/
Pulse ID: 6a8367506b41736758a8d45b
Pulse Link: https://otx.alienvault.com/pulse/6a8367506b41736758a8d45b
Pulse Author: CyberHunter_NL
Created: 2026-08-17 19:56:00Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #Cyberespionage #DNS #Espionage #Google #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #Outlook #RCE #SecureList #bot #CyberHunter_NL
-
Russia is targeting Ukraine using internet-connected cameras across Europe. The camera hacks facilitate the targeting of Ukrainian soldiers and materiel.
https://www.databreachtoday.com/russia-targeting-ukraine-using-internet-connected-cameras-a-32566 #cyberespionage -
New Armored Likho tools target Telegram and eavesdropping
In May 2026, a cyber-espionage campaign by the Armored Likho group (also known as Eagle Werewolf) targeted private individuals and organizations across Russia, including major corporations, public sector entities, IT companies, and educational institutions. The attackers employed fake donation service applications as initial infection vectors. The campaign introduced the Still Toolkit, comprising two Rust-based components: Still Sync, which steals Telegram session data and leverages the Telegram API to extract chat logs and media files, and Still Audio, an implant that conducts covert audio surveillance by detecting speech patterns and recording conversations. The toolkit demonstrates sophisticated capabilities including Dead Drop Resolver techniques, RMS-based voice activity detection, and gRPC-based C2 communications. The campaign shows significant code overlap with previous Armored Likho operations, particularly from February 2026, including identical dropper architecture, encryption algorithms, and inf...
Pulse ID: 6a7eef664b5b3aa69c6a38b3
Pulse Link: https://otx.alienvault.com/pulse/6a7eef664b5b3aa69c6a38b3
Pulse Author: AlienVault
Created: 2026-08-14 10:35:18Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #Education #Encryption #Espionage #InfoSec #OTX #OpenThreatExchange #RAT #RPC #Russia #Rust #Telegram #bot #cyberespionage #AlienVault
-
New Armored Likho tools target Telegram and eavesdropping
In May 2026, a new cyber-espionage campaign by the Armored Likho group targeted private individuals and organizations across Russia, including major corporations, public sector entities, IT companies, and educational institutions. The operation used fake donation service applications as initial infection vectors. The attackers deployed a new toolkit called Still Toolkit, written in Rust, comprising two components: Still Sync steals Telegram session data enabling automated extraction of chat logs, media files and account information through Telegram API; Still Audio performs covert audio surveillance by analyzing incoming audio streams, automatically detecting speech patterns, recording conversations and transmitting them to command-and-control servers. The campaign demonstrates significant evolution in the group's capabilities, utilizing shared infrastructure patterns and encryption techniques consistent with previous operations.
Pulse ID: 6a7da6ccbbdd8552713c76a1
Pulse Link: https://otx.alienvault.com/pulse/6a7da6ccbbdd8552713c76a1
Pulse Author: AlienVault
Created: 2026-08-13 11:13:16Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #Education #Encryption #Espionage #InfoSec #OTX #OpenThreatExchange #RAT #Russia #Rust #Telegram #bot #cyberespionage #AlienVault
-
Armored Likho expands its cyber-espionage toolkit
Indicators extracted from public reporting. Source: https://securelist.com/armored-likho-still-toolkit/121033/
Pulse ID: 6a7d8697e0bd510e87086185
Pulse Link: https://otx.alienvault.com/pulse/6a7d8697e0bd510e87086185
Pulse Author: CyberHunter_NL
Created: 2026-08-13 08:55:51Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #Espionage #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RCE #SecureList #bot #cyberespionage #CyberHunter_NL
-
NightLedger Backdoor Deployed in Espionage Campaign Targeting the Middle East and Africa
An advanced persistent threat group, Mirage Kitten, is conducting cyber-espionage operations across the Middle East and Africa using three previously undocumented malware families: NightLedger, BridgeHead, and ArcBridge. These tools provide reconnaissance, command execution, covert tunneling, and persistent access capabilities. The campaign targets organizations in Egypt, Jordan, Tanzania, Pakistan, Ethiopia, and Burkina Faso across aerospace, aviation, defense, telecommunications, government, financial services, and SMB sectors. Initial access is gained through targeted spear-phishing with recruitment-themed lures and fake videoconferencing pages. The malware demonstrates sophisticated operational security features including victim-specific execution controls, WebSocket-based tunneling, and Cloudflare-backed infrastructure, reflecting the group's investment in bespoke tooling for long-term intelligence collection.
Pulse ID: 6a71aa488c89bfcbd2814692
Pulse Link: https://otx.alienvault.com/pulse/6a71aa488c89bfcbd2814692
Pulse Author: AlienVault
Created: 2026-08-04 09:00:56Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Africa #BackDoor #Cloud #CyberSecurity #Edge #Espionage #Government #InfoSec #Malware #MiddleEast #OTX #OpenThreatExchange #Pakistan #Phishing #RAT #SMB #SpearPhishing #Telecom #Telecommunication #bot #cyberespionage #AlienVault
-
A massive Chinese hacking campaign was exposed after attackers left their server directories open, revealing SNOWLIGHT malware and thousands of global targets.
#Cybersecurity #Malware #SNOWLIGHT #CyberEspionage #TechNews
https://meterpreter.org/snowlight-malware-exposed/?utm_source=mastodon&utm_medium=jetpack_social
-
Mirage Kitten malware, tied to the UNC1549 APT, hit aviation and telecom targets across the Middle East and Africa with new backdoors and tunnelers.
#MirageKitten #UNC1549 #APT #CyberEspionage #NightLedger #Iran #ThreatIntel #InfoSec #CyberSecurity
http://securityonline.info/mirage-kitten-malware/?utm_source=mastodon&utm_medium=jetpack_social
-
A Leaked Memo Ties Cyberattacks on Minnesota Water Utilities to Iran
In its report on the Minnesota water cyberattacks, Tenable pointed to an advisory from CISA that was initially…
#NewsBeep #News #BreakingNews #affiliate-disclaimer-disable #breakingnews #cyberattacksandhacks #cyberespionage #cybersecurity #cyberwar #hacking #Iran #malware #Security #splitscreenimagerightinset #War #web
https://www.newsbeep.com/670846/ -
A Leaked Memo Ties Cyberattacks on Minnesota Water Utilities to Iran
-
📰 China-Aligned APTs Use Public AI Tools in Espionage Campaigns
China-aligned APTs are now using public AI tools like Claude Code and DeepSeek in espionage campaigns. The attackers use the AI for scripting and command execution, targeting government and financial entities in Asia. #APT #CyberEspionage #AI #Threat...
🌐 cyber[.]netsecops[.]io
-
GoSerpent backdoor drives a patient cyber espionage campaign against Southeast Asian governments, stealing files and credentials since at least 2021.
#GoSerpent #CyberEspionage #Kaspersky #Backdoor #APT #SoutheastAsia #ThreatIntel
https://securityonline.info/goserpent-backdoor/?utm_source=mastodon&utm_medium=jetpack_social
-
Global Webmail Espionage
A persistent cyberespionage campaign tracked as CL-STA-1114, overlapping with Russian threat actor activity known as Void Blizzard and LAUNDRY BEAR, has been targeting Zimbra webmail in government, defense, transportation, and financial organizations. The campaign focuses on NATO member states, Ukraine, Commonwealth of Independent States countries, and Africa. Attackers exploit CVE-2025-66376, a vulnerability in Zimbra Collaboration Suite, using zero-click phishing emails that automatically inject malicious JavaScript payloads without user interaction. The payload exfiltrates sensitive data including login credentials, email archives, CSRF tokens, 2FA scratch codes, and 90 days of email history to command and control servers. Active since 2024, the campaign targeting Zimbra servers began in July 2025, utilizing HTML attachments with obfuscated Base64-encoded scripts that deploy SVG elements to inject the JavaScript into victims' browsers.
Pulse ID: 6a624073df6738006a6f6e5a
Pulse Link: https://otx.alienvault.com/pulse/6a624073df6738006a6f6e5a
Pulse Author: AlienVault
Created: 2026-07-23 16:25:23Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#2FA #Africa #Browser #CyberSecurity #Cyberespionage #Email #Espionage #Government #HTML #InfoSec #Java #JavaScript #NATO #OTX #OpenThreatExchange #Phishing #RAT #Russia #SVG #UK #Ukr #Ukraine #Vulnerability #Webmail #Zimbra #bot #AlienVault
-
🚨 SIGINT // Cybersecurity Watch — 2026-07-24
US agencies warn Iran-affiliated hackers are targeting Siemens, Schneider Electric & Rockwell ICS devices in critical infrastructure attacks.
https://www.securityweek.com/us-warns-of-iranian-hackers-targeting-siemens-schneider-and-rockwell-ics-devices/
#ICS #CriticalInfrastructure #CyberEspionage #InfoSec -
📰 China-Aligned APTs Use Public AI Tools in Espionage Campaigns
China-aligned APTs are now using public AI tools like Claude Code and DeepSeek in espionage campaigns. The attackers use the AI for scripting and command execution, targeting government and financial entities in Asia. #APT #CyberEspionage #AI #Threat...
🌐 cyber[.]netsecops[.]io
-
He was an astronomer. Not a spy. Not a cop. Just a curious man who found a 75-cent error and followed it all the way to the KGB. Read The Cuckoo's Egg.
#CuckoosEgg #CliffordStoll #CyberEspionage #books #bookreviews
https://thisgrandpablogs.com/cuckoos-egg-book-review/ -
This is one of the first true accounts of cyber espionage ever written. It holds up after 35 years. Read why.
#books #bookreview #cyberespionage #coldwarspy
https://thisgrandpablogs.com/cuckoos-egg-book-review/ -
CRITICAL threat: Russian FSB-linked cyber espionage & sabotage campaign hits gov & infrastructure across Europe since 2010. No CVE, but big impact on power, heating, transport. Follow national guidance; boost vigilance. https://radar.offseq.com/threat/eu-targets-russian-intelligence-officers-accused-o-fc2dc036f7820f41 #OffSeq #CyberEspionage #FSB #EU
-
🚨 A newly identified APT dubbed #ArmoredLikho is targeting government agencies and energy organizations with #BusySnake Stealer, a Python-based infostealer delivered through AI-generated loaders and spear-phishing campaigns.
The malware steals credentials, Telegram sessions, cryptocurrency wallets, and more, while built-in reverse SSH tunneling gives attackers long-term remote access.
Listen/Read: https://hackread.com/armored-likho-government-energy-busysnake-stealer/
#CyberSecurity #InfoSec #APT #Malware #Phishing #CyberEspionage
-
2/3
GTG-1002: Anthropic's own disclosed report on a Chinese state-sponsored group that jailbroke Claude Code by claiming to be a legitimate security firm, then ran ~80-90% of a 30-target espionage campaign autonomously. Five months before contested (unconfirmed) covert China-proxy detection code turned up in Claude Code. The timing isn't abstract. -
During H1 2026 I recorded 55 incidents exploiting 66 #vulnerabilities targeting security vendors
🔴 50% #Cybercrime
🔴 22% #Cyberespionage
🔴 #Malware & #RCE dominate attack techniquesFull interactive report 👇
https://hackmageddon.com/2026/06/25/exploited-security-vendor-vulnerabilities-in-2026/