#cyberespionage — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #cyberespionage, aggregated by home.social.
-
Chinese hackers launch Chrome zero-day exploit chain attacks against NGOs. Learn how this Chrome zero-day exploit chain exploits patch gaps.
#ChromeZeroDay #JungleBamboo #UTA0560 #CyberEspionage #InfoSec #Malware
-
The ted backdoor is DPRK Linux malware hidden inside HAProxy. It pairs with curlRAT to spy on South Korean media and automotive firms, Rapid7 reports.
#TedBackdoor #curlRAT #DPRK #APT37 #LinuxMalware #HAProxy #SouthKorea #Cyberespionage #Rapid7 #InfoSec
http://securityonline.info/ted-backdoor-curlrat-dprk/?utm_source=mastodon&utm_medium=jetpack_social
-
Threat analysts reveal Kimsuky uses AI agent opencode to mass-produce phishing decoys. Discover how the group leverages AI to enhance its LNK attacks.
#Kimsuky #Opencode #AIAgent #CyberEspionage #Cybersecurity
https://securityonline.info/kimsuky-ai-agent-opencode/?utm_source=mastodon&utm_medium=jetpack_social
-
Threat analysts reveal Kimsuky uses AI agent opencode to mass-produce phishing decoys. Discover how the group leverages AI to enhance its LNK attacks.
#Kimsuky #Opencode #AIAgent #CyberEspionage #Cybersecurity
https://securityonline.info/kimsuky-ai-agent-opencode/?utm_source=mastodon&utm_medium=jetpack_social
-
Threat analysts reveal Kimsuky uses AI agent opencode to mass-produce phishing decoys. Discover how the group leverages AI to enhance its LNK attacks.
#Kimsuky #Opencode #AIAgent #CyberEspionage #Cybersecurity
https://securityonline.info/kimsuky-ai-agent-opencode/?utm_source=mastodon&utm_medium=jetpack_social
-
Threat analysts reveal Kimsuky uses AI agent opencode to mass-produce phishing decoys. Discover how the group leverages AI to enhance its LNK attacks.
#Kimsuky #Opencode #AIAgent #CyberEspionage #Cybersecurity
https://securityonline.info/kimsuky-ai-agent-opencode/?utm_source=mastodon&utm_medium=jetpack_social
-
Espionage groups use the BlueMoon exploit kit in new attacks. Discover how BlueMoon exploit kit campaigns exploit Chrome zero-days.
#BlueMoon #ExploitKit #Chrome #ZeroDay #CyberEspionage #InfoSec
-
Espionage groups use the BlueMoon exploit kit in new attacks. Discover how BlueMoon exploit kit campaigns exploit Chrome zero-days.
#BlueMoon #ExploitKit #Chrome #ZeroDay #CyberEspionage #InfoSec
-
Espionage groups use the BlueMoon exploit kit in new attacks. Discover how BlueMoon exploit kit campaigns exploit Chrome zero-days.
#BlueMoon #ExploitKit #Chrome #ZeroDay #CyberEspionage #InfoSec
-
Espionage groups use the BlueMoon exploit kit in new attacks. Discover how BlueMoon exploit kit campaigns exploit Chrome zero-days.
#BlueMoon #ExploitKit #Chrome #ZeroDay #CyberEspionage #InfoSec
-
SilkParasite: Tracking a China-Nexus APT Across Central Asia
SilkParasite is a cyberespionage operation assessed with medium confidence as China-nexus that targeted government bodies across Central Asia. Seven remote access tool families were deployed, five of which were previously undocumented: DriveSilkRAT, CookiETagRAT, NomadRAT, GoginRAT, and NodeEdgeRAT. The toolset is small, modular, and professionally engineered with traces of AI-assisted development. Initial access occurred through malicious Microsoft Office documents delivered via spear-phishing, using regionally tailored lures impersonating government ministries. The operation leveraged DLL sideloading as the primary delivery mechanism and used Google Drive for command-and-control communications to hide within trusted services. Infrastructure analysis identified connections to China Unicom's backbone network, and operational patterns suggest a functioning software organization with maintained build pipelines and careful operational security.
Pulse ID: 6a86a70eb8b57f155e62d4f7
Pulse Link: https://otx.alienvault.com/pulse/6a86a70eb8b57f155e62d4f7
Pulse Author: AlienVault
Created: 2026-08-20 07:04:46Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Asia #CentralAsia #China #CyberSecurity #Cyberespionage #DRat #Edge #Espionage #Google #Government #InfoSec #Microsoft #MicrosoftOffice #OTX #Office #OpenThreatExchange #Phishing #RAT #Rust #SideLoading #SpearPhishing #bot #AlienVault
-
I buried the lede in not mentioning that UNC5291 is assessed with medium confidence to be associated with Volt Typhoon, a Chinese state-sponsored Advanced Persistent Threat (APT). See related The Record reporting: Volt Typhoon and 4 other groups targeting US energy and defense sectors through Ivanti bugs
#Ivanti #ConnectSecure #vulnerability #cyberespionage #China #activeexploitation #eitw #zeroday #KEV #CISA #CVE_2023_46805 #CVE_2024_21887 #CVE_2024_21893 #UNC5221 #UNC5266 #UNC5330 #UNC5337 #UNC5291
-
Mandiant releases part 4 of the Ivanti Connect Secure incident response investigation. They detail different types of post-exploitation activity across their IR engagements. Chinese threat actors have a growing knowledge of Ivanti Connect Secure in abusing appliance-specific functionality to perform actions on objective. They highlight FIVE Chinese threat actors: UNC5221, UNC5266, UNC5330, UNC5337, and UNC5291 abusing a mix of CVE-2023-46805, CVE-2024-21887, and CVE-2024-21893. New TTPs, new malware families and new IOC: 🔗 https://cloud.google.com/blog/topics/threat-intelligence/ivanti-post-exploitation-lateral-movement
EDIT: For your situational awareness, it's my understanding that future Mandiant articles will be located at https://cloud.google.com/blog/topics/threat-intelligence/
#Ivanti #ConnectSecure #vulnerability #cyberespionage #China #activeexploitation #eitw #zeroday #KEV #CISA #CVE_2023_46805 #CVE_2024_21887 #CVE_2024_21893 #UNC5221 #UNC5266 #UNC5330 #UNC5337 #UNC5291