home.social

#cyberespionage — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #cyberespionage, aggregated by home.social.

  1. SilkParasite: Tracking a China-Nexus APT Across Central Asia

    SilkParasite is a cyberespionage operation assessed with medium confidence as China-nexus that targeted government bodies across Central Asia. Seven remote access tool families were deployed, five of which were previously undocumented: DriveSilkRAT, CookiETagRAT, NomadRAT, GoginRAT, and NodeEdgeRAT. The toolset is small, modular, and professionally engineered with traces of AI-assisted development. Initial access occurred through malicious Microsoft Office documents delivered via spear-phishing, using regionally tailored lures impersonating government ministries. The operation leveraged DLL sideloading as the primary delivery mechanism and used Google Drive for command-and-control communications to hide within trusted services. Infrastructure analysis identified connections to China Unicom's backbone network, and operational patterns suggest a functioning software organization with maintained build pipelines and careful operational security.

    Pulse ID: 6a86a70eb8b57f155e62d4f7
    Pulse Link: otx.alienvault.com/pulse/6a86a
    Pulse Author: AlienVault
    Created: 2026-08-20 07:04:46

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Asia #CentralAsia #China #CyberSecurity #Cyberespionage #DRat #Edge #Espionage #Google #Government #InfoSec #Microsoft #MicrosoftOffice #OTX #Office #OpenThreatExchange #Phishing #RAT #Rust #SideLoading #SpearPhishing #bot #AlienVault

  2. CVE-2026-22769 (CVSS 10.0) in Dell RecoverPoint for VMs is under confirmed exploitation.

    Attribution: UNC6201 (linked to Silk Typhoon)
    Malware: BRICKSTORM (evolving) → GRIMBOLT
    Vector: Hard-coded credentials
    Impact Layer: VMware-integrated DR appliances

    This is a high-leverage target:
    - Elevated privileges
    - Direct integration with hypervisors & storage
    - Influence over replicated datasets
    - Potential long-term espionage dwell time

    CISA has mandated immediate patching for federal agencies.

    Key takeaway: Recovery infrastructure is now an active battlefield.
    How are you validating integrity of replicated VM copies?
    Comment below.

    Source: therecord.media/fed-agencies-o

    Follow TechNadu for threat intelligence updates.
    Share within your security teams.
    #Infosec #ThreatIntelligence #ZeroDay #CISAAlert #VMwareSecurity #CyberEspionage #BlueTeam #RedTeam #APT #SecurityOperations #DigitalForensics

  3. CVE-2026-22769 (CVSS 10.0) in Dell RecoverPoint for VMs is under confirmed exploitation.

    Attribution: UNC6201 (linked to Silk Typhoon)
    Malware: BRICKSTORM (evolving) → GRIMBOLT
    Vector: Hard-coded credentials
    Impact Layer: VMware-integrated DR appliances

    This is a high-leverage target:
    - Elevated privileges
    - Direct integration with hypervisors & storage
    - Influence over replicated datasets
    - Potential long-term espionage dwell time

    CISA has mandated immediate patching for federal agencies.

    Key takeaway: Recovery infrastructure is now an active battlefield.
    How are you validating integrity of replicated VM copies?
    Comment below.

    Source: therecord.media/fed-agencies-o

    Follow TechNadu for threat intelligence updates.
    Share within your security teams.
    #Infosec #ThreatIntelligence #ZeroDay #CISAAlert #VMwareSecurity #CyberEspionage #BlueTeam #RedTeam #APT #SecurityOperations #DigitalForensics

  4. CVE-2026-22769 (CVSS 10.0) in Dell RecoverPoint for VMs is under confirmed exploitation.

    Attribution: UNC6201 (linked to Silk Typhoon)
    Malware: BRICKSTORM (evolving) → GRIMBOLT
    Vector: Hard-coded credentials
    Impact Layer: VMware-integrated DR appliances

    This is a high-leverage target:
    - Elevated privileges
    - Direct integration with hypervisors & storage
    - Influence over replicated datasets
    - Potential long-term espionage dwell time

    CISA has mandated immediate patching for federal agencies.

    Key takeaway: Recovery infrastructure is now an active battlefield.
    How are you validating integrity of replicated VM copies?
    Comment below.

    Source: therecord.media/fed-agencies-o

    Follow TechNadu for threat intelligence updates.
    Share within your security teams.
    #Infosec #ThreatIntelligence #ZeroDay #CISAAlert #VMwareSecurity #CyberEspionage #BlueTeam #RedTeam #APT #SecurityOperations #DigitalForensics

  5. CVE-2026-22769 (CVSS 10.0) in Dell RecoverPoint for VMs is under confirmed exploitation.

    Attribution: UNC6201 (linked to Silk Typhoon)
    Malware: BRICKSTORM (evolving) → GRIMBOLT
    Vector: Hard-coded credentials
    Impact Layer: VMware-integrated DR appliances

    This is a high-leverage target:
    - Elevated privileges
    - Direct integration with hypervisors & storage
    - Influence over replicated datasets
    - Potential long-term espionage dwell time

    CISA has mandated immediate patching for federal agencies.

    Key takeaway: Recovery infrastructure is now an active battlefield.
    How are you validating integrity of replicated VM copies?
    Comment below.

    Source: therecord.media/fed-agencies-o

    Follow TechNadu for threat intelligence updates.
    Share within your security teams.
    #Infosec #ThreatIntelligence #ZeroDay #CISAAlert #VMwareSecurity #CyberEspionage #BlueTeam #RedTeam #APT #SecurityOperations #DigitalForensics

  6. Stone Panda (APT 10) continues global espionage campaigns tied to China’s MSS.
    🎯 Targets: healthcare, defense, academia
    🛠️ Tools: Mimikatz, BloodHound, Impacket
    🌍 Active in the U.S., UK, Japan, India & more
    Espionage vs disruption — which do you see as their long-term mission?
    Follow @technadu for continuous APT tracking.

    #StonePanda #APT10 #CyberEspionage #ChinaAPT #ThreatActor #Cyble

  7. The Kremlin's Most Devious #Hacking Group Is Using #Russian ISPs to Plant #Spyware

    The #FSB #cyberespionage group known as #Turla seems to have used its control of Russia's network #infrastructure to meddle with web traffic and trick #diplomats into #infecting their computers.
    #russia #kremlin #isp

    wired.com/story/russia-fsb-tur

  8. Russia’s FSB-linked hacking group Turla exploits Russian ISPs to implant spyware on diplomats' devices in Moscow, hijacking internet traffic to steal sensitive data. A new espionage tactic blurs the line between surveillance and intrusion. Full story 👇🕵️‍♂️🌐 #CyberEspionage #Turla #FSB #CyberSecurity #newz

    wired.com/story/russia-fsb-tur