#mustangpanda — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #mustangpanda, aggregated by home.social.
-
Kaspersky uncovered the new HoneyMyte CoolClient rootkit. The HoneyMyte CoolClient rootkit deploys a kernel driver to hide malware on Windows.
#HoneyMyte #CoolClient #Rootkit #MustangPanda #Cybersecurity #Kaspersky
-
Kaspersky uncovered the new HoneyMyte CoolClient rootkit. The HoneyMyte CoolClient rootkit deploys a kernel driver to hide malware on Windows.
#HoneyMyte #CoolClient #Rootkit #MustangPanda #Cybersecurity #Kaspersky
-
HoneyMyte's updated CoolClient backdoor now deploys a signed kernel-mode driver, msagent.sys, to hide processes, files, and C2 traffic on government targets.
-
HoneyMyte's updated CoolClient backdoor now deploys a signed kernel-mode driver, msagent.sys, to hide processes, files, and C2 traffic on government targets.
-
Kaspersky has identified a new variant of the CoolClient backdoor attributed to Mustang Panda. The updated toolkit now includes msagent.sys, a signed kernel-mode driver installed as a Windows service. Through IOCTL requests, it conceals processes, files, registry keys, kernel modules, and network activity from the operating system.
#MustangPanda #KernelRootkit #ThreatIntelligence #MalwareAnalysis
https://cyberworldops.eu/en/mustang-panda-strengthens-coolclient-with-a-hard-to-detect-kernel
-
Kaspersky has identified a new variant of the CoolClient backdoor attributed to Mustang Panda. The updated toolkit now includes msagent.sys, a signed kernel-mode driver installed as a Windows service. Through IOCTL requests, it conceals processes, files, registry keys, kernel modules, and network activity from the operating system.
#MustangPanda #KernelRootkit #ThreatIntelligence #MalwareAnalysis
https://cyberworldops.eu/en/mustang-panda-strengthens-coolclient-with-a-hard-to-detect-kernel
-
HoneyMyte aggiorna CoolClient: la backdoor di Mustang Panda ora si nasconde con un rootkit kernel
Il gruppo APT cinese HoneyMyte (Mustang Panda) ha potenziato la sua backdoor CoolClient con un driver kernel firmato che nasconde processi, file e traffico C2. Analisi tecnica completa della catena di infezione e degli IoC contro obiettivi in Myanmar, Mongolia, Pakistan e Russia. -
HoneyMyte aggiorna CoolClient: la backdoor di Mustang Panda ora si nasconde con un rootkit kernel
Il gruppo APT cinese HoneyMyte (Mustang Panda) ha potenziato la sua backdoor CoolClient con un driver kernel firmato che nasconde processi, file e traffico C2. Analisi tecnica completa della catena di infezione e degli IoC contro obiettivi in Myanmar, Mongolia, Pakistan e Russia. -
HoneyMyte aggiorna CoolClient: la backdoor di Mustang Panda ora si nasconde con un rootkit kernel
Il gruppo APT cinese HoneyMyte (Mustang Panda) ha potenziato la sua backdoor CoolClient con un driver kernel firmato che nasconde processi, file e traffico C2. Analisi tecnica completa della catena di infezione e degli IoC contro obiettivi in Myanmar, Mongolia, Pakistan e Russia. -
HoneyMyte aggiorna CoolClient: la backdoor di Mustang Panda ora si nasconde con un rootkit kernel
Il gruppo APT cinese HoneyMyte (Mustang Panda) ha potenziato la sua backdoor CoolClient con un driver kernel firmato che nasconde processi, file e traffico C2. Analisi tecnica completa della catena di infezione e degli IoC contro obiettivi in Myanmar, Mongolia, Pakistan e Russia. -
HoneyMyte aggiorna CoolClient: la backdoor di Mustang Panda ora si nasconde con un rootkit kernel
Il gruppo APT cinese HoneyMyte (Mustang Panda) ha potenziato la sua backdoor CoolClient con un driver kernel firmato che nasconde processi, file e traffico C2. Analisi tecnica completa della catena di infezione e degli IoC contro obiettivi in Myanmar, Mongolia, Pakistan e Russia. -
Mustang Panda has integrated a signed Windows kernel-mode rootkit into its CoolClient backdoor, enhancing its ability to evade detection by concealing malicious activities. This highlights the growing sophistication of state-sponsored cyber threats and the need for advanced security measures.
#MustangPanda #Cybersecurity #Rootkit #CoolClient #APT #ThreatIntelligence
https://thedailytechfeed.com/mustang-panda-deploys-signed-windows-rootkit-to-evade-detection/
-
Mustang Panda targets India's government and hydropower sectors, abusing Zoho WorkDrive for C2. Acronis found new ZOHOMURK and MINIRECON implants.
#MustangPanda #ZohoWorkDrive #ZOHOMURK #India #CyberEspionage #APT
-
Mustang Panda targets India's government and hydropower sectors, abusing Zoho WorkDrive for C2. Acronis found new ZOHOMURK and MINIRECON implants.
#MustangPanda #ZohoWorkDrive #ZOHOMURK #India #CyberEspionage #APT
-
Acronis has been tracking 2 concurrent campaigns orchestrated by #MustangPanda targeting Indian government entities, delivering new malware implants & abusing Zoho WorkDrive, a legitimate cloud storage platform commonly used by the Indian government.
🔗 https://www.acronis.com/en/tru/posts/mustang-panda-targets-indias-government-and-energy-sectors/
-
📰 Chinese APT Mustang Panda Targets Indian Banks, Korean Policy Experts in Espionage Campaign
🇨🇳 APT UPDATE: Mustang Panda targets Indian banks & Korean policy experts in a new espionage campaign. The group uses spear-phishing & DLL sideloading to deploy the LotusLite backdoor for intelligence gathering. 🕵️ #APT #MustangPanda #CyberEspiona...
🌐 cyber[.]netsecops[.]io
🔗 https://cyber.netsecops.io/articles/chinese-apt-mustang-panda-targets-indian-banks-and-korean-p…
-
Mustang Panda Unveils Modular FDMTP Backdoor in Cyberespionage Push
Cyberespionage groups like Mustang Panda are constantly evolving their tactics, and a recent campaign has seen the emergence of a modular backdoor that allows attackers to adapt and persist in compromised environments. This sophisticated tool enables hackers to blend in with legitimate processes, making it a major concern for security…
#Cyberespionage #ModularBackdoor #Fdmtp #MustangPanda #EarthPreta
-
Mustang Panda Deploys Updated FDMTP Backdoor in Asia-Pacific Espionage
A sophisticated espionage campaign has been targeting organizations across Asia-Pacific and Japan for months, with researchers linking the activity to the notorious China-aligned group Mustang Panda with moderate confidence. The group's tactics may evolve, but their execution model remains eerily consistent.
#MustangPanda #Asiapacific #Espionage #Chinaaligned #FdmtpBackdoor
-
📢⚠️ Watch out as China-linked #MustangPanda is deploying an updated LOTUSLITE backdoor to target Indian banks and South Korean diplomats.
Read: https://hackread.com/mustang-panda-india-s-korea-lotuslite-backdoor/
-
📢⚠️ Watch out as China-linked #MustangPanda is deploying an updated LOTUSLITE backdoor to target Indian banks and South Korean diplomats.
Read: https://hackread.com/mustang-panda-india-s-korea-lotuslite-backdoor/
-
📢⚠️ Watch out as China-linked #MustangPanda is deploying an updated LOTUSLITE backdoor to target Indian banks and South Korean diplomats.
Read: https://hackread.com/mustang-panda-india-s-korea-lotuslite-backdoor/
-
📢⚠️ Watch out as China-linked #MustangPanda is deploying an updated LOTUSLITE backdoor to target Indian banks and South Korean diplomats.
Read: https://hackread.com/mustang-panda-india-s-korea-lotuslite-backdoor/
-
📢⚠️ Watch out as China-linked #MustangPanda is deploying an updated LOTUSLITE backdoor to target Indian banks and South Korean diplomats.
Read: https://hackread.com/mustang-panda-india-s-korea-lotuslite-backdoor/
-
Mustang Panda Expands LOTUSLITE Malware to Target India, Korea
Meet the evolved LOTUSLITE backdoor, now wielding dynamic DNS-based command-and-control over HTTPS, enabling its operators to remotely access and manipulate targeted systems for espionage purposes. This sophisticated malware supports remote shell access, file operations, and session management, a potent toolkit for data collection and…
#LotusliteMalware #MustangPanda #Espionage #NationState #DynamicDns
-
📰 Chinese APT Mustang Panda Targets Indian Banks, Korean Policy Experts in Espionage Campaign
🇨🇳 APT UPDATE: Mustang Panda targets Indian banks & Korean policy experts in a new espionage campaign. The group uses spear-phishing & DLL sideloading to deploy the LotusLite backdoor for intelligence gathering. 🕵️ #APT #MustangPanda #CyberEspion...
-
📰 Chinese APT Mustang Panda Renews Espionage Campaign Against European Governments
🇨🇳 Chinese APT Mustang Panda (TA416) is back, targeting European governments, EU & NATO missions with updated tactics. Campaigns use phishing links, abuse MSBuild, and deploy PlugX malware for espionage. #APT #MustangPanda #CyberSecurity #China
-
📰 Chinese APT Mustang Panda Renews Espionage Campaign Against European Governments
🇨🇳 Chinese APT Mustang Panda (TA416) is back, targeting European governments, EU & NATO missions with updated tactics. Campaigns use phishing links, abuse MSBuild, and deploy PlugX malware for espionage. #APT #MustangPanda #CyberSecurity #China
-
https://lab52.io/blog/plugx-meeting-invitation-via-msbuild-and-gdata/
They switch up how the payload gets delivered to the victim.
-
https://lab52.io/blog/plugx-meeting-invitation-via-msbuild-and-gdata/
They switch up how the payload gets delivered to the victim.
-
https://lab52.io/blog/plugx-meeting-invitation-via-msbuild-and-gdata/
They switch up how the payload gets delivered to the victim.
-
https://lab52.io/blog/plugx-meeting-invitation-via-msbuild-and-gdata/
They switch up how the payload gets delivered to the victim.
-
https://lab52.io/blog/plugx-meeting-invitation-via-msbuild-and-gdata/
They switch up how the payload gets delivered to the victim.
-
📢🔍⚠️Chinese-linked Mustang Panda hackers used fake diplomatic briefings to target officials with spyware.
Read: https://hackread.com/chinese-mustang-panda-briefing-spy-diplomat/
-
📢🔍⚠️Chinese-linked Mustang Panda hackers used fake diplomatic briefings to target officials with spyware.
Read: https://hackread.com/chinese-mustang-panda-briefing-spy-diplomat/
-
📢🔍⚠️Chinese-linked Mustang Panda hackers used fake diplomatic briefings to target officials with spyware.
Read: https://hackread.com/chinese-mustang-panda-briefing-spy-diplomat/
-
📢🔍⚠️Chinese-linked Mustang Panda hackers used fake diplomatic briefings to target officials with spyware.
Read: https://hackread.com/chinese-mustang-panda-briefing-spy-diplomat/
-
📢🔍⚠️Chinese-linked Mustang Panda hackers used fake diplomatic briefings to target officials with spyware.
Read: https://hackread.com/chinese-mustang-panda-briefing-spy-diplomat/
-
quote :
#DreamSecurity 判定這波攻勢是由中國網路間諜組織 #MustangPanda 發動。該組織利用各國的頭條新聞或重要議題作為誘餌,藉此竊取國家機密並潛伏在美國政府機構之中。#中國 #駭客 鎖定全球外交官員寄假美國政策檔案 開啟即遭駭入
https://www.cna.com.tw/news/aopl/202602040014.aspx -
quote :
#DreamSecurity 判定這波攻勢是由中國網路間諜組織 #MustangPanda 發動。該組織利用各國的頭條新聞或重要議題作為誘餌,藉此竊取國家機密並潛伏在美國政府機構之中。#中國 #駭客 鎖定全球外交官員寄假美國政策檔案 開啟即遭駭入
https://www.cna.com.tw/news/aopl/202602040014.aspx -
quote :
#DreamSecurity 判定這波攻勢是由中國網路間諜組織 #MustangPanda 發動。該組織利用各國的頭條新聞或重要議題作為誘餌,藉此竊取國家機密並潛伏在美國政府機構之中。#中國 #駭客 鎖定全球外交官員寄假美國政策檔案 開啟即遭駭入
https://www.cna.com.tw/news/aopl/202602040014.aspx -
quote :
#DreamSecurity 判定這波攻勢是由中國網路間諜組織 #MustangPanda 發動。該組織利用各國的頭條新聞或重要議題作為誘餌,藉此竊取國家機密並潛伏在美國政府機構之中。#中國 #駭客 鎖定全球外交官員寄假美國政策檔案 開啟即遭駭入
https://www.cna.com.tw/news/aopl/202602040014.aspx -
💔 10M Dating App Users Exposed in Match Group Breach 💔
ShinyHunters cybercrime group claims to have stolen over 10 million records from Match Group (NASDAQ: MTCH), owner of Tinder, Hinge, Match.com, and OkCupid. The alleged breach, posted January 28, 2026, includes user behavioral data from Appsflyer analytics (swipes, matches, sessions, geo-locations), hundreds of internal corporate documents, and highly sensitive personal information including romantic preferences. The 1.76GB compressed dump appears linked to ShinyHunters' broader Okta voice-phishing campaign that has already compromised Crunchbase, Betterment, and SoundCloud.
Sources:
- https://x.com/justabreach/status/2016436843164696661
- https://www.ransomware.live/id/TWF0Y2ggR3JvdXBAc2hpbnlodW50ZXJz
- https://cybernews.com/security/hinge-okcupid-data-leak-shinyhunters-claims/
- https://darknetsearch.com/knowledge/news/en/match-group-leak-2026-urgent-data-breach-impact-guide/
- https://www.binance.com/en/square/post/01-28-2026-data-breach-exposes-millions-of-user-records-from-dating-apps-35696579060105#Tinder #PlentyofFish #Hinge #OKCupid #Match.com
-----------------🐴 Chinese APT Upgrades Backdoor with Browser Stealers 🐼
|Chinese espionage group Mustang Panda (aka HoneyMyte) has updated its CoolClient backdoor to steal login credentials from Chrome, Edge, and Chromium-based browsers while monitoring clipboard activity. Kaspersky researchers observed the malware targeting government entities in Myanmar, Mongolia, Malaysia, Russia, and Pakistan throughout 2025. The backdoor was deployed via compromised legitimate software from Sangfor, a Chinese cybersecurity company, and uses hardcoded API tokens for Google Drive and Pixeldrain to exfiltrate stolen data.
Sources:
- https://www.bleepingcomputer.com/news/security/chinese-mustang-panda-hackers-deploy-infostealers-via-coolclient-backdoor/
- https://securelist.com/honeymyte-updates-coolclient-uses-browser-stealers-and-scripts/118664/#China #CoolClinet #Chrome #Edge #MustangPanda
-----------------🚨 DHS Agents Doxxed: ICE List Leaks Thousands of Federal Employee Details 🚨
A whistleblower allegedly leaked data on ~4,500 DHS employees (ICE, Border Patrol) to a site called ICE List, exposing names, emails, phone numbers, and job info. While some data came from scraping LinkedIn, centralizing it creates a dangerous attack surface for harassment and phishing. Meta is now blocking links to the site across all platforms.
Sources:
- https://x.com/justabreach/status/2016059957452341347
- https://www.wired.com/story/meta-is-blocking-links-to-ice-list-on-facebook-instagram-and-threads/
- https://www.wired.com/story/ice-agents-are-doxing-themselves/
- https://www.police1.com/officer-safety/ice-list-doxxing-site-alleges-dhs-whistleblower-leaked-identities-of-4-500-agents
- https://www.scworld.com/brief/suspected-russian-ddos-attack-disrupts-ice-agent-data-leak-site#ICE #Minneapolis #Immigration #DOXED #BorderPatrol
----------------- -
💔 10M Dating App Users Exposed in Match Group Breach 💔
ShinyHunters cybercrime group claims to have stolen over 10 million records from Match Group (NASDAQ: MTCH), owner of Tinder, Hinge, Match.com, and OkCupid. The alleged breach, posted January 28, 2026, includes user behavioral data from Appsflyer analytics (swipes, matches, sessions, geo-locations), hundreds of internal corporate documents, and highly sensitive personal information including romantic preferences. The 1.76GB compressed dump appears linked to ShinyHunters' broader Okta voice-phishing campaign that has already compromised Crunchbase, Betterment, and SoundCloud.
Sources:
- https://x.com/justabreach/status/2016436843164696661
- https://www.ransomware.live/id/TWF0Y2ggR3JvdXBAc2hpbnlodW50ZXJz
- https://cybernews.com/security/hinge-okcupid-data-leak-shinyhunters-claims/
- https://darknetsearch.com/knowledge/news/en/match-group-leak-2026-urgent-data-breach-impact-guide/
- https://www.binance.com/en/square/post/01-28-2026-data-breach-exposes-millions-of-user-records-from-dating-apps-35696579060105#Tinder #PlentyofFish #Hinge #OKCupid #Match.com
-----------------🐴 Chinese APT Upgrades Backdoor with Browser Stealers 🐼
|Chinese espionage group Mustang Panda (aka HoneyMyte) has updated its CoolClient backdoor to steal login credentials from Chrome, Edge, and Chromium-based browsers while monitoring clipboard activity. Kaspersky researchers observed the malware targeting government entities in Myanmar, Mongolia, Malaysia, Russia, and Pakistan throughout 2025. The backdoor was deployed via compromised legitimate software from Sangfor, a Chinese cybersecurity company, and uses hardcoded API tokens for Google Drive and Pixeldrain to exfiltrate stolen data.
Sources:
- https://www.bleepingcomputer.com/news/security/chinese-mustang-panda-hackers-deploy-infostealers-via-coolclient-backdoor/
- https://securelist.com/honeymyte-updates-coolclient-uses-browser-stealers-and-scripts/118664/#China #CoolClinet #Chrome #Edge #MustangPanda
-----------------🚨 DHS Agents Doxxed: ICE List Leaks Thousands of Federal Employee Details 🚨
A whistleblower allegedly leaked data on ~4,500 DHS employees (ICE, Border Patrol) to a site called ICE List, exposing names, emails, phone numbers, and job info. While some data came from scraping LinkedIn, centralizing it creates a dangerous attack surface for harassment and phishing. Meta is now blocking links to the site across all platforms.
Sources:
- https://x.com/justabreach/status/2016059957452341347
- https://www.wired.com/story/meta-is-blocking-links-to-ice-list-on-facebook-instagram-and-threads/
- https://www.wired.com/story/ice-agents-are-doxing-themselves/
- https://www.police1.com/officer-safety/ice-list-doxxing-site-alleges-dhs-whistleblower-leaked-identities-of-4-500-agents
- https://www.scworld.com/brief/suspected-russian-ddos-attack-disrupts-ice-agent-data-leak-site#ICE #Minneapolis #Immigration #DOXED #BorderPatrol
----------------- -
💔 10M Dating App Users Exposed in Match Group Breach 💔
ShinyHunters cybercrime group claims to have stolen over 10 million records from Match Group (NASDAQ: MTCH), owner of Tinder, Hinge, Match.com, and OkCupid. The alleged breach, posted January 28, 2026, includes user behavioral data from Appsflyer analytics (swipes, matches, sessions, geo-locations), hundreds of internal corporate documents, and highly sensitive personal information including romantic preferences. The 1.76GB compressed dump appears linked to ShinyHunters' broader Okta voice-phishing campaign that has already compromised Crunchbase, Betterment, and SoundCloud.
Sources:
- https://x.com/justabreach/status/2016436843164696661
- https://www.ransomware.live/id/TWF0Y2ggR3JvdXBAc2hpbnlodW50ZXJz
- https://cybernews.com/security/hinge-okcupid-data-leak-shinyhunters-claims/
- https://darknetsearch.com/knowledge/news/en/match-group-leak-2026-urgent-data-breach-impact-guide/
- https://www.binance.com/en/square/post/01-28-2026-data-breach-exposes-millions-of-user-records-from-dating-apps-35696579060105#Tinder #PlentyofFish #Hinge #OKCupid #Match.com
-----------------🐴 Chinese APT Upgrades Backdoor with Browser Stealers 🐼
|Chinese espionage group Mustang Panda (aka HoneyMyte) has updated its CoolClient backdoor to steal login credentials from Chrome, Edge, and Chromium-based browsers while monitoring clipboard activity. Kaspersky researchers observed the malware targeting government entities in Myanmar, Mongolia, Malaysia, Russia, and Pakistan throughout 2025. The backdoor was deployed via compromised legitimate software from Sangfor, a Chinese cybersecurity company, and uses hardcoded API tokens for Google Drive and Pixeldrain to exfiltrate stolen data.
Sources:
- https://www.bleepingcomputer.com/news/security/chinese-mustang-panda-hackers-deploy-infostealers-via-coolclient-backdoor/
- https://securelist.com/honeymyte-updates-coolclient-uses-browser-stealers-and-scripts/118664/#China #CoolClinet #Chrome #Edge #MustangPanda
-----------------🚨 DHS Agents Doxxed: ICE List Leaks Thousands of Federal Employee Details 🚨
A whistleblower allegedly leaked data on ~4,500 DHS employees (ICE, Border Patrol) to a site called ICE List, exposing names, emails, phone numbers, and job info. While some data came from scraping LinkedIn, centralizing it creates a dangerous attack surface for harassment and phishing. Meta is now blocking links to the site across all platforms.
Sources:
- https://x.com/justabreach/status/2016059957452341347
- https://www.wired.com/story/meta-is-blocking-links-to-ice-list-on-facebook-instagram-and-threads/
- https://www.wired.com/story/ice-agents-are-doxing-themselves/
- https://www.police1.com/officer-safety/ice-list-doxxing-site-alleges-dhs-whistleblower-leaked-identities-of-4-500-agents
- https://www.scworld.com/brief/suspected-russian-ddos-attack-disrupts-ice-agent-data-leak-site#ICE #Minneapolis #Immigration #DOXED #BorderPatrol
----------------- -
💔 10M Dating App Users Exposed in Match Group Breach 💔
ShinyHunters cybercrime group claims to have stolen over 10 million records from Match Group (NASDAQ: MTCH), owner of Tinder, Hinge, Match.com, and OkCupid. The alleged breach, posted January 28, 2026, includes user behavioral data from Appsflyer analytics (swipes, matches, sessions, geo-locations), hundreds of internal corporate documents, and highly sensitive personal information including romantic preferences. The 1.76GB compressed dump appears linked to ShinyHunters' broader Okta voice-phishing campaign that has already compromised Crunchbase, Betterment, and SoundCloud.
Sources:
- https://x.com/justabreach/status/2016436843164696661
- https://www.ransomware.live/id/TWF0Y2ggR3JvdXBAc2hpbnlodW50ZXJz
- https://cybernews.com/security/hinge-okcupid-data-leak-shinyhunters-claims/
- https://darknetsearch.com/knowledge/news/en/match-group-leak-2026-urgent-data-breach-impact-guide/
- https://www.binance.com/en/square/post/01-28-2026-data-breach-exposes-millions-of-user-records-from-dating-apps-35696579060105#Tinder #PlentyofFish #Hinge #OKCupid #Match.com
-----------------🐴 Chinese APT Upgrades Backdoor with Browser Stealers 🐼
|Chinese espionage group Mustang Panda (aka HoneyMyte) has updated its CoolClient backdoor to steal login credentials from Chrome, Edge, and Chromium-based browsers while monitoring clipboard activity. Kaspersky researchers observed the malware targeting government entities in Myanmar, Mongolia, Malaysia, Russia, and Pakistan throughout 2025. The backdoor was deployed via compromised legitimate software from Sangfor, a Chinese cybersecurity company, and uses hardcoded API tokens for Google Drive and Pixeldrain to exfiltrate stolen data.
Sources:
- https://www.bleepingcomputer.com/news/security/chinese-mustang-panda-hackers-deploy-infostealers-via-coolclient-backdoor/
- https://securelist.com/honeymyte-updates-coolclient-uses-browser-stealers-and-scripts/118664/#China #CoolClinet #Chrome #Edge #MustangPanda
-----------------🚨 DHS Agents Doxxed: ICE List Leaks Thousands of Federal Employee Details 🚨
A whistleblower allegedly leaked data on ~4,500 DHS employees (ICE, Border Patrol) to a site called ICE List, exposing names, emails, phone numbers, and job info. While some data came from scraping LinkedIn, centralizing it creates a dangerous attack surface for harassment and phishing. Meta is now blocking links to the site across all platforms.
Sources:
- https://x.com/justabreach/status/2016059957452341347
- https://www.wired.com/story/meta-is-blocking-links-to-ice-list-on-facebook-instagram-and-threads/
- https://www.wired.com/story/ice-agents-are-doxing-themselves/
- https://www.police1.com/officer-safety/ice-list-doxxing-site-alleges-dhs-whistleblower-leaked-identities-of-4-500-agents
- https://www.scworld.com/brief/suspected-russian-ddos-attack-disrupts-ice-agent-data-leak-site#ICE #Minneapolis #Immigration #DOXED #BorderPatrol
----------------- -
💔 10M Dating App Users Exposed in Match Group Breach 💔
ShinyHunters cybercrime group claims to have stolen over 10 million records from Match Group (NASDAQ: MTCH), owner of Tinder, Hinge, Match.com, and OkCupid. The alleged breach, posted January 28, 2026, includes user behavioral data from Appsflyer analytics (swipes, matches, sessions, geo-locations), hundreds of internal corporate documents, and highly sensitive personal information including romantic preferences. The 1.76GB compressed dump appears linked to ShinyHunters' broader Okta voice-phishing campaign that has already compromised Crunchbase, Betterment, and SoundCloud.
Sources:
- https://x.com/justabreach/status/2016436843164696661
- https://www.ransomware.live/id/TWF0Y2ggR3JvdXBAc2hpbnlodW50ZXJz
- https://cybernews.com/security/hinge-okcupid-data-leak-shinyhunters-claims/
- https://darknetsearch.com/knowledge/news/en/match-group-leak-2026-urgent-data-breach-impact-guide/
- https://www.binance.com/en/square/post/01-28-2026-data-breach-exposes-millions-of-user-records-from-dating-apps-35696579060105#Tinder #PlentyofFish #Hinge #OKCupid #Match.com
-----------------🐴 Chinese APT Upgrades Backdoor with Browser Stealers 🐼
|Chinese espionage group Mustang Panda (aka HoneyMyte) has updated its CoolClient backdoor to steal login credentials from Chrome, Edge, and Chromium-based browsers while monitoring clipboard activity. Kaspersky researchers observed the malware targeting government entities in Myanmar, Mongolia, Malaysia, Russia, and Pakistan throughout 2025. The backdoor was deployed via compromised legitimate software from Sangfor, a Chinese cybersecurity company, and uses hardcoded API tokens for Google Drive and Pixeldrain to exfiltrate stolen data.
Sources:
- https://www.bleepingcomputer.com/news/security/chinese-mustang-panda-hackers-deploy-infostealers-via-coolclient-backdoor/
- https://securelist.com/honeymyte-updates-coolclient-uses-browser-stealers-and-scripts/118664/#China #CoolClinet #Chrome #Edge #MustangPanda
-----------------🚨 DHS Agents Doxxed: ICE List Leaks Thousands of Federal Employee Details 🚨
A whistleblower allegedly leaked data on ~4,500 DHS employees (ICE, Border Patrol) to a site called ICE List, exposing names, emails, phone numbers, and job info. While some data came from scraping LinkedIn, centralizing it creates a dangerous attack surface for harassment and phishing. Meta is now blocking links to the site across all platforms.
Sources:
- https://x.com/justabreach/status/2016059957452341347
- https://www.wired.com/story/meta-is-blocking-links-to-ice-list-on-facebook-instagram-and-threads/
- https://www.wired.com/story/ice-agents-are-doxing-themselves/
- https://www.police1.com/officer-safety/ice-list-doxxing-site-alleges-dhs-whistleblower-leaked-identities-of-4-500-agents
- https://www.scworld.com/brief/suspected-russian-ddos-attack-disrupts-ice-agent-data-leak-site#ICE #Minneapolis #Immigration #DOXED #BorderPatrol
----------------- -
📢⚠️ The China-linked notorious Mustang Panda group is using #Venezuela related news lure to deliver #LOTUSLITE backdoor against US govt targets in a cyberespionage campaign.
Read: https://hackread.com/mastang-panda-venezuela-news-lotuslite-malware/
-
📢⚠️ The China-linked notorious Mustang Panda group is using #Venezuela related news lure to deliver #LOTUSLITE backdoor against US govt targets in a cyberespionage campaign.
Read: https://hackread.com/mastang-panda-venezuela-news-lotuslite-malware/
-
📢⚠️ The China-linked notorious Mustang Panda group is using #Venezuela related news lure to deliver #LOTUSLITE backdoor against US govt targets in a cyberespionage campaign.
Read: https://hackread.com/mastang-panda-venezuela-news-lotuslite-malware/
-
📢⚠️ The China-linked notorious Mustang Panda group is using #Venezuela related news lure to deliver #LOTUSLITE backdoor against US govt targets in a cyberespionage campaign.
Read: https://hackread.com/mastang-panda-venezuela-news-lotuslite-malware/
-
📢⚠️ The China-linked notorious Mustang Panda group is using #Venezuela related news lure to deliver #LOTUSLITE backdoor against US govt targets in a cyberespionage campaign.
Read: https://hackread.com/mastang-panda-venezuela-news-lotuslite-malware/
-
HoneyMyte aka Mustang Panda is using a signed rootkit to drop the #ToneShell backdoor in ongoing attacks, hiding its activity from security tools and giving attackers remote access to system.
Read: https://hackread.com/honeymyte-mustang-panda-toneshell-backdoor/
-
HoneyMyte aka Mustang Panda is using a signed rootkit to drop the #ToneShell backdoor in ongoing attacks, hiding its activity from security tools and giving attackers remote access to system.
Read: https://hackread.com/honeymyte-mustang-panda-toneshell-backdoor/
-
HoneyMyte aka Mustang Panda is using a signed rootkit to drop the #ToneShell backdoor in ongoing attacks, hiding its activity from security tools and giving attackers remote access to system.
Read: https://hackread.com/honeymyte-mustang-panda-toneshell-backdoor/
-
HoneyMyte aka Mustang Panda is using a signed rootkit to drop the #ToneShell backdoor in ongoing attacks, hiding its activity from security tools and giving attackers remote access to system.
Read: https://hackread.com/honeymyte-mustang-panda-toneshell-backdoor/