#spearphishing — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #spearphishing, aggregated by home.social.
-
Half of New Zealand agencies miss email security bar https://www.byteseu.com/2343451/ #AsiaPacific #BusinessEmailCompromise #Compliance #cybersecurity #DigitalIdentity #DigitalTrust #DMARC #EmailSecurity #EnergySector #infosec #MinistryOfDefence(MOD) #NationalCyberSecurityCentre(NCSC) #NewZealand #NewZealand(NZ) #NewZealandGovernment #Phishing #Proofpoint #PublicSector #Risk&Compliance #SpearPhishing #ThreatLandscape #trade
-
Iranian Hackers Deploy Cross-Platform Malware via Coding Tests
Iranian hackers are using clever tactics to deploy cross-platform malware, disguising it as coding challenges on LinkedIn and other job search platforms to trick developers into installing the threat. This malware, tracked as NodeRabbit and PollCat, can infect Windows, Linux, and macOS workstations, allowing hackers to gain remote…
#IranianHackers #Noderabbit #CrossplatformMalware #Spearphishing #Linkedin
-
Recent Kimsuky spear phishing campaigns abuse remote control tools and AI extensions to target victims in Japan and South Korea. Read the full analysis.
#Kimsuky #CyberSecurity #SpearPhishing #Malware #ThreatIntel
-
Recent Kimsuky spear phishing campaigns abuse remote control tools and AI extensions to target victims in Japan and South Korea. Read the full analysis.
#Kimsuky #CyberSecurity #SpearPhishing #Malware #ThreatIntel
-
Recent Kimsuky spear phishing campaigns abuse remote control tools and AI extensions to target victims in Japan and South Korea. Read the full analysis.
#Kimsuky #CyberSecurity #SpearPhishing #Malware #ThreatIntel
-
Recent Kimsuky spear phishing campaigns abuse remote control tools and AI extensions to target victims in Japan and South Korea. Read the full analysis.
#Kimsuky #CyberSecurity #SpearPhishing #Malware #ThreatIntel
-
July 2026 Threat Trend Report on APT Attacks (South Korea)
During July 2026, multiple APT campaigns targeted entities in South Korea primarily through spear phishing attacks utilizing LNK files. Seven distinct attack types (A through G) were identified, each employing different techniques including PowerShell scripts, AutoIt programs, curl.exe downloads, and DLL side-loading. Attackers distributed malware through platforms like GitHub, Google Drive, and Dropbox, often disguised as legitimate documents or resumes. These campaigns deployed backdoors, infostealers, keyloggers, and XenoRAT malware to exfiltrate system information, credentials, virtual asset data, and maintain persistent access through Task Scheduler entries. Communications occurred via PubNub channels with data encoded in Base64. The attacks primarily began with phishing emails containing work-related content designed to deceive specific victims into executing malicious files.
Pulse ID: 6a91687da8e6cd5cc16f64a6
Pulse Link: https://otx.alienvault.com/pulse/6a91687da8e6cd5cc16f64a6
Pulse Author: AlienVault
Created: 2026-08-28 10:52:45Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Autoit #BackDoor #CyberSecurity #Dropbox #Email #GitHub #Google #InfoSec #InfoStealer #KeyLogger #Korea #LNK #Malware #OTX #OpenThreatExchange #Phishing #PowerShell #RAT #SouthKorea #SpearPhishing #bot #AlienVault
-
July 2026 Threat Trend Report on APT Attacks (South Korea)
During July 2026, multiple APT campaigns targeted entities in South Korea primarily through spear phishing attacks utilizing LNK files. Seven distinct attack types (A through G) were identified, each employing different techniques including PowerShell scripts, AutoIt programs, curl.exe downloads, and DLL side-loading. Attackers distributed malware through platforms like GitHub, Google Drive, and Dropbox, often disguised as legitimate documents or resumes. These campaigns deployed backdoors, infostealers, keyloggers, and XenoRAT malware to exfiltrate system information, credentials, virtual asset data, and maintain persistent access through Task Scheduler entries. Communications occurred via PubNub channels with data encoded in Base64. The attacks primarily began with phishing emails containing work-related content designed to deceive specific victims into executing malicious files.
Pulse ID: 6a91687da8e6cd5cc16f64a6
Pulse Link: https://otx.alienvault.com/pulse/6a91687da8e6cd5cc16f64a6
Pulse Author: AlienVault
Created: 2026-08-28 10:52:45Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Autoit #BackDoor #CyberSecurity #Dropbox #Email #GitHub #Google #InfoSec #InfoStealer #KeyLogger #Korea #LNK #Malware #OTX #OpenThreatExchange #Phishing #PowerShell #RAT #SouthKorea #SpearPhishing #bot #AlienVault
-
July 2026 Threat Trend Report on APT Attacks (South Korea)
During July 2026, multiple APT campaigns targeted entities in South Korea primarily through spear phishing attacks utilizing LNK files. Seven distinct attack types (A through G) were identified, each employing different techniques including PowerShell scripts, AutoIt programs, curl.exe downloads, and DLL side-loading. Attackers distributed malware through platforms like GitHub, Google Drive, and Dropbox, often disguised as legitimate documents or resumes. These campaigns deployed backdoors, infostealers, keyloggers, and XenoRAT malware to exfiltrate system information, credentials, virtual asset data, and maintain persistent access through Task Scheduler entries. Communications occurred via PubNub channels with data encoded in Base64. The attacks primarily began with phishing emails containing work-related content designed to deceive specific victims into executing malicious files.
Pulse ID: 6a91687da8e6cd5cc16f64a6
Pulse Link: https://otx.alienvault.com/pulse/6a91687da8e6cd5cc16f64a6
Pulse Author: AlienVault
Created: 2026-08-28 10:52:45Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Autoit #BackDoor #CyberSecurity #Dropbox #Email #GitHub #Google #InfoSec #InfoStealer #KeyLogger #Korea #LNK #Malware #OTX #OpenThreatExchange #Phishing #PowerShell #RAT #SouthKorea #SpearPhishing #bot #AlienVault
-
July 2026 Threat Trend Report on APT Attacks (South Korea)
During July 2026, multiple APT campaigns targeted entities in South Korea primarily through spear phishing attacks utilizing LNK files. Seven distinct attack types (A through G) were identified, each employing different techniques including PowerShell scripts, AutoIt programs, curl.exe downloads, and DLL side-loading. Attackers distributed malware through platforms like GitHub, Google Drive, and Dropbox, often disguised as legitimate documents or resumes. These campaigns deployed backdoors, infostealers, keyloggers, and XenoRAT malware to exfiltrate system information, credentials, virtual asset data, and maintain persistent access through Task Scheduler entries. Communications occurred via PubNub channels with data encoded in Base64. The attacks primarily began with phishing emails containing work-related content designed to deceive specific victims into executing malicious files.
Pulse ID: 6a91687da8e6cd5cc16f64a6
Pulse Link: https://otx.alienvault.com/pulse/6a91687da8e6cd5cc16f64a6
Pulse Author: AlienVault
Created: 2026-08-28 10:52:45Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Autoit #BackDoor #CyberSecurity #Dropbox #Email #GitHub #Google #InfoSec #InfoStealer #KeyLogger #Korea #LNK #Malware #OTX #OpenThreatExchange #Phishing #PowerShell #RAT #SouthKorea #SpearPhishing #bot #AlienVault
-
July 2026 Threat Trend Report on APT Attacks (South Korea)
During July 2026, multiple APT campaigns targeted entities in South Korea primarily through spear phishing attacks utilizing LNK files. Seven distinct attack types (A through G) were identified, each employing different techniques including PowerShell scripts, AutoIt programs, curl.exe downloads, and DLL side-loading. Attackers distributed malware through platforms like GitHub, Google Drive, and Dropbox, often disguised as legitimate documents or resumes. These campaigns deployed backdoors, infostealers, keyloggers, and XenoRAT malware to exfiltrate system information, credentials, virtual asset data, and maintain persistent access through Task Scheduler entries. Communications occurred via PubNub channels with data encoded in Base64. The attacks primarily began with phishing emails containing work-related content designed to deceive specific victims into executing malicious files.
Pulse ID: 6a91687da8e6cd5cc16f64a6
Pulse Link: https://otx.alienvault.com/pulse/6a91687da8e6cd5cc16f64a6
Pulse Author: AlienVault
Created: 2026-08-28 10:52:45Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Autoit #BackDoor #CyberSecurity #Dropbox #Email #GitHub #Google #InfoSec #InfoStealer #KeyLogger #Korea #LNK #Malware #OTX #OpenThreatExchange #Phishing #PowerShell #RAT #SouthKorea #SpearPhishing #bot #AlienVault
-
📢 Des hackers soutenus par des États ciblent des hauts fonctionnaires de l'UE via WhatsApp
Le CERT-EU (EU Computer Emergency Response Team) a formellement identifié des campagnes de spearphishing étatique ciblant des hauts fonctionnaires de l'Union européenne via des applications de messagerie, notamment WhatsApp et Signal.
📖 cyberveille : https://cyberveille.ch/posts/2026-08-27-des-hackers-soutenus-par-des-etats-ciblent-des-hauts-fonctionnaires-de-l-ue-via-whatsapp/
🌐 source : https://www.politico.eu/article/hackers-target-eu-officials-whatsapp/
🟢 vérification factuelle haute
#CERTEU #spearphishing #Cyberveille -
Inside Kimsuky's Abuse of Legitimate Remote Control Tools Across Northeast Asia
Kimsuky conducted spear phishing campaigns against South Korean and Japanese targets during the first half of 2026, distributing LNK malware through OneDrive share links. The malicious files established scheduled tasks that periodically fetched PowerShell scripts from command-and-control servers to profile systems, exfiltrate Thunderbird and Outlook email data, and log keystrokes. The threat actor installed legitimate remote control software including Chrome Remote Desktop and AnyDesk to evade antivirus detection and maintain multiple access channels. A malicious Chrome extension designed to steal Gmail data exhibited characteristics of AI-generated code, featuring Korean comments, debug strings, and Unicode emoji throughout. The operation employed rotating infrastructure and compromised legitimate Korean servers as command-and-control nodes to impede tracking efforts.
Pulse ID: 6a873495a873c0ec3c6d9880
Pulse Link: https://otx.alienvault.com/pulse/6a873495a873c0ec3c6d9880
Pulse Author: AlienVault
Created: 2026-08-20 17:08:37Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#AnyDesk #Asia #Chrome #ChromeExtension #CyberSecurity #EDR #Email #ICS #InfoSec #Japan #Kimsuky #Korea #LNK #Malware #OTX #OpenThreatExchange #Outlook #Phishing #PowerShell #RAT #SouthKorea #SpearPhishing #UK #bot #AlienVault
-
Inside Kimsuky's Abuse of Legitimate Remote Control Tools Across Northeast Asia
Kimsuky conducted spear phishing campaigns against South Korean and Japanese targets during the first half of 2026, distributing LNK malware through OneDrive share links. The malicious files established scheduled tasks that periodically fetched PowerShell scripts from command-and-control servers to profile systems, exfiltrate Thunderbird and Outlook email data, and log keystrokes. The threat actor installed legitimate remote control software including Chrome Remote Desktop and AnyDesk to evade antivirus detection and maintain multiple access channels. A malicious Chrome extension designed to steal Gmail data exhibited characteristics of AI-generated code, featuring Korean comments, debug strings, and Unicode emoji throughout. The operation employed rotating infrastructure and compromised legitimate Korean servers as command-and-control nodes to impede tracking efforts.
Pulse ID: 6a873495a873c0ec3c6d9880
Pulse Link: https://otx.alienvault.com/pulse/6a873495a873c0ec3c6d9880
Pulse Author: AlienVault
Created: 2026-08-20 17:08:37Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#AnyDesk #Asia #Chrome #ChromeExtension #CyberSecurity #EDR #Email #ICS #InfoSec #Japan #Kimsuky #Korea #LNK #Malware #OTX #OpenThreatExchange #Outlook #Phishing #PowerShell #RAT #SouthKorea #SpearPhishing #UK #bot #AlienVault
-
Inside Kimsuky's Abuse of Legitimate Remote Control Tools Across Northeast Asia
Kimsuky conducted spear phishing campaigns against South Korean and Japanese targets during the first half of 2026, distributing LNK malware through OneDrive share links. The malicious files established scheduled tasks that periodically fetched PowerShell scripts from command-and-control servers to profile systems, exfiltrate Thunderbird and Outlook email data, and log keystrokes. The threat actor installed legitimate remote control software including Chrome Remote Desktop and AnyDesk to evade antivirus detection and maintain multiple access channels. A malicious Chrome extension designed to steal Gmail data exhibited characteristics of AI-generated code, featuring Korean comments, debug strings, and Unicode emoji throughout. The operation employed rotating infrastructure and compromised legitimate Korean servers as command-and-control nodes to impede tracking efforts.
Pulse ID: 6a873495a873c0ec3c6d9880
Pulse Link: https://otx.alienvault.com/pulse/6a873495a873c0ec3c6d9880
Pulse Author: AlienVault
Created: 2026-08-20 17:08:37Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#AnyDesk #Asia #Chrome #ChromeExtension #CyberSecurity #EDR #Email #ICS #InfoSec #Japan #Kimsuky #Korea #LNK #Malware #OTX #OpenThreatExchange #Outlook #Phishing #PowerShell #RAT #SouthKorea #SpearPhishing #UK #bot #AlienVault
-
Inside Kimsuky's Abuse of Legitimate Remote Control Tools Across Northeast Asia
Kimsuky conducted spear phishing campaigns against South Korean and Japanese targets during the first half of 2026, distributing LNK malware through OneDrive share links. The malicious files established scheduled tasks that periodically fetched PowerShell scripts from command-and-control servers to profile systems, exfiltrate Thunderbird and Outlook email data, and log keystrokes. The threat actor installed legitimate remote control software including Chrome Remote Desktop and AnyDesk to evade antivirus detection and maintain multiple access channels. A malicious Chrome extension designed to steal Gmail data exhibited characteristics of AI-generated code, featuring Korean comments, debug strings, and Unicode emoji throughout. The operation employed rotating infrastructure and compromised legitimate Korean servers as command-and-control nodes to impede tracking efforts.
Pulse ID: 6a873495a873c0ec3c6d9880
Pulse Link: https://otx.alienvault.com/pulse/6a873495a873c0ec3c6d9880
Pulse Author: AlienVault
Created: 2026-08-20 17:08:37Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#AnyDesk #Asia #Chrome #ChromeExtension #CyberSecurity #EDR #Email #ICS #InfoSec #Japan #Kimsuky #Korea #LNK #Malware #OTX #OpenThreatExchange #Outlook #Phishing #PowerShell #RAT #SouthKorea #SpearPhishing #UK #bot #AlienVault
-
Inside Kimsuky's Abuse of Legitimate Remote Control Tools Across Northeast Asia
Kimsuky conducted spear phishing campaigns against South Korean and Japanese targets during the first half of 2026, distributing LNK malware through OneDrive share links. The malicious files established scheduled tasks that periodically fetched PowerShell scripts from command-and-control servers to profile systems, exfiltrate Thunderbird and Outlook email data, and log keystrokes. The threat actor installed legitimate remote control software including Chrome Remote Desktop and AnyDesk to evade antivirus detection and maintain multiple access channels. A malicious Chrome extension designed to steal Gmail data exhibited characteristics of AI-generated code, featuring Korean comments, debug strings, and Unicode emoji throughout. The operation employed rotating infrastructure and compromised legitimate Korean servers as command-and-control nodes to impede tracking efforts.
Pulse ID: 6a873495a873c0ec3c6d9880
Pulse Link: https://otx.alienvault.com/pulse/6a873495a873c0ec3c6d9880
Pulse Author: AlienVault
Created: 2026-08-20 17:08:37Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#AnyDesk #Asia #Chrome #ChromeExtension #CyberSecurity #EDR #Email #ICS #InfoSec #Japan #Kimsuky #Korea #LNK #Malware #OTX #OpenThreatExchange #Outlook #Phishing #PowerShell #RAT #SouthKorea #SpearPhishing #UK #bot #AlienVault
-
SilkParasite: Tracking a China-Nexus APT Across Central Asia
SilkParasite is a cyberespionage operation assessed with medium confidence as China-nexus that targeted government bodies across Central Asia. Seven remote access tool families were deployed, five of which were previously undocumented: DriveSilkRAT, CookiETagRAT, NomadRAT, GoginRAT, and NodeEdgeRAT. The toolset is small, modular, and professionally engineered with traces of AI-assisted development. Initial access occurred through malicious Microsoft Office documents delivered via spear-phishing, using regionally tailored lures impersonating government ministries. The operation leveraged DLL sideloading as the primary delivery mechanism and used Google Drive for command-and-control communications to hide within trusted services. Infrastructure analysis identified connections to China Unicom's backbone network, and operational patterns suggest a functioning software organization with maintained build pipelines and careful operational security.
Pulse ID: 6a86a70eb8b57f155e62d4f7
Pulse Link: https://otx.alienvault.com/pulse/6a86a70eb8b57f155e62d4f7
Pulse Author: AlienVault
Created: 2026-08-20 07:04:46Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Asia #CentralAsia #China #CyberSecurity #Cyberespionage #DRat #Edge #Espionage #Google #Government #InfoSec #Microsoft #MicrosoftOffice #OTX #Office #OpenThreatExchange #Phishing #RAT #Rust #SideLoading #SpearPhishing #bot #AlienVault
-
SilkParasite: Tracking a China-Nexus APT Across Central Asia
SilkParasite is a cyberespionage operation assessed with medium confidence as China-nexus that targeted government bodies across Central Asia. Seven remote access tool families were deployed, five of which were previously undocumented: DriveSilkRAT, CookiETagRAT, NomadRAT, GoginRAT, and NodeEdgeRAT. The toolset is small, modular, and professionally engineered with traces of AI-assisted development. Initial access occurred through malicious Microsoft Office documents delivered via spear-phishing, using regionally tailored lures impersonating government ministries. The operation leveraged DLL sideloading as the primary delivery mechanism and used Google Drive for command-and-control communications to hide within trusted services. Infrastructure analysis identified connections to China Unicom's backbone network, and operational patterns suggest a functioning software organization with maintained build pipelines and careful operational security.
Pulse ID: 6a86a70eb8b57f155e62d4f7
Pulse Link: https://otx.alienvault.com/pulse/6a86a70eb8b57f155e62d4f7
Pulse Author: AlienVault
Created: 2026-08-20 07:04:46Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Asia #CentralAsia #China #CyberSecurity #Cyberespionage #DRat #Edge #Espionage #Google #Government #InfoSec #Microsoft #MicrosoftOffice #OTX #Office #OpenThreatExchange #Phishing #RAT #Rust #SideLoading #SpearPhishing #bot #AlienVault
-
SilkParasite: Tracking a China-Nexus APT Across Central Asia
SilkParasite is a cyberespionage operation assessed with medium confidence as China-nexus that targeted government bodies across Central Asia. Seven remote access tool families were deployed, five of which were previously undocumented: DriveSilkRAT, CookiETagRAT, NomadRAT, GoginRAT, and NodeEdgeRAT. The toolset is small, modular, and professionally engineered with traces of AI-assisted development. Initial access occurred through malicious Microsoft Office documents delivered via spear-phishing, using regionally tailored lures impersonating government ministries. The operation leveraged DLL sideloading as the primary delivery mechanism and used Google Drive for command-and-control communications to hide within trusted services. Infrastructure analysis identified connections to China Unicom's backbone network, and operational patterns suggest a functioning software organization with maintained build pipelines and careful operational security.
Pulse ID: 6a86a70eb8b57f155e62d4f7
Pulse Link: https://otx.alienvault.com/pulse/6a86a70eb8b57f155e62d4f7
Pulse Author: AlienVault
Created: 2026-08-20 07:04:46Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Asia #CentralAsia #China #CyberSecurity #Cyberespionage #DRat #Edge #Espionage #Google #Government #InfoSec #Microsoft #MicrosoftOffice #OTX #Office #OpenThreatExchange #Phishing #RAT #Rust #SideLoading #SpearPhishing #bot #AlienVault
-
SilkParasite: Tracking a China-Nexus APT Across Central Asia
SilkParasite is a cyberespionage operation assessed with medium confidence as China-nexus that targeted government bodies across Central Asia. Seven remote access tool families were deployed, five of which were previously undocumented: DriveSilkRAT, CookiETagRAT, NomadRAT, GoginRAT, and NodeEdgeRAT. The toolset is small, modular, and professionally engineered with traces of AI-assisted development. Initial access occurred through malicious Microsoft Office documents delivered via spear-phishing, using regionally tailored lures impersonating government ministries. The operation leveraged DLL sideloading as the primary delivery mechanism and used Google Drive for command-and-control communications to hide within trusted services. Infrastructure analysis identified connections to China Unicom's backbone network, and operational patterns suggest a functioning software organization with maintained build pipelines and careful operational security.
Pulse ID: 6a86a70eb8b57f155e62d4f7
Pulse Link: https://otx.alienvault.com/pulse/6a86a70eb8b57f155e62d4f7
Pulse Author: AlienVault
Created: 2026-08-20 07:04:46Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Asia #CentralAsia #China #CyberSecurity #Cyberespionage #DRat #Edge #Espionage #Google #Government #InfoSec #Microsoft #MicrosoftOffice #OTX #Office #OpenThreatExchange #Phishing #RAT #Rust #SideLoading #SpearPhishing #bot #AlienVault
-
SilkParasite: Tracking a China-Nexus APT Across Central Asia
SilkParasite is a cyberespionage operation assessed with medium confidence as China-nexus that targeted government bodies across Central Asia. Seven remote access tool families were deployed, five of which were previously undocumented: DriveSilkRAT, CookiETagRAT, NomadRAT, GoginRAT, and NodeEdgeRAT. The toolset is small, modular, and professionally engineered with traces of AI-assisted development. Initial access occurred through malicious Microsoft Office documents delivered via spear-phishing, using regionally tailored lures impersonating government ministries. The operation leveraged DLL sideloading as the primary delivery mechanism and used Google Drive for command-and-control communications to hide within trusted services. Infrastructure analysis identified connections to China Unicom's backbone network, and operational patterns suggest a functioning software organization with maintained build pipelines and careful operational security.
Pulse ID: 6a86a70eb8b57f155e62d4f7
Pulse Link: https://otx.alienvault.com/pulse/6a86a70eb8b57f155e62d4f7
Pulse Author: AlienVault
Created: 2026-08-20 07:04:46Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Asia #CentralAsia #China #CyberSecurity #Cyberespionage #DRat #Edge #Espionage #Google #Government #InfoSec #Microsoft #MicrosoftOffice #OTX #Office #OpenThreatExchange #Phishing #RAT #Rust #SideLoading #SpearPhishing #bot #AlienVault
-
Iran's Mabna Institute ran a 3-phase spearphishing campaign against university professors for a decade. The 50-page superseding indictmen...
Indicators extracted from public reporting. Source: https://www.reddit.com/r/netsec/comments/1vsrji8/irans_mabna_institute_ran_a_3phase_spearphishing/
Pulse ID: 6a85e02d9151a30aa821db6a
Pulse Link: https://otx.alienvault.com/pulse/6a85e02d9151a30aa821db6a
Pulse Author: CyberHunter_NL
Created: 2026-08-19 16:56:13Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #HTTP #HTTPS #InfoSec #Iran #OTX #OpenThreatExchange #Phishing #RCE #SpearPhishing #bot #CyberHunter_NL
-
Iran's Mabna Institute ran a 3-phase spearphishing campaign against university professors for a decade. The 50-page superseding indictmen...
Indicators extracted from public reporting. Source: https://www.reddit.com/r/netsec/comments/1vsrji8/irans_mabna_institute_ran_a_3phase_spearphishing/
Pulse ID: 6a85e02d9151a30aa821db6a
Pulse Link: https://otx.alienvault.com/pulse/6a85e02d9151a30aa821db6a
Pulse Author: CyberHunter_NL
Created: 2026-08-19 16:56:13Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #HTTP #HTTPS #InfoSec #Iran #OTX #OpenThreatExchange #Phishing #RCE #SpearPhishing #bot #CyberHunter_NL
-
Iran's Mabna Institute ran a 3-phase spearphishing campaign against university professors for a decade. The 50-page superseding indictmen...
Indicators extracted from public reporting. Source: https://www.reddit.com/r/netsec/comments/1vsrji8/irans_mabna_institute_ran_a_3phase_spearphishing/
Pulse ID: 6a85e02d9151a30aa821db6a
Pulse Link: https://otx.alienvault.com/pulse/6a85e02d9151a30aa821db6a
Pulse Author: CyberHunter_NL
Created: 2026-08-19 16:56:13Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #HTTP #HTTPS #InfoSec #Iran #OTX #OpenThreatExchange #Phishing #RCE #SpearPhishing #bot #CyberHunter_NL
-
Iran's Mabna Institute ran a 3-phase spearphishing campaign against university professors for a decade. The 50-page superseding indictmen...
Indicators extracted from public reporting. Source: https://www.reddit.com/r/netsec/comments/1vsrji8/irans_mabna_institute_ran_a_3phase_spearphishing/
Pulse ID: 6a85e02d9151a30aa821db6a
Pulse Link: https://otx.alienvault.com/pulse/6a85e02d9151a30aa821db6a
Pulse Author: CyberHunter_NL
Created: 2026-08-19 16:56:13Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #HTTP #HTTPS #InfoSec #Iran #OTX #OpenThreatExchange #Phishing #RCE #SpearPhishing #bot #CyberHunter_NL
-
Iran's Mabna Institute ran a 3-phase spearphishing campaign against university professors for a decade. The 50-page superseding indictmen...
Indicators extracted from public reporting. Source: https://www.reddit.com/r/netsec/comments/1vsrji8/irans_mabna_institute_ran_a_3phase_spearphishing/
Pulse ID: 6a85e02d9151a30aa821db6a
Pulse Link: https://otx.alienvault.com/pulse/6a85e02d9151a30aa821db6a
Pulse Author: CyberHunter_NL
Created: 2026-08-19 16:56:13Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #HTTP #HTTPS #InfoSec #Iran #OTX #OpenThreatExchange #Phishing #RCE #SpearPhishing #bot #CyberHunter_NL
-
#Cyberkriminelle nutzen #KI nicht nur zur Skalierung von #Phishing Mails, sondern auch zur Individualisierung - kombiniert mit #OSINT ein effektives Instrument, um Social Engineering voranzutreiben.
In einem groß angelegten Feldexperiment mit über 7.700 Beschäftigten der TU Braunschweig haben jetzt Forschende der TU Berlin, von Inria und der Ruhr-Universität Bochum getestet, wie gefährlich automatisiertes #Spearphishing mit Sprachmodellen wirklich ist:
https://www.usenix.org/system/files/conference/usenixsecurity26/sec26_prepub_czybik.pdf #cybersecurity
-
#Cyberkriminelle nutzen #KI nicht nur zur Skalierung von #Phishing Mails, sondern auch zur Individualisierung - kombiniert mit #OSINT ein effektives Instrument, um Social Engineering voranzutreiben.
In einem groß angelegten Feldexperiment mit über 7.700 Beschäftigten der TU Braunschweig haben jetzt Forschende der TU Berlin, von Inria und der Ruhr-Universität Bochum getestet, wie gefährlich automatisiertes #Spearphishing mit Sprachmodellen wirklich ist:
https://www.usenix.org/system/files/conference/usenixsecurity26/sec26_prepub_czybik.pdf #cybersecurity
-
#Cyberkriminelle nutzen #KI nicht nur zur Skalierung von #Phishing Mails, sondern auch zur Individualisierung - kombiniert mit #OSINT ein effektives Instrument, um Social Engineering voranzutreiben.
In einem groß angelegten Feldexperiment mit über 7.700 Beschäftigten der TU Braunschweig haben jetzt Forschende der TU Berlin, von Inria und der Ruhr-Universität Bochum getestet, wie gefährlich automatisiertes #Spearphishing mit Sprachmodellen wirklich ist:
https://www.usenix.org/system/files/conference/usenixsecurity26/sec26_prepub_czybik.pdf #cybersecurity
-
#Cyberkriminelle nutzen #KI nicht nur zur Skalierung von #Phishing Mails, sondern auch zur Individualisierung - kombiniert mit #OSINT ein effektives Instrument, um Social Engineering voranzutreiben.
In einem groß angelegten Feldexperiment mit über 7.700 Beschäftigten der TU Braunschweig haben jetzt Forschende der TU Berlin, von Inria und der Ruhr-Universität Bochum getestet, wie gefährlich automatisiertes #Spearphishing mit Sprachmodellen wirklich ist:
https://www.usenix.org/system/files/conference/usenixsecurity26/sec26_prepub_czybik.pdf #cybersecurity
-
#Cyberkriminelle nutzen #KI nicht nur zur Skalierung von #Phishing Mails, sondern auch zur Individualisierung - kombiniert mit #OSINT ein effektives Instrument, um Social Engineering voranzutreiben.
In einem groß angelegten Feldexperiment mit über 7.700 Beschäftigten der TU Braunschweig haben jetzt Forschende der TU Berlin, von Inria und der Ruhr-Universität Bochum getestet, wie gefährlich automatisiertes #Spearphishing mit Sprachmodellen wirklich ist:
https://www.usenix.org/system/files/conference/usenixsecurity26/sec26_prepub_czybik.pdf #cybersecurity
-
El lado del mal - Cómo los Agentes IA de Red Team hacen ataques de Ingeniería Social con Fake Accounts https://www.elladodelmal.com/2026/08/como-los-agentes-ia-de-red-team-hacen.html #IA #AI #AgenticAI #RedTeam #Hacking #Pentest #Pentesting #GitHub #SpearPhishing #IngenieriaSocial
-
El lado del mal - Cómo los Agentes IA de Red Team hacen ataques de Ingeniería Social con Fake Accounts https://www.elladodelmal.com/2026/08/como-los-agentes-ia-de-red-team-hacen.html #IA #AI #AgenticAI #RedTeam #Hacking #Pentest #Pentesting #GitHub #SpearPhishing #IngenieriaSocial
-
El lado del mal - Cómo los Agentes IA de Red Team hacen ataques de Ingeniería Social con Fake Accounts https://www.elladodelmal.com/2026/08/como-los-agentes-ia-de-red-team-hacen.html #IA #AI #AgenticAI #RedTeam #Hacking #Pentest #Pentesting #GitHub #SpearPhishing #IngenieriaSocial
-
El lado del mal - Cómo los Agentes IA de Red Team hacen ataques de Ingeniería Social con Fake Accounts https://www.elladodelmal.com/2026/08/como-los-agentes-ia-de-red-team-hacen.html #IA #AI #AgenticAI #RedTeam #Hacking #Pentest #Pentesting #GitHub #SpearPhishing #IngenieriaSocial
-
El lado del mal - Cómo los Agentes IA de Red Team hacen ataques de Ingeniería Social con Fake Accounts https://www.elladodelmal.com/2026/08/como-los-agentes-ia-de-red-team-hacen.html #IA #AI #AgenticAI #RedTeam #Hacking #Pentest #Pentesting #GitHub #SpearPhishing #IngenieriaSocial
-
Genians exposed Operation Capsule Vault, an APT37 campaign. The RokRAT malware hides inside a fake PDF to spy on academics and researchers.
-
Xiamen Empress Information Technology: come Pechino ha affittato account LINE per spiare giornalisti e attivisti a Taiwan
Le autorità taiwanesi hanno incriminato due imprenditori per aver affittato account LINE a Xiamen Empress Information Technology, usati da operatori legati a Pechino per impersonare giornalisti e colpire funzionari, accademici e attivisti. Il caso conferma le inchieste di ICIJ e Citizen Lab sulla repressione transnazionale cinese. -
Xiamen Empress Information Technology: come Pechino ha affittato account LINE per spiare giornalisti e attivisti a Taiwan
Le autorità taiwanesi hanno incriminato due imprenditori per aver affittato account LINE a Xiamen Empress Information Technology, usati da operatori legati a Pechino per impersonare giornalisti e colpire funzionari, accademici e attivisti. Il caso conferma le inchieste di ICIJ e Citizen Lab sulla repressione transnazionale cinese. -
Xiamen Empress Information Technology: come Pechino ha affittato account LINE per spiare giornalisti e attivisti a Taiwan
Le autorità taiwanesi hanno incriminato due imprenditori per aver affittato account LINE a Xiamen Empress Information Technology, usati da operatori legati a Pechino per impersonare giornalisti e colpire funzionari, accademici e attivisti. Il caso conferma le inchieste di ICIJ e Citizen Lab sulla repressione transnazionale cinese. -
Xiamen Empress Information Technology: come Pechino ha affittato account LINE per spiare giornalisti e attivisti a Taiwan
Le autorità taiwanesi hanno incriminato due imprenditori per aver affittato account LINE a Xiamen Empress Information Technology, usati da operatori legati a Pechino per impersonare giornalisti e colpire funzionari, accademici e attivisti. Il caso conferma le inchieste di ICIJ e Citizen Lab sulla repressione transnazionale cinese. -
Xiamen Empress Information Technology: come Pechino ha affittato account LINE per spiare giornalisti e attivisti a Taiwan
Le autorità taiwanesi hanno incriminato due imprenditori per aver affittato account LINE a Xiamen Empress Information Technology, usati da operatori legati a Pechino per impersonare giornalisti e colpire funzionari, accademici e attivisti. Il caso conferma le inchieste di ICIJ e Citizen Lab sulla repressione transnazionale cinese. -
Once, during an #awareness session, I brought a jar into the room.
One of those old-school glass jars with a metal lid.
I put it on the table and asked the executives (not the CISOs) to drop a poker chip inside.
Yes, poker chips. Don’t laugh. That’s what I had.
The value of each chip was supposed to reflect two things: perceived risk and willingness to spend.
At the beginning, the jar looked miserable.
Two or three 50s.
One brave 500.
Fewer than ten 100s.Then came lunch.
Paid for, obviously.
But lunch was also the exercise.Heavy #socialengineering. Casual conversation. Names, routines, vendors, habits, internal friction, travel plans, tools, weak points, ego, trust.
Then the last two hours began.
Real risk demonstration.#spearphishing built with information collected during lunch.
Fake WhatsApp chats after recon.
#OSINT before the session even restarted.
QR codes everywhere.Then we talked about recovery costs.
Regulatory fines.
Production downtime.
Loss of trust.
Reputational damage.
The unpleasant difference between “unlikely” and “not impossible”.And, magically, the jar filled up with 500 and 1000 chips.
You don’t fucking say.
My #Decoded for #Baited: https://blog.baited.io/2026/cost-of-phishing-shrinking-budgets/
-
Once, during an #awareness session, I brought a jar into the room.
One of those old-school glass jars with a metal lid.
I put it on the table and asked the executives (not the CISOs) to drop a poker chip inside.
Yes, poker chips. Don’t laugh. That’s what I had.
The value of each chip was supposed to reflect two things: perceived risk and willingness to spend.
At the beginning, the jar looked miserable.
Two or three 50s.
One brave 500.
Fewer than ten 100s.Then came lunch.
Paid for, obviously.
But lunch was also the exercise.Heavy #socialengineering. Casual conversation. Names, routines, vendors, habits, internal friction, travel plans, tools, weak points, ego, trust.
Then the last two hours began.
Real risk demonstration.#spearphishing built with information collected during lunch.
Fake WhatsApp chats after recon.
#OSINT before the session even restarted.
QR codes everywhere.Then we talked about recovery costs.
Regulatory fines.
Production downtime.
Loss of trust.
Reputational damage.
The unpleasant difference between “unlikely” and “not impossible”.And, magically, the jar filled up with 500 and 1000 chips.
You don’t fucking say.
My #Decoded for #Baited: https://blog.baited.io/2026/cost-of-phishing-shrinking-budgets/
-
Once, during an #awareness session, I brought a jar into the room.
One of those old-school glass jars with a metal lid.
I put it on the table and asked the executives (not the CISOs) to drop a poker chip inside.
Yes, poker chips. Don’t laugh. That’s what I had.
The value of each chip was supposed to reflect two things: perceived risk and willingness to spend.
At the beginning, the jar looked miserable.
Two or three 50s.
One brave 500.
Fewer than ten 100s.Then came lunch.
Paid for, obviously.
But lunch was also the exercise.Heavy #socialengineering. Casual conversation. Names, routines, vendors, habits, internal friction, travel plans, tools, weak points, ego, trust.
Then the last two hours began.
Real risk demonstration.#spearphishing built with information collected during lunch.
Fake WhatsApp chats after recon.
#OSINT before the session even restarted.
QR codes everywhere.Then we talked about recovery costs.
Regulatory fines.
Production downtime.
Loss of trust.
Reputational damage.
The unpleasant difference between “unlikely” and “not impossible”.And, magically, the jar filled up with 500 and 1000 chips.
You don’t fucking say.
My #Decoded for #Baited: https://blog.baited.io/2026/cost-of-phishing-shrinking-budgets/
-
Once, during an #awareness session, I brought a jar into the room.
One of those old-school glass jars with a metal lid.
I put it on the table and asked the executives (not the CISOs) to drop a poker chip inside.
Yes, poker chips. Don’t laugh. That’s what I had.
The value of each chip was supposed to reflect two things: perceived risk and willingness to spend.
At the beginning, the jar looked miserable.
Two or three 50s.
One brave 500.
Fewer than ten 100s.Then came lunch.
Paid for, obviously.
But lunch was also the exercise.Heavy #socialengineering. Casual conversation. Names, routines, vendors, habits, internal friction, travel plans, tools, weak points, ego, trust.
Then the last two hours began.
Real risk demonstration.#spearphishing built with information collected during lunch.
Fake WhatsApp chats after recon.
#OSINT before the session even restarted.
QR codes everywhere.Then we talked about recovery costs.
Regulatory fines.
Production downtime.
Loss of trust.
Reputational damage.
The unpleasant difference between “unlikely” and “not impossible”.And, magically, the jar filled up with 500 and 1000 chips.
You don’t fucking say.
My #Decoded for #Baited: https://blog.baited.io/2026/cost-of-phishing-shrinking-budgets/
-
Once, during an #awareness session, I brought a jar into the room.
One of those old-school glass jars with a metal lid.
I put it on the table and asked the executives (not the CISOs) to drop a poker chip inside.
Yes, poker chips. Don’t laugh. That’s what I had.
The value of each chip was supposed to reflect two things: perceived risk and willingness to spend.
At the beginning, the jar looked miserable.
Two or three 50s.
One brave 500.
Fewer than ten 100s.Then came lunch.
Paid for, obviously.
But lunch was also the exercise.Heavy #socialengineering. Casual conversation. Names, routines, vendors, habits, internal friction, travel plans, tools, weak points, ego, trust.
Then the last two hours began.
Real risk demonstration.#spearphishing built with information collected during lunch.
Fake WhatsApp chats after recon.
#OSINT before the session even restarted.
QR codes everywhere.Then we talked about recovery costs.
Regulatory fines.
Production downtime.
Loss of trust.
Reputational damage.
The unpleasant difference between “unlikely” and “not impossible”.And, magically, the jar filled up with 500 and 1000 chips.
You don’t fucking say.
My #Decoded for #Baited: https://blog.baited.io/2026/cost-of-phishing-shrinking-budgets/
-
https://www.europesays.com/si/142358/ Ena pika je bila dovolj: 41-letni računovodja goljufom nevede nakazal 5000 evrov #Business #DirektorskePrevare #Economic #FinančneGoljufije #IzobraževanjeZaposlenih #KibernetskaVarnost #Poslovni #PoslovniSvet #SI #Slovene #Slovenia #Slovenija #Slovenščina #SocialniInženiring #SpearPhishing #VarnostniProtokoli
-
The New Frontier: Securing Japan’s Hybrid Digital Workforce (2026 & Beyond)
As Japan navigates the mid-point of the decade, its cybersecurity landscape is undergoing a fundamental transformation. Driven by…
#EuropeSays #Japan #JP #anti-phishingtraining #cryptolocker #Florida #hackers #hacking #kevinmitnick #knowbe4 #Nihon #on-linetraining #phish-prone #phishing #ransomware #securityawarenesstraining #socialengineering #spearphishing #stusjouwerman #tampabay #Training
https://www.europesays.com/japan/37843/ -
The New Frontier: Securing Japan’s Hybrid Digital Workforce (2026 & Beyond)
As Japan navigates the mid-point of the decade, its cyb…
#Japan #JP #JapanNews #anti-phishingtraining #cryptolocker #florida #hackers #hacking #kevinmitnick #knowbe4 #news #on-linetraining #phish-prone #phishing #ransomware #securityawarenesstraining #socialengineering #spearphishing #stusjouwerman #tampabay #training
https://www.alojapan.com/1496415/the-new-frontier-securing-japans-hybrid-digital-workforce-2026-beyond/ -
The New Frontier: Securing Japan’s Hybrid Digital Workforce (2026 & Beyond)
As Japan navigates the mid-point of the decade, its cyb…
#Japan #JP #JapanNews #anti-phishingtraining #cryptolocker #florida #hackers #hacking #kevinmitnick #knowbe4 #news #on-linetraining #phish-prone #phishing #ransomware #securityawarenesstraining #socialengineering #spearphishing #stusjouwerman #tampabay #training
https://www.alojapan.com/1496415/the-new-frontier-securing-japans-hybrid-digital-workforce-2026-beyond/ -
https://www.alojapan.com/1496415/the-new-frontier-securing-japans-hybrid-digital-workforce-2026-beyond/ The New Frontier: Securing Japan’s Hybrid Digital Workforce (2026 & Beyond) #AntiPhishingTraining #cryptolocker #florida #hackers #hacking #Japan #JapanNews #KevinMitnick #knowbe4 #news #OnLineTraining #PhishProne #phishing #ransomware #SecurityAwarenessTraining #SocialEngineering #SpearPhishing #StuSjouwerman #TampaBay #training As Japan navigates the mid-point of the decade, its cybersecurity landscape is undergoing a fundamental trans
-
https://www.alojapan.com/1496415/the-new-frontier-securing-japans-hybrid-digital-workforce-2026-beyond/ The New Frontier: Securing Japan’s Hybrid Digital Workforce (2026 & Beyond) #AntiPhishingTraining #cryptolocker #florida #hackers #hacking #Japan #JapanNews #KevinMitnick #knowbe4 #news #OnLineTraining #PhishProne #phishing #ransomware #SecurityAwarenessTraining #SocialEngineering #SpearPhishing #StuSjouwerman #TampaBay #training As Japan navigates the mid-point of the decade, its cybersecurity landscape is undergoing a fundamental trans
-
Meta Disrupts NSO Group's WhatsApp Phishing Campaign
Meta detected and blocked a sneaky WhatsApp phishing campaign linked to NSO Group, where attackers tried to trick people into clicking malicious links that led to external websites. The company also filed a contempt order against NSO for allegedly violating a court injunction by targeting WhatsApp users.
#WhatsappPhishing #NsoGroup #SpearPhishing #Meta #1clickPhishing
-
SideCopy Targets Afghan Finance Ministry with Xeno RAT Malware
Seqrite Labs researchers uncovered a sneaky malware attack, dubbed Operation XENOFISCAL, where the Pakistan-aligned SideCopy group targeted Afghanistan's Ministry of Finance and government officials with a cleverly crafted phishing lure written in Pashto. The attack used Xeno RAT Malware, delivered through a ZIP archive with a malicious…
#XenoRatMalware #Sidecopy #Afghanistan #FinanceSector #SpearPhishing
-
Operation Dragon Weave: l’APT cinese usa Azure Blob Storage come C2 per colpire Repubblica Ceca e Taiwan
Seqrite ha identificato Operation Dragon Weave, una campagna APT attribuita con moderata confidenza a un attore cinese che colpisce funzionari e ricercatori in Repubblica Ceca e Taiwan. Il payload finale AZUREVEIL usa Azure Blob Storage come canale C2 dead-drop, mascherando il traffico malevolo tra le normali comunicazioni cloud enterprise. -
Operation Dragon Weave: l’APT cinese usa Azure Blob Storage come C2 per colpire Repubblica Ceca e Taiwan
Seqrite ha identificato Operation Dragon Weave, una campagna APT attribuita con moderata confidenza a un attore cinese che colpisce funzionari e ricercatori in Repubblica Ceca e Taiwan. Il payload finale AZUREVEIL usa Azure Blob Storage come canale C2 dead-drop, mascherando il traffico malevolo tra le normali comunicazioni cloud enterprise. -
Operation Dragon Weave: l’APT cinese usa Azure Blob Storage come C2 per colpire Repubblica Ceca e Taiwan
Seqrite ha identificato Operation Dragon Weave, una campagna APT attribuita con moderata confidenza a un attore cinese che colpisce funzionari e ricercatori in Repubblica Ceca e Taiwan. Il payload finale AZUREVEIL usa Azure Blob Storage come canale C2 dead-drop, mascherando il traffico malevolo tra le normali comunicazioni cloud enterprise. -
Operation Dragon Weave: l’APT cinese usa Azure Blob Storage come C2 per colpire Repubblica Ceca e Taiwan
Seqrite ha identificato Operation Dragon Weave, una campagna APT attribuita con moderata confidenza a un attore cinese che colpisce funzionari e ricercatori in Repubblica Ceca e Taiwan. Il payload finale AZUREVEIL usa Azure Blob Storage come canale C2 dead-drop, mascherando il traffico malevolo tra le normali comunicazioni cloud enterprise.