home.social

#spearphishing — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #spearphishing, aggregated by home.social.

fetched live
  1. Iranian Hackers Deploy Cross-Platform Malware via Coding Tests

    Iranian hackers are using clever tactics to deploy cross-platform malware, disguising it as coding challenges on LinkedIn and other job search platforms to trick developers into installing the threat. This malware, tracked as NodeRabbit and PollCat, can infect Windows, Linux, and macOS workstations, allowing hackers to gain remote…

    osintsights.com/iranian-hacker

    #IranianHackers #Noderabbit #CrossplatformMalware #Spearphishing #Linkedin

  2. July 2026 Threat Trend Report on APT Attacks (South Korea)

    During July 2026, multiple APT campaigns targeted entities in South Korea primarily through spear phishing attacks utilizing LNK files. Seven distinct attack types (A through G) were identified, each employing different techniques including PowerShell scripts, AutoIt programs, curl.exe downloads, and DLL side-loading. Attackers distributed malware through platforms like GitHub, Google Drive, and Dropbox, often disguised as legitimate documents or resumes. These campaigns deployed backdoors, infostealers, keyloggers, and XenoRAT malware to exfiltrate system information, credentials, virtual asset data, and maintain persistent access through Task Scheduler entries. Communications occurred via PubNub channels with data encoded in Base64. The attacks primarily began with phishing emails containing work-related content designed to deceive specific victims into executing malicious files.

    Pulse ID: 6a91687da8e6cd5cc16f64a6
    Pulse Link: otx.alienvault.com/pulse/6a916
    Pulse Author: AlienVault
    Created: 2026-08-28 10:52:45

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Autoit #BackDoor #CyberSecurity #Dropbox #Email #GitHub #Google #InfoSec #InfoStealer #KeyLogger #Korea #LNK #Malware #OTX #OpenThreatExchange #Phishing #PowerShell #RAT #SouthKorea #SpearPhishing #bot #AlienVault

  3. July 2026 Threat Trend Report on APT Attacks (South Korea)

    During July 2026, multiple APT campaigns targeted entities in South Korea primarily through spear phishing attacks utilizing LNK files. Seven distinct attack types (A through G) were identified, each employing different techniques including PowerShell scripts, AutoIt programs, curl.exe downloads, and DLL side-loading. Attackers distributed malware through platforms like GitHub, Google Drive, and Dropbox, often disguised as legitimate documents or resumes. These campaigns deployed backdoors, infostealers, keyloggers, and XenoRAT malware to exfiltrate system information, credentials, virtual asset data, and maintain persistent access through Task Scheduler entries. Communications occurred via PubNub channels with data encoded in Base64. The attacks primarily began with phishing emails containing work-related content designed to deceive specific victims into executing malicious files.

    Pulse ID: 6a91687da8e6cd5cc16f64a6
    Pulse Link: otx.alienvault.com/pulse/6a916
    Pulse Author: AlienVault
    Created: 2026-08-28 10:52:45

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Autoit #BackDoor #CyberSecurity #Dropbox #Email #GitHub #Google #InfoSec #InfoStealer #KeyLogger #Korea #LNK #Malware #OTX #OpenThreatExchange #Phishing #PowerShell #RAT #SouthKorea #SpearPhishing #bot #AlienVault

  4. July 2026 Threat Trend Report on APT Attacks (South Korea)

    During July 2026, multiple APT campaigns targeted entities in South Korea primarily through spear phishing attacks utilizing LNK files. Seven distinct attack types (A through G) were identified, each employing different techniques including PowerShell scripts, AutoIt programs, curl.exe downloads, and DLL side-loading. Attackers distributed malware through platforms like GitHub, Google Drive, and Dropbox, often disguised as legitimate documents or resumes. These campaigns deployed backdoors, infostealers, keyloggers, and XenoRAT malware to exfiltrate system information, credentials, virtual asset data, and maintain persistent access through Task Scheduler entries. Communications occurred via PubNub channels with data encoded in Base64. The attacks primarily began with phishing emails containing work-related content designed to deceive specific victims into executing malicious files.

    Pulse ID: 6a91687da8e6cd5cc16f64a6
    Pulse Link: otx.alienvault.com/pulse/6a916
    Pulse Author: AlienVault
    Created: 2026-08-28 10:52:45

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Autoit #BackDoor #CyberSecurity #Dropbox #Email #GitHub #Google #InfoSec #InfoStealer #KeyLogger #Korea #LNK #Malware #OTX #OpenThreatExchange #Phishing #PowerShell #RAT #SouthKorea #SpearPhishing #bot #AlienVault

  5. July 2026 Threat Trend Report on APT Attacks (South Korea)

    During July 2026, multiple APT campaigns targeted entities in South Korea primarily through spear phishing attacks utilizing LNK files. Seven distinct attack types (A through G) were identified, each employing different techniques including PowerShell scripts, AutoIt programs, curl.exe downloads, and DLL side-loading. Attackers distributed malware through platforms like GitHub, Google Drive, and Dropbox, often disguised as legitimate documents or resumes. These campaigns deployed backdoors, infostealers, keyloggers, and XenoRAT malware to exfiltrate system information, credentials, virtual asset data, and maintain persistent access through Task Scheduler entries. Communications occurred via PubNub channels with data encoded in Base64. The attacks primarily began with phishing emails containing work-related content designed to deceive specific victims into executing malicious files.

    Pulse ID: 6a91687da8e6cd5cc16f64a6
    Pulse Link: otx.alienvault.com/pulse/6a916
    Pulse Author: AlienVault
    Created: 2026-08-28 10:52:45

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Autoit #BackDoor #CyberSecurity #Dropbox #Email #GitHub #Google #InfoSec #InfoStealer #KeyLogger #Korea #LNK #Malware #OTX #OpenThreatExchange #Phishing #PowerShell #RAT #SouthKorea #SpearPhishing #bot #AlienVault

  6. July 2026 Threat Trend Report on APT Attacks (South Korea)

    During July 2026, multiple APT campaigns targeted entities in South Korea primarily through spear phishing attacks utilizing LNK files. Seven distinct attack types (A through G) were identified, each employing different techniques including PowerShell scripts, AutoIt programs, curl.exe downloads, and DLL side-loading. Attackers distributed malware through platforms like GitHub, Google Drive, and Dropbox, often disguised as legitimate documents or resumes. These campaigns deployed backdoors, infostealers, keyloggers, and XenoRAT malware to exfiltrate system information, credentials, virtual asset data, and maintain persistent access through Task Scheduler entries. Communications occurred via PubNub channels with data encoded in Base64. The attacks primarily began with phishing emails containing work-related content designed to deceive specific victims into executing malicious files.

    Pulse ID: 6a91687da8e6cd5cc16f64a6
    Pulse Link: otx.alienvault.com/pulse/6a916
    Pulse Author: AlienVault
    Created: 2026-08-28 10:52:45

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Autoit #BackDoor #CyberSecurity #Dropbox #Email #GitHub #Google #InfoSec #InfoStealer #KeyLogger #Korea #LNK #Malware #OTX #OpenThreatExchange #Phishing #PowerShell #RAT #SouthKorea #SpearPhishing #bot #AlienVault

  7. 📢 Des hackers soutenus par des États ciblent des hauts fonctionnaires de l'UE via WhatsApp

    Le CERT-EU (EU Computer Emergency Response Team) a formellement identifié des campagnes de spearphishing étatique ciblant des hauts fonctionnaires de l'Union européenne via des applications de messagerie, notamment WhatsApp et Signal.

    📖 cyberveille : cyberveille.ch/posts/2026-08-2
    🌐 source : politico.eu/article/hackers-ta
    🟢 vérification factuelle haute
    #CERTEU #spearphishing #Cyberveille

  8. Inside Kimsuky's Abuse of Legitimate Remote Control Tools Across Northeast Asia

    Kimsuky conducted spear phishing campaigns against South Korean and Japanese targets during the first half of 2026, distributing LNK malware through OneDrive share links. The malicious files established scheduled tasks that periodically fetched PowerShell scripts from command-and-control servers to profile systems, exfiltrate Thunderbird and Outlook email data, and log keystrokes. The threat actor installed legitimate remote control software including Chrome Remote Desktop and AnyDesk to evade antivirus detection and maintain multiple access channels. A malicious Chrome extension designed to steal Gmail data exhibited characteristics of AI-generated code, featuring Korean comments, debug strings, and Unicode emoji throughout. The operation employed rotating infrastructure and compromised legitimate Korean servers as command-and-control nodes to impede tracking efforts.

    Pulse ID: 6a873495a873c0ec3c6d9880
    Pulse Link: otx.alienvault.com/pulse/6a873
    Pulse Author: AlienVault
    Created: 2026-08-20 17:08:37

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #AnyDesk #Asia #Chrome #ChromeExtension #CyberSecurity #EDR #Email #ICS #InfoSec #Japan #Kimsuky #Korea #LNK #Malware #OTX #OpenThreatExchange #Outlook #Phishing #PowerShell #RAT #SouthKorea #SpearPhishing #UK #bot #AlienVault

  9. Inside Kimsuky's Abuse of Legitimate Remote Control Tools Across Northeast Asia

    Kimsuky conducted spear phishing campaigns against South Korean and Japanese targets during the first half of 2026, distributing LNK malware through OneDrive share links. The malicious files established scheduled tasks that periodically fetched PowerShell scripts from command-and-control servers to profile systems, exfiltrate Thunderbird and Outlook email data, and log keystrokes. The threat actor installed legitimate remote control software including Chrome Remote Desktop and AnyDesk to evade antivirus detection and maintain multiple access channels. A malicious Chrome extension designed to steal Gmail data exhibited characteristics of AI-generated code, featuring Korean comments, debug strings, and Unicode emoji throughout. The operation employed rotating infrastructure and compromised legitimate Korean servers as command-and-control nodes to impede tracking efforts.

    Pulse ID: 6a873495a873c0ec3c6d9880
    Pulse Link: otx.alienvault.com/pulse/6a873
    Pulse Author: AlienVault
    Created: 2026-08-20 17:08:37

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #AnyDesk #Asia #Chrome #ChromeExtension #CyberSecurity #EDR #Email #ICS #InfoSec #Japan #Kimsuky #Korea #LNK #Malware #OTX #OpenThreatExchange #Outlook #Phishing #PowerShell #RAT #SouthKorea #SpearPhishing #UK #bot #AlienVault

  10. Inside Kimsuky's Abuse of Legitimate Remote Control Tools Across Northeast Asia

    Kimsuky conducted spear phishing campaigns against South Korean and Japanese targets during the first half of 2026, distributing LNK malware through OneDrive share links. The malicious files established scheduled tasks that periodically fetched PowerShell scripts from command-and-control servers to profile systems, exfiltrate Thunderbird and Outlook email data, and log keystrokes. The threat actor installed legitimate remote control software including Chrome Remote Desktop and AnyDesk to evade antivirus detection and maintain multiple access channels. A malicious Chrome extension designed to steal Gmail data exhibited characteristics of AI-generated code, featuring Korean comments, debug strings, and Unicode emoji throughout. The operation employed rotating infrastructure and compromised legitimate Korean servers as command-and-control nodes to impede tracking efforts.

    Pulse ID: 6a873495a873c0ec3c6d9880
    Pulse Link: otx.alienvault.com/pulse/6a873
    Pulse Author: AlienVault
    Created: 2026-08-20 17:08:37

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #AnyDesk #Asia #Chrome #ChromeExtension #CyberSecurity #EDR #Email #ICS #InfoSec #Japan #Kimsuky #Korea #LNK #Malware #OTX #OpenThreatExchange #Outlook #Phishing #PowerShell #RAT #SouthKorea #SpearPhishing #UK #bot #AlienVault

  11. Inside Kimsuky's Abuse of Legitimate Remote Control Tools Across Northeast Asia

    Kimsuky conducted spear phishing campaigns against South Korean and Japanese targets during the first half of 2026, distributing LNK malware through OneDrive share links. The malicious files established scheduled tasks that periodically fetched PowerShell scripts from command-and-control servers to profile systems, exfiltrate Thunderbird and Outlook email data, and log keystrokes. The threat actor installed legitimate remote control software including Chrome Remote Desktop and AnyDesk to evade antivirus detection and maintain multiple access channels. A malicious Chrome extension designed to steal Gmail data exhibited characteristics of AI-generated code, featuring Korean comments, debug strings, and Unicode emoji throughout. The operation employed rotating infrastructure and compromised legitimate Korean servers as command-and-control nodes to impede tracking efforts.

    Pulse ID: 6a873495a873c0ec3c6d9880
    Pulse Link: otx.alienvault.com/pulse/6a873
    Pulse Author: AlienVault
    Created: 2026-08-20 17:08:37

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #AnyDesk #Asia #Chrome #ChromeExtension #CyberSecurity #EDR #Email #ICS #InfoSec #Japan #Kimsuky #Korea #LNK #Malware #OTX #OpenThreatExchange #Outlook #Phishing #PowerShell #RAT #SouthKorea #SpearPhishing #UK #bot #AlienVault

  12. Inside Kimsuky's Abuse of Legitimate Remote Control Tools Across Northeast Asia

    Kimsuky conducted spear phishing campaigns against South Korean and Japanese targets during the first half of 2026, distributing LNK malware through OneDrive share links. The malicious files established scheduled tasks that periodically fetched PowerShell scripts from command-and-control servers to profile systems, exfiltrate Thunderbird and Outlook email data, and log keystrokes. The threat actor installed legitimate remote control software including Chrome Remote Desktop and AnyDesk to evade antivirus detection and maintain multiple access channels. A malicious Chrome extension designed to steal Gmail data exhibited characteristics of AI-generated code, featuring Korean comments, debug strings, and Unicode emoji throughout. The operation employed rotating infrastructure and compromised legitimate Korean servers as command-and-control nodes to impede tracking efforts.

    Pulse ID: 6a873495a873c0ec3c6d9880
    Pulse Link: otx.alienvault.com/pulse/6a873
    Pulse Author: AlienVault
    Created: 2026-08-20 17:08:37

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #AnyDesk #Asia #Chrome #ChromeExtension #CyberSecurity #EDR #Email #ICS #InfoSec #Japan #Kimsuky #Korea #LNK #Malware #OTX #OpenThreatExchange #Outlook #Phishing #PowerShell #RAT #SouthKorea #SpearPhishing #UK #bot #AlienVault

  13. SilkParasite: Tracking a China-Nexus APT Across Central Asia

    SilkParasite is a cyberespionage operation assessed with medium confidence as China-nexus that targeted government bodies across Central Asia. Seven remote access tool families were deployed, five of which were previously undocumented: DriveSilkRAT, CookiETagRAT, NomadRAT, GoginRAT, and NodeEdgeRAT. The toolset is small, modular, and professionally engineered with traces of AI-assisted development. Initial access occurred through malicious Microsoft Office documents delivered via spear-phishing, using regionally tailored lures impersonating government ministries. The operation leveraged DLL sideloading as the primary delivery mechanism and used Google Drive for command-and-control communications to hide within trusted services. Infrastructure analysis identified connections to China Unicom's backbone network, and operational patterns suggest a functioning software organization with maintained build pipelines and careful operational security.

    Pulse ID: 6a86a70eb8b57f155e62d4f7
    Pulse Link: otx.alienvault.com/pulse/6a86a
    Pulse Author: AlienVault
    Created: 2026-08-20 07:04:46

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Asia #CentralAsia #China #CyberSecurity #Cyberespionage #DRat #Edge #Espionage #Google #Government #InfoSec #Microsoft #MicrosoftOffice #OTX #Office #OpenThreatExchange #Phishing #RAT #Rust #SideLoading #SpearPhishing #bot #AlienVault

  14. SilkParasite: Tracking a China-Nexus APT Across Central Asia

    SilkParasite is a cyberespionage operation assessed with medium confidence as China-nexus that targeted government bodies across Central Asia. Seven remote access tool families were deployed, five of which were previously undocumented: DriveSilkRAT, CookiETagRAT, NomadRAT, GoginRAT, and NodeEdgeRAT. The toolset is small, modular, and professionally engineered with traces of AI-assisted development. Initial access occurred through malicious Microsoft Office documents delivered via spear-phishing, using regionally tailored lures impersonating government ministries. The operation leveraged DLL sideloading as the primary delivery mechanism and used Google Drive for command-and-control communications to hide within trusted services. Infrastructure analysis identified connections to China Unicom's backbone network, and operational patterns suggest a functioning software organization with maintained build pipelines and careful operational security.

    Pulse ID: 6a86a70eb8b57f155e62d4f7
    Pulse Link: otx.alienvault.com/pulse/6a86a
    Pulse Author: AlienVault
    Created: 2026-08-20 07:04:46

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Asia #CentralAsia #China #CyberSecurity #Cyberespionage #DRat #Edge #Espionage #Google #Government #InfoSec #Microsoft #MicrosoftOffice #OTX #Office #OpenThreatExchange #Phishing #RAT #Rust #SideLoading #SpearPhishing #bot #AlienVault

  15. SilkParasite: Tracking a China-Nexus APT Across Central Asia

    SilkParasite is a cyberespionage operation assessed with medium confidence as China-nexus that targeted government bodies across Central Asia. Seven remote access tool families were deployed, five of which were previously undocumented: DriveSilkRAT, CookiETagRAT, NomadRAT, GoginRAT, and NodeEdgeRAT. The toolset is small, modular, and professionally engineered with traces of AI-assisted development. Initial access occurred through malicious Microsoft Office documents delivered via spear-phishing, using regionally tailored lures impersonating government ministries. The operation leveraged DLL sideloading as the primary delivery mechanism and used Google Drive for command-and-control communications to hide within trusted services. Infrastructure analysis identified connections to China Unicom's backbone network, and operational patterns suggest a functioning software organization with maintained build pipelines and careful operational security.

    Pulse ID: 6a86a70eb8b57f155e62d4f7
    Pulse Link: otx.alienvault.com/pulse/6a86a
    Pulse Author: AlienVault
    Created: 2026-08-20 07:04:46

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Asia #CentralAsia #China #CyberSecurity #Cyberespionage #DRat #Edge #Espionage #Google #Government #InfoSec #Microsoft #MicrosoftOffice #OTX #Office #OpenThreatExchange #Phishing #RAT #Rust #SideLoading #SpearPhishing #bot #AlienVault

  16. SilkParasite: Tracking a China-Nexus APT Across Central Asia

    SilkParasite is a cyberespionage operation assessed with medium confidence as China-nexus that targeted government bodies across Central Asia. Seven remote access tool families were deployed, five of which were previously undocumented: DriveSilkRAT, CookiETagRAT, NomadRAT, GoginRAT, and NodeEdgeRAT. The toolset is small, modular, and professionally engineered with traces of AI-assisted development. Initial access occurred through malicious Microsoft Office documents delivered via spear-phishing, using regionally tailored lures impersonating government ministries. The operation leveraged DLL sideloading as the primary delivery mechanism and used Google Drive for command-and-control communications to hide within trusted services. Infrastructure analysis identified connections to China Unicom's backbone network, and operational patterns suggest a functioning software organization with maintained build pipelines and careful operational security.

    Pulse ID: 6a86a70eb8b57f155e62d4f7
    Pulse Link: otx.alienvault.com/pulse/6a86a
    Pulse Author: AlienVault
    Created: 2026-08-20 07:04:46

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Asia #CentralAsia #China #CyberSecurity #Cyberespionage #DRat #Edge #Espionage #Google #Government #InfoSec #Microsoft #MicrosoftOffice #OTX #Office #OpenThreatExchange #Phishing #RAT #Rust #SideLoading #SpearPhishing #bot #AlienVault

  17. SilkParasite: Tracking a China-Nexus APT Across Central Asia

    SilkParasite is a cyberespionage operation assessed with medium confidence as China-nexus that targeted government bodies across Central Asia. Seven remote access tool families were deployed, five of which were previously undocumented: DriveSilkRAT, CookiETagRAT, NomadRAT, GoginRAT, and NodeEdgeRAT. The toolset is small, modular, and professionally engineered with traces of AI-assisted development. Initial access occurred through malicious Microsoft Office documents delivered via spear-phishing, using regionally tailored lures impersonating government ministries. The operation leveraged DLL sideloading as the primary delivery mechanism and used Google Drive for command-and-control communications to hide within trusted services. Infrastructure analysis identified connections to China Unicom's backbone network, and operational patterns suggest a functioning software organization with maintained build pipelines and careful operational security.

    Pulse ID: 6a86a70eb8b57f155e62d4f7
    Pulse Link: otx.alienvault.com/pulse/6a86a
    Pulse Author: AlienVault
    Created: 2026-08-20 07:04:46

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Asia #CentralAsia #China #CyberSecurity #Cyberespionage #DRat #Edge #Espionage #Google #Government #InfoSec #Microsoft #MicrosoftOffice #OTX #Office #OpenThreatExchange #Phishing #RAT #Rust #SideLoading #SpearPhishing #bot #AlienVault

  18. Iran's Mabna Institute ran a 3-phase spearphishing campaign against university professors for a decade. The 50-page superseding indictmen...

    Indicators extracted from public reporting. Source: reddit.com/r/netsec/comments/1

    Pulse ID: 6a85e02d9151a30aa821db6a
    Pulse Link: otx.alienvault.com/pulse/6a85e
    Pulse Author: CyberHunter_NL
    Created: 2026-08-19 16:56:13

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #HTTP #HTTPS #InfoSec #Iran #OTX #OpenThreatExchange #Phishing #RCE #SpearPhishing #bot #CyberHunter_NL

  19. Iran's Mabna Institute ran a 3-phase spearphishing campaign against university professors for a decade. The 50-page superseding indictmen...

    Indicators extracted from public reporting. Source: reddit.com/r/netsec/comments/1

    Pulse ID: 6a85e02d9151a30aa821db6a
    Pulse Link: otx.alienvault.com/pulse/6a85e
    Pulse Author: CyberHunter_NL
    Created: 2026-08-19 16:56:13

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #HTTP #HTTPS #InfoSec #Iran #OTX #OpenThreatExchange #Phishing #RCE #SpearPhishing #bot #CyberHunter_NL

  20. Iran's Mabna Institute ran a 3-phase spearphishing campaign against university professors for a decade. The 50-page superseding indictmen...

    Indicators extracted from public reporting. Source: reddit.com/r/netsec/comments/1

    Pulse ID: 6a85e02d9151a30aa821db6a
    Pulse Link: otx.alienvault.com/pulse/6a85e
    Pulse Author: CyberHunter_NL
    Created: 2026-08-19 16:56:13

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #HTTP #HTTPS #InfoSec #Iran #OTX #OpenThreatExchange #Phishing #RCE #SpearPhishing #bot #CyberHunter_NL

  21. Iran's Mabna Institute ran a 3-phase spearphishing campaign against university professors for a decade. The 50-page superseding indictmen...

    Indicators extracted from public reporting. Source: reddit.com/r/netsec/comments/1

    Pulse ID: 6a85e02d9151a30aa821db6a
    Pulse Link: otx.alienvault.com/pulse/6a85e
    Pulse Author: CyberHunter_NL
    Created: 2026-08-19 16:56:13

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #HTTP #HTTPS #InfoSec #Iran #OTX #OpenThreatExchange #Phishing #RCE #SpearPhishing #bot #CyberHunter_NL

  22. Iran's Mabna Institute ran a 3-phase spearphishing campaign against university professors for a decade. The 50-page superseding indictmen...

    Indicators extracted from public reporting. Source: reddit.com/r/netsec/comments/1

    Pulse ID: 6a85e02d9151a30aa821db6a
    Pulse Link: otx.alienvault.com/pulse/6a85e
    Pulse Author: CyberHunter_NL
    Created: 2026-08-19 16:56:13

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #HTTP #HTTPS #InfoSec #Iran #OTX #OpenThreatExchange #Phishing #RCE #SpearPhishing #bot #CyberHunter_NL

  23. #Cyberkriminelle nutzen #KI nicht nur zur Skalierung von #Phishing Mails, sondern auch zur Individualisierung - kombiniert mit #OSINT ein effektives Instrument, um Social Engineering voranzutreiben.

    In einem groß angelegten Feldexperiment mit über 7.700 Beschäftigten der TU Braunschweig haben jetzt Forschende der TU Berlin, von Inria und der Ruhr-Universität Bochum getestet, wie gefährlich automatisiertes #Spearphishing mit Sprachmodellen wirklich ist:

    usenix.org/system/files/confer #cybersecurity

  24. #Cyberkriminelle nutzen #KI nicht nur zur Skalierung von #Phishing Mails, sondern auch zur Individualisierung - kombiniert mit #OSINT ein effektives Instrument, um Social Engineering voranzutreiben.

    In einem groß angelegten Feldexperiment mit über 7.700 Beschäftigten der TU Braunschweig haben jetzt Forschende der TU Berlin, von Inria und der Ruhr-Universität Bochum getestet, wie gefährlich automatisiertes #Spearphishing mit Sprachmodellen wirklich ist:

    usenix.org/system/files/confer #cybersecurity

  25. #Cyberkriminelle nutzen #KI nicht nur zur Skalierung von #Phishing Mails, sondern auch zur Individualisierung - kombiniert mit #OSINT ein effektives Instrument, um Social Engineering voranzutreiben.

    In einem groß angelegten Feldexperiment mit über 7.700 Beschäftigten der TU Braunschweig haben jetzt Forschende der TU Berlin, von Inria und der Ruhr-Universität Bochum getestet, wie gefährlich automatisiertes #Spearphishing mit Sprachmodellen wirklich ist:

    usenix.org/system/files/confer #cybersecurity

  26. #Cyberkriminelle nutzen #KI nicht nur zur Skalierung von #Phishing Mails, sondern auch zur Individualisierung - kombiniert mit #OSINT ein effektives Instrument, um Social Engineering voranzutreiben.

    In einem groß angelegten Feldexperiment mit über 7.700 Beschäftigten der TU Braunschweig haben jetzt Forschende der TU Berlin, von Inria und der Ruhr-Universität Bochum getestet, wie gefährlich automatisiertes #Spearphishing mit Sprachmodellen wirklich ist:

    usenix.org/system/files/confer #cybersecurity

  27. #Cyberkriminelle nutzen #KI nicht nur zur Skalierung von #Phishing Mails, sondern auch zur Individualisierung - kombiniert mit #OSINT ein effektives Instrument, um Social Engineering voranzutreiben.

    In einem groß angelegten Feldexperiment mit über 7.700 Beschäftigten der TU Braunschweig haben jetzt Forschende der TU Berlin, von Inria und der Ruhr-Universität Bochum getestet, wie gefährlich automatisiertes #Spearphishing mit Sprachmodellen wirklich ist:

    usenix.org/system/files/confer #cybersecurity

  28. Xiamen Empress Information Technology: come Pechino ha affittato account LINE per spiare giornalisti e attivisti a Taiwan

    Le autorità taiwanesi hanno incriminato due imprenditori per aver affittato account LINE a Xiamen Empress Information Technology, usati da operatori legati a Pechino per impersonare giornalisti e colpire funzionari, accademici e attivisti. Il caso conferma le inchieste di ICIJ e Citizen Lab sulla repressione transnazionale cinese.

    insicurezzadigitale.com/xiamen

  29. Xiamen Empress Information Technology: come Pechino ha affittato account LINE per spiare giornalisti e attivisti a Taiwan

    Le autorità taiwanesi hanno incriminato due imprenditori per aver affittato account LINE a Xiamen Empress Information Technology, usati da operatori legati a Pechino per impersonare giornalisti e colpire funzionari, accademici e attivisti. Il caso conferma le inchieste di ICIJ e Citizen Lab sulla repressione transnazionale cinese.

    insicurezzadigitale.com/xiamen

  30. Xiamen Empress Information Technology: come Pechino ha affittato account LINE per spiare giornalisti e attivisti a Taiwan

    Le autorità taiwanesi hanno incriminato due imprenditori per aver affittato account LINE a Xiamen Empress Information Technology, usati da operatori legati a Pechino per impersonare giornalisti e colpire funzionari, accademici e attivisti. Il caso conferma le inchieste di ICIJ e Citizen Lab sulla repressione transnazionale cinese.

    insicurezzadigitale.com/xiamen

  31. Xiamen Empress Information Technology: come Pechino ha affittato account LINE per spiare giornalisti e attivisti a Taiwan

    Le autorità taiwanesi hanno incriminato due imprenditori per aver affittato account LINE a Xiamen Empress Information Technology, usati da operatori legati a Pechino per impersonare giornalisti e colpire funzionari, accademici e attivisti. Il caso conferma le inchieste di ICIJ e Citizen Lab sulla repressione transnazionale cinese.

    insicurezzadigitale.com/xiamen

  32. Xiamen Empress Information Technology: come Pechino ha affittato account LINE per spiare giornalisti e attivisti a Taiwan

    Le autorità taiwanesi hanno incriminato due imprenditori per aver affittato account LINE a Xiamen Empress Information Technology, usati da operatori legati a Pechino per impersonare giornalisti e colpire funzionari, accademici e attivisti. Il caso conferma le inchieste di ICIJ e Citizen Lab sulla repressione transnazionale cinese.

    insicurezzadigitale.com/xiamen

  33. Once, during an #awareness session, I brought a jar into the room.

    One of those old-school glass jars with a metal lid.

    I put it on the table and asked the executives (not the CISOs) to drop a poker chip inside.

    Yes, poker chips. Don’t laugh. That’s what I had.

    The value of each chip was supposed to reflect two things: perceived risk and willingness to spend.

    At the beginning, the jar looked miserable.

    Two or three 50s.
    One brave 500.
    Fewer than ten 100s.

    Then came lunch.
    Paid for, obviously.
    But lunch was also the exercise.

    Heavy #socialengineering. Casual conversation. Names, routines, vendors, habits, internal friction, travel plans, tools, weak points, ego, trust.

    Then the last two hours began.
    Real risk demonstration.

    #spearphishing built with information collected during lunch.
    Fake WhatsApp chats after recon.
    #OSINT before the session even restarted.
    QR codes everywhere.

    Then we talked about recovery costs.

    Regulatory fines.
    Production downtime.
    Loss of trust.
    Reputational damage.
    The unpleasant difference between “unlikely” and “not impossible”.

    And, magically, the jar filled up with 500 and 1000 chips.

    You don’t fucking say.

    My #Decoded for #Baited: blog.baited.io/2026/cost-of-ph

  34. Once, during an #awareness session, I brought a jar into the room.

    One of those old-school glass jars with a metal lid.

    I put it on the table and asked the executives (not the CISOs) to drop a poker chip inside.

    Yes, poker chips. Don’t laugh. That’s what I had.

    The value of each chip was supposed to reflect two things: perceived risk and willingness to spend.

    At the beginning, the jar looked miserable.

    Two or three 50s.
    One brave 500.
    Fewer than ten 100s.

    Then came lunch.
    Paid for, obviously.
    But lunch was also the exercise.

    Heavy #socialengineering. Casual conversation. Names, routines, vendors, habits, internal friction, travel plans, tools, weak points, ego, trust.

    Then the last two hours began.
    Real risk demonstration.

    #spearphishing built with information collected during lunch.
    Fake WhatsApp chats after recon.
    #OSINT before the session even restarted.
    QR codes everywhere.

    Then we talked about recovery costs.

    Regulatory fines.
    Production downtime.
    Loss of trust.
    Reputational damage.
    The unpleasant difference between “unlikely” and “not impossible”.

    And, magically, the jar filled up with 500 and 1000 chips.

    You don’t fucking say.

    My #Decoded for #Baited: blog.baited.io/2026/cost-of-ph

  35. Once, during an #awareness session, I brought a jar into the room.

    One of those old-school glass jars with a metal lid.

    I put it on the table and asked the executives (not the CISOs) to drop a poker chip inside.

    Yes, poker chips. Don’t laugh. That’s what I had.

    The value of each chip was supposed to reflect two things: perceived risk and willingness to spend.

    At the beginning, the jar looked miserable.

    Two or three 50s.
    One brave 500.
    Fewer than ten 100s.

    Then came lunch.
    Paid for, obviously.
    But lunch was also the exercise.

    Heavy #socialengineering. Casual conversation. Names, routines, vendors, habits, internal friction, travel plans, tools, weak points, ego, trust.

    Then the last two hours began.
    Real risk demonstration.

    #spearphishing built with information collected during lunch.
    Fake WhatsApp chats after recon.
    #OSINT before the session even restarted.
    QR codes everywhere.

    Then we talked about recovery costs.

    Regulatory fines.
    Production downtime.
    Loss of trust.
    Reputational damage.
    The unpleasant difference between “unlikely” and “not impossible”.

    And, magically, the jar filled up with 500 and 1000 chips.

    You don’t fucking say.

    My #Decoded for #Baited: blog.baited.io/2026/cost-of-ph

  36. Once, during an #awareness session, I brought a jar into the room.

    One of those old-school glass jars with a metal lid.

    I put it on the table and asked the executives (not the CISOs) to drop a poker chip inside.

    Yes, poker chips. Don’t laugh. That’s what I had.

    The value of each chip was supposed to reflect two things: perceived risk and willingness to spend.

    At the beginning, the jar looked miserable.

    Two or three 50s.
    One brave 500.
    Fewer than ten 100s.

    Then came lunch.
    Paid for, obviously.
    But lunch was also the exercise.

    Heavy #socialengineering. Casual conversation. Names, routines, vendors, habits, internal friction, travel plans, tools, weak points, ego, trust.

    Then the last two hours began.
    Real risk demonstration.

    #spearphishing built with information collected during lunch.
    Fake WhatsApp chats after recon.
    #OSINT before the session even restarted.
    QR codes everywhere.

    Then we talked about recovery costs.

    Regulatory fines.
    Production downtime.
    Loss of trust.
    Reputational damage.
    The unpleasant difference between “unlikely” and “not impossible”.

    And, magically, the jar filled up with 500 and 1000 chips.

    You don’t fucking say.

    My #Decoded for #Baited: blog.baited.io/2026/cost-of-ph

  37. Once, during an #awareness session, I brought a jar into the room.

    One of those old-school glass jars with a metal lid.

    I put it on the table and asked the executives (not the CISOs) to drop a poker chip inside.

    Yes, poker chips. Don’t laugh. That’s what I had.

    The value of each chip was supposed to reflect two things: perceived risk and willingness to spend.

    At the beginning, the jar looked miserable.

    Two or three 50s.
    One brave 500.
    Fewer than ten 100s.

    Then came lunch.
    Paid for, obviously.
    But lunch was also the exercise.

    Heavy #socialengineering. Casual conversation. Names, routines, vendors, habits, internal friction, travel plans, tools, weak points, ego, trust.

    Then the last two hours began.
    Real risk demonstration.

    #spearphishing built with information collected during lunch.
    Fake WhatsApp chats after recon.
    #OSINT before the session even restarted.
    QR codes everywhere.

    Then we talked about recovery costs.

    Regulatory fines.
    Production downtime.
    Loss of trust.
    Reputational damage.
    The unpleasant difference between “unlikely” and “not impossible”.

    And, magically, the jar filled up with 500 and 1000 chips.

    You don’t fucking say.

    My #Decoded for #Baited: blog.baited.io/2026/cost-of-ph

  38. The New Frontier: Securing Japan’s Hybrid Digital Workforce (2026 & Beyond)

    As Japan navigates the mid-point of the decade, its cybersecurity landscape is undergoing a fundamental transformation. Driven by…
    #EuropeSays #Japan #JP #anti-phishingtraining #cryptolocker #Florida #hackers #hacking #kevinmitnick #knowbe4 #Nihon #on-linetraining #phish-prone #phishing #ransomware #securityawarenesstraining #socialengineering #spearphishing #stusjouwerman #tampabay #Training
    europesays.com/japan/37843/

  39. Meta Disrupts NSO Group's WhatsApp Phishing Campaign

    Meta detected and blocked a sneaky WhatsApp phishing campaign linked to NSO Group, where attackers tried to trick people into clicking malicious links that led to external websites. The company also filed a contempt order against NSO for allegedly violating a court injunction by targeting WhatsApp users.

    osintsights.com/meta-disrupts-

    #WhatsappPhishing #NsoGroup #SpearPhishing #Meta #1clickPhishing

  40. SideCopy Targets Afghan Finance Ministry with Xeno RAT Malware

    Seqrite Labs researchers uncovered a sneaky malware attack, dubbed Operation XENOFISCAL, where the Pakistan-aligned SideCopy group targeted Afghanistan's Ministry of Finance and government officials with a cleverly crafted phishing lure written in Pashto. The attack used Xeno RAT Malware, delivered through a ZIP archive with a malicious…

    osintsights.com/sidecopy-targe

    #XenoRatMalware #Sidecopy #Afghanistan #FinanceSector #SpearPhishing

  41. Operation Dragon Weave: l’APT cinese usa Azure Blob Storage come C2 per colpire Repubblica Ceca e Taiwan

    Seqrite ha identificato Operation Dragon Weave, una campagna APT attribuita con moderata confidenza a un attore cinese che colpisce funzionari e ricercatori in Repubblica Ceca e Taiwan. Il payload finale AZUREVEIL usa Azure Blob Storage come canale C2 dead-drop, mascherando il traffico malevolo tra le normali comunicazioni cloud enterprise.

    insicurezzadigitale.com/operat

  42. Operation Dragon Weave: l’APT cinese usa Azure Blob Storage come C2 per colpire Repubblica Ceca e Taiwan

    Seqrite ha identificato Operation Dragon Weave, una campagna APT attribuita con moderata confidenza a un attore cinese che colpisce funzionari e ricercatori in Repubblica Ceca e Taiwan. Il payload finale AZUREVEIL usa Azure Blob Storage come canale C2 dead-drop, mascherando il traffico malevolo tra le normali comunicazioni cloud enterprise.

    insicurezzadigitale.com/operat

  43. Operation Dragon Weave: l’APT cinese usa Azure Blob Storage come C2 per colpire Repubblica Ceca e Taiwan

    Seqrite ha identificato Operation Dragon Weave, una campagna APT attribuita con moderata confidenza a un attore cinese che colpisce funzionari e ricercatori in Repubblica Ceca e Taiwan. Il payload finale AZUREVEIL usa Azure Blob Storage come canale C2 dead-drop, mascherando il traffico malevolo tra le normali comunicazioni cloud enterprise.

    insicurezzadigitale.com/operat

  44. Operation Dragon Weave: l’APT cinese usa Azure Blob Storage come C2 per colpire Repubblica Ceca e Taiwan

    Seqrite ha identificato Operation Dragon Weave, una campagna APT attribuita con moderata confidenza a un attore cinese che colpisce funzionari e ricercatori in Repubblica Ceca e Taiwan. Il payload finale AZUREVEIL usa Azure Blob Storage come canale C2 dead-drop, mascherando il traffico malevolo tra le normali comunicazioni cloud enterprise.

    insicurezzadigitale.com/operat