home.social

#spearphishing — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #spearphishing, aggregated by home.social.

  1. Beware of the LegionLoader malware being distributed via the ClickFix method

    LegionLoader malware is being distributed through ClickFix tactics using fake Cloudflare CAPTCHA pages. Two primary distribution methods have been identified: one exploits Korea's Newlywed Hope Town Namu Wiki page with malicious URLs, while the other uses spear phishing emails targeting specific companies disguised as internal business system account issuance instructions. When users access these malicious URLs, they are redirected to fake CAPTCHA pages that trick them into executing PowerShell commands, which download and execute LegionLoader. The malware sequentially decrypts encrypted shellcode and PE files, evaluates the infection environment through display device checks and ASN verification, then executes backdoor malware capable of running various payloads including PE files, shellcode, PowerShell scripts, and MSI files. It also steals Chrome browser credentials and profile information based on C2 server commands.

    Pulse ID: 6aa3fef84a7f54f4ae325151
    Pulse Link: otx.alienvault.com/pulse/6aa3f
    Pulse Author: AlienVault
    Created: 2026-09-11 13:15:36

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #BackDoor #Browser #CAPTCHA #Chrome #Cloud #CyberSecurity #Email #ICS #InfoSec #Korea #LUA #Malware #OTX #OpenThreatExchange #Phishing #PowerShell #ShellCode #SpearPhishing #bot #AlienVault

  2. Beware of the LegionLoader malware being distributed via the ClickFix method

    LegionLoader malware is being distributed through ClickFix tactics using fake Cloudflare CAPTCHA pages. Two primary distribution methods have been identified: one exploits Korea's Newlywed Hope Town Namu Wiki page with malicious URLs, while the other uses spear phishing emails targeting specific companies disguised as internal business system account issuance instructions. When users access these malicious URLs, they are redirected to fake CAPTCHA pages that trick them into executing PowerShell commands, which download and execute LegionLoader. The malware sequentially decrypts encrypted shellcode and PE files, evaluates the infection environment through display device checks and ASN verification, then executes backdoor malware capable of running various payloads including PE files, shellcode, PowerShell scripts, and MSI files. It also steals Chrome browser credentials and profile information based on C2 server commands.

    Pulse ID: 6aa3fef84a7f54f4ae325151
    Pulse Link: otx.alienvault.com/pulse/6aa3f
    Pulse Author: AlienVault
    Created: 2026-09-11 13:15:36

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #BackDoor #Browser #CAPTCHA #Chrome #Cloud #CyberSecurity #Email #ICS #InfoSec #Korea #LUA #Malware #OTX #OpenThreatExchange #Phishing #PowerShell #ShellCode #SpearPhishing #bot #AlienVault

  3. Beware of the LegionLoader malware being distributed via the ClickFix method

    LegionLoader malware is being distributed through ClickFix tactics using fake Cloudflare CAPTCHA pages. Two primary distribution methods have been identified: one exploits Korea's Newlywed Hope Town Namu Wiki page with malicious URLs, while the other uses spear phishing emails targeting specific companies disguised as internal business system account issuance instructions. When users access these malicious URLs, they are redirected to fake CAPTCHA pages that trick them into executing PowerShell commands, which download and execute LegionLoader. The malware sequentially decrypts encrypted shellcode and PE files, evaluates the infection environment through display device checks and ASN verification, then executes backdoor malware capable of running various payloads including PE files, shellcode, PowerShell scripts, and MSI files. It also steals Chrome browser credentials and profile information based on C2 server commands.

    Pulse ID: 6aa3fef84a7f54f4ae325151
    Pulse Link: otx.alienvault.com/pulse/6aa3f
    Pulse Author: AlienVault
    Created: 2026-09-11 13:15:36

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #BackDoor #Browser #CAPTCHA #Chrome #Cloud #CyberSecurity #Email #ICS #InfoSec #Korea #LUA #Malware #OTX #OpenThreatExchange #Phishing #PowerShell #ShellCode #SpearPhishing #bot #AlienVault

  4. Beware of the LegionLoader malware being distributed via the ClickFix method

    LegionLoader malware is being distributed through ClickFix tactics using fake Cloudflare CAPTCHA pages. Two primary distribution methods have been identified: one exploits Korea's Newlywed Hope Town Namu Wiki page with malicious URLs, while the other uses spear phishing emails targeting specific companies disguised as internal business system account issuance instructions. When users access these malicious URLs, they are redirected to fake CAPTCHA pages that trick them into executing PowerShell commands, which download and execute LegionLoader. The malware sequentially decrypts encrypted shellcode and PE files, evaluates the infection environment through display device checks and ASN verification, then executes backdoor malware capable of running various payloads including PE files, shellcode, PowerShell scripts, and MSI files. It also steals Chrome browser credentials and profile information based on C2 server commands.

    Pulse ID: 6aa3fef84a7f54f4ae325151
    Pulse Link: otx.alienvault.com/pulse/6aa3f
    Pulse Author: AlienVault
    Created: 2026-09-11 13:15:36

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #BackDoor #Browser #CAPTCHA #Chrome #Cloud #CyberSecurity #Email #ICS #InfoSec #Korea #LUA #Malware #OTX #OpenThreatExchange #Phishing #PowerShell #ShellCode #SpearPhishing #bot #AlienVault

  5. Beware of the LegionLoader malware being distributed via the ClickFix method

    LegionLoader malware is being distributed through ClickFix tactics using fake Cloudflare CAPTCHA pages. Two primary distribution methods have been identified: one exploits Korea's Newlywed Hope Town Namu Wiki page with malicious URLs, while the other uses spear phishing emails targeting specific companies disguised as internal business system account issuance instructions. When users access these malicious URLs, they are redirected to fake CAPTCHA pages that trick them into executing PowerShell commands, which download and execute LegionLoader. The malware sequentially decrypts encrypted shellcode and PE files, evaluates the infection environment through display device checks and ASN verification, then executes backdoor malware capable of running various payloads including PE files, shellcode, PowerShell scripts, and MSI files. It also steals Chrome browser credentials and profile information based on C2 server commands.

    Pulse ID: 6aa3fef84a7f54f4ae325151
    Pulse Link: otx.alienvault.com/pulse/6aa3f
    Pulse Author: AlienVault
    Created: 2026-09-11 13:15:36

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #BackDoor #Browser #CAPTCHA #Chrome #Cloud #CyberSecurity #Email #ICS #InfoSec #Korea #LUA #Malware #OTX #OpenThreatExchange #Phishing #PowerShell #ShellCode #SpearPhishing #bot #AlienVault

  6. Mind the (Patch) Gap: Multiple Chinese Threat Actors Chain 0-day Exploits in Chrome & Windows

    In September 2026, two Chinese threat actors, UTA0560 and JungleBamboo, were observed exploiting an identical Chrome zero-day vulnerability chain targeting NGOs and other organizations. The exploitation leveraged CVE-2026-85046 and CVE-2026-87491 in Chrome alongside CVE-2026-85880 in Windows kernel. These vulnerabilities had been patched in Chromium source code but not yet released to Chrome users, creating a patch-gap exploitation window. UTA0560 conducted spear-phishing campaigns using financial lures to deliver GRIMWEDGE JScript backdoor for reconnaissance and command execution. JungleBamboo employed generic phishing themes to deploy SUPERSTOMP loader, which installed the LONGTALE Chrome extension designed for credential theft, keylogging, and surveillance. Both actors used byte-for-byte identical shellcode, suggesting a shared exploit supply chain while deploying distinct post-exploitation tools tailored to their operational objectives.

    Pulse ID: 6aa2707076e8a9dd36706bde
    Pulse Link: otx.alienvault.com/pulse/6aa27
    Pulse Author: AlienVault
    Created: 2026-09-10 08:55:12

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #0Day #BackDoor #Chinese #Chrome #ChromeExtension #CyberSecurity #Edge #InfoSec #OTX #OpenThreatExchange #Phishing #RAT #RCE #ShellCode #SpearPhishing #SupplyChain #Vulnerability #Windows #ZeroDay #bot #AlienVault

  7. Mind the (Patch) Gap: Multiple Chinese Threat Actors Chain 0-day Exploits in Chrome & Windows

    In September 2026, two Chinese threat actors, UTA0560 and JungleBamboo, were observed exploiting an identical Chrome zero-day vulnerability chain targeting NGOs and other organizations. The exploitation leveraged CVE-2026-85046 and CVE-2026-87491 in Chrome alongside CVE-2026-85880 in Windows kernel. These vulnerabilities had been patched in Chromium source code but not yet released to Chrome users, creating a patch-gap exploitation window. UTA0560 conducted spear-phishing campaigns using financial lures to deliver GRIMWEDGE JScript backdoor for reconnaissance and command execution. JungleBamboo employed generic phishing themes to deploy SUPERSTOMP loader, which installed the LONGTALE Chrome extension designed for credential theft, keylogging, and surveillance. Both actors used byte-for-byte identical shellcode, suggesting a shared exploit supply chain while deploying distinct post-exploitation tools tailored to their operational objectives.

    Pulse ID: 6aa2707076e8a9dd36706bde
    Pulse Link: otx.alienvault.com/pulse/6aa27
    Pulse Author: AlienVault
    Created: 2026-09-10 08:55:12

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #0Day #BackDoor #Chinese #Chrome #ChromeExtension #CyberSecurity #Edge #InfoSec #OTX #OpenThreatExchange #Phishing #RAT #RCE #ShellCode #SpearPhishing #SupplyChain #Vulnerability #Windows #ZeroDay #bot #AlienVault

  8. Mind the (Patch) Gap: Multiple Chinese Threat Actors Chain 0-day Exploits in Chrome & Windows

    In September 2026, two Chinese threat actors, UTA0560 and JungleBamboo, were observed exploiting an identical Chrome zero-day vulnerability chain targeting NGOs and other organizations. The exploitation leveraged CVE-2026-85046 and CVE-2026-87491 in Chrome alongside CVE-2026-85880 in Windows kernel. These vulnerabilities had been patched in Chromium source code but not yet released to Chrome users, creating a patch-gap exploitation window. UTA0560 conducted spear-phishing campaigns using financial lures to deliver GRIMWEDGE JScript backdoor for reconnaissance and command execution. JungleBamboo employed generic phishing themes to deploy SUPERSTOMP loader, which installed the LONGTALE Chrome extension designed for credential theft, keylogging, and surveillance. Both actors used byte-for-byte identical shellcode, suggesting a shared exploit supply chain while deploying distinct post-exploitation tools tailored to their operational objectives.

    Pulse ID: 6aa2707076e8a9dd36706bde
    Pulse Link: otx.alienvault.com/pulse/6aa27
    Pulse Author: AlienVault
    Created: 2026-09-10 08:55:12

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #0Day #BackDoor #Chinese #Chrome #ChromeExtension #CyberSecurity #Edge #InfoSec #OTX #OpenThreatExchange #Phishing #RAT #RCE #ShellCode #SpearPhishing #SupplyChain #Vulnerability #Windows #ZeroDay #bot #AlienVault

  9. Mind the (Patch) Gap: Multiple Chinese Threat Actors Chain 0-day Exploits in Chrome & Windows

    In September 2026, two Chinese threat actors, UTA0560 and JungleBamboo, were observed exploiting an identical Chrome zero-day vulnerability chain targeting NGOs and other organizations. The exploitation leveraged CVE-2026-85046 and CVE-2026-87491 in Chrome alongside CVE-2026-85880 in Windows kernel. These vulnerabilities had been patched in Chromium source code but not yet released to Chrome users, creating a patch-gap exploitation window. UTA0560 conducted spear-phishing campaigns using financial lures to deliver GRIMWEDGE JScript backdoor for reconnaissance and command execution. JungleBamboo employed generic phishing themes to deploy SUPERSTOMP loader, which installed the LONGTALE Chrome extension designed for credential theft, keylogging, and surveillance. Both actors used byte-for-byte identical shellcode, suggesting a shared exploit supply chain while deploying distinct post-exploitation tools tailored to their operational objectives.

    Pulse ID: 6aa2707076e8a9dd36706bde
    Pulse Link: otx.alienvault.com/pulse/6aa27
    Pulse Author: AlienVault
    Created: 2026-09-10 08:55:12

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #0Day #BackDoor #Chinese #Chrome #ChromeExtension #CyberSecurity #Edge #InfoSec #OTX #OpenThreatExchange #Phishing #RAT #RCE #ShellCode #SpearPhishing #SupplyChain #Vulnerability #Windows #ZeroDay #bot #AlienVault

  10. Mind the (Patch) Gap: Multiple Chinese Threat Actors Chain 0-day Exploits in Chrome & Windows

    In September 2026, two Chinese threat actors, UTA0560 and JungleBamboo, were observed exploiting an identical Chrome zero-day vulnerability chain targeting NGOs and other organizations. The exploitation leveraged CVE-2026-85046 and CVE-2026-87491 in Chrome alongside CVE-2026-85880 in Windows kernel. These vulnerabilities had been patched in Chromium source code but not yet released to Chrome users, creating a patch-gap exploitation window. UTA0560 conducted spear-phishing campaigns using financial lures to deliver GRIMWEDGE JScript backdoor for reconnaissance and command execution. JungleBamboo employed generic phishing themes to deploy SUPERSTOMP loader, which installed the LONGTALE Chrome extension designed for credential theft, keylogging, and surveillance. Both actors used byte-for-byte identical shellcode, suggesting a shared exploit supply chain while deploying distinct post-exploitation tools tailored to their operational objectives.

    Pulse ID: 6aa2707076e8a9dd36706bde
    Pulse Link: otx.alienvault.com/pulse/6aa27
    Pulse Author: AlienVault
    Created: 2026-09-10 08:55:12

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #0Day #BackDoor #Chinese #Chrome #ChromeExtension #CyberSecurity #Edge #InfoSec #OTX #OpenThreatExchange #Phishing #RAT #RCE #ShellCode #SpearPhishing #SupplyChain #Vulnerability #Windows #ZeroDay #bot #AlienVault

  11. BigBear 2.0: la piattaforma di phishing-as-a-service che aggira anche l’MFA di Microsoft 365

    CloudSEK smaschera BigBear 2.0, un kit AiTM basato su Evilginx2 che ha compromesso 258 organizzazioni in 40 paesi, rubando 474 sessioni con secondo fattore già superato e disabilitando via JavaScript le chiavi di sicurezza FIDO2/WebAuthn.

    insicurezzadigitale.com/bigbea

  12. BigBear 2.0: la piattaforma di phishing-as-a-service che aggira anche l’MFA di Microsoft 365

    CloudSEK smaschera BigBear 2.0, un kit AiTM basato su Evilginx2 che ha compromesso 258 organizzazioni in 40 paesi, rubando 474 sessioni con secondo fattore già superato e disabilitando via JavaScript le chiavi di sicurezza FIDO2/WebAuthn.

    insicurezzadigitale.com/bigbea

  13. BigBear 2.0: la piattaforma di phishing-as-a-service che aggira anche l’MFA di Microsoft 365

    CloudSEK smaschera BigBear 2.0, un kit AiTM basato su Evilginx2 che ha compromesso 258 organizzazioni in 40 paesi, rubando 474 sessioni con secondo fattore già superato e disabilitando via JavaScript le chiavi di sicurezza FIDO2/WebAuthn.

    insicurezzadigitale.com/bigbea

  14. BigBear 2.0: la piattaforma di phishing-as-a-service che aggira anche l’MFA di Microsoft 365

    CloudSEK smaschera BigBear 2.0, un kit AiTM basato su Evilginx2 che ha compromesso 258 organizzazioni in 40 paesi, rubando 474 sessioni con secondo fattore già superato e disabilitando via JavaScript le chiavi di sicurezza FIDO2/WebAuthn.

    insicurezzadigitale.com/bigbea

  15. BigBear 2.0: la piattaforma di phishing-as-a-service che aggira anche l’MFA di Microsoft 365

    CloudSEK smaschera BigBear 2.0, un kit AiTM basato su Evilginx2 che ha compromesso 258 organizzazioni in 40 paesi, rubando 474 sessioni con secondo fattore già superato e disabilitando via JavaScript le chiavi di sicurezza FIDO2/WebAuthn.

    insicurezzadigitale.com/bigbea

  16. Iranian Hackers Deploy Cross-Platform Malware via Coding Tests

    Iranian hackers are using clever tactics to deploy cross-platform malware, disguising it as coding challenges on LinkedIn and other job search platforms to trick developers into installing the threat. This malware, tracked as NodeRabbit and PollCat, can infect Windows, Linux, and macOS workstations, allowing hackers to gain remote…

    osintsights.com/iranian-hacker

    #IranianHackers #Noderabbit #CrossplatformMalware #Spearphishing #Linkedin

  17. July 2026 Threat Trend Report on APT Attacks (South Korea)

    During July 2026, multiple APT campaigns targeted entities in South Korea primarily through spear phishing attacks utilizing LNK files. Seven distinct attack types (A through G) were identified, each employing different techniques including PowerShell scripts, AutoIt programs, curl.exe downloads, and DLL side-loading. Attackers distributed malware through platforms like GitHub, Google Drive, and Dropbox, often disguised as legitimate documents or resumes. These campaigns deployed backdoors, infostealers, keyloggers, and XenoRAT malware to exfiltrate system information, credentials, virtual asset data, and maintain persistent access through Task Scheduler entries. Communications occurred via PubNub channels with data encoded in Base64. The attacks primarily began with phishing emails containing work-related content designed to deceive specific victims into executing malicious files.

    Pulse ID: 6a91687da8e6cd5cc16f64a6
    Pulse Link: otx.alienvault.com/pulse/6a916
    Pulse Author: AlienVault
    Created: 2026-08-28 10:52:45

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Autoit #BackDoor #CyberSecurity #Dropbox #Email #GitHub #Google #InfoSec #InfoStealer #KeyLogger #Korea #LNK #Malware #OTX #OpenThreatExchange #Phishing #PowerShell #RAT #SouthKorea #SpearPhishing #bot #AlienVault

  18. July 2026 Threat Trend Report on APT Attacks (South Korea)

    During July 2026, multiple APT campaigns targeted entities in South Korea primarily through spear phishing attacks utilizing LNK files. Seven distinct attack types (A through G) were identified, each employing different techniques including PowerShell scripts, AutoIt programs, curl.exe downloads, and DLL side-loading. Attackers distributed malware through platforms like GitHub, Google Drive, and Dropbox, often disguised as legitimate documents or resumes. These campaigns deployed backdoors, infostealers, keyloggers, and XenoRAT malware to exfiltrate system information, credentials, virtual asset data, and maintain persistent access through Task Scheduler entries. Communications occurred via PubNub channels with data encoded in Base64. The attacks primarily began with phishing emails containing work-related content designed to deceive specific victims into executing malicious files.

    Pulse ID: 6a91687da8e6cd5cc16f64a6
    Pulse Link: otx.alienvault.com/pulse/6a916
    Pulse Author: AlienVault
    Created: 2026-08-28 10:52:45

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Autoit #BackDoor #CyberSecurity #Dropbox #Email #GitHub #Google #InfoSec #InfoStealer #KeyLogger #Korea #LNK #Malware #OTX #OpenThreatExchange #Phishing #PowerShell #RAT #SouthKorea #SpearPhishing #bot #AlienVault

  19. July 2026 Threat Trend Report on APT Attacks (South Korea)

    During July 2026, multiple APT campaigns targeted entities in South Korea primarily through spear phishing attacks utilizing LNK files. Seven distinct attack types (A through G) were identified, each employing different techniques including PowerShell scripts, AutoIt programs, curl.exe downloads, and DLL side-loading. Attackers distributed malware through platforms like GitHub, Google Drive, and Dropbox, often disguised as legitimate documents or resumes. These campaigns deployed backdoors, infostealers, keyloggers, and XenoRAT malware to exfiltrate system information, credentials, virtual asset data, and maintain persistent access through Task Scheduler entries. Communications occurred via PubNub channels with data encoded in Base64. The attacks primarily began with phishing emails containing work-related content designed to deceive specific victims into executing malicious files.

    Pulse ID: 6a91687da8e6cd5cc16f64a6
    Pulse Link: otx.alienvault.com/pulse/6a916
    Pulse Author: AlienVault
    Created: 2026-08-28 10:52:45

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Autoit #BackDoor #CyberSecurity #Dropbox #Email #GitHub #Google #InfoSec #InfoStealer #KeyLogger #Korea #LNK #Malware #OTX #OpenThreatExchange #Phishing #PowerShell #RAT #SouthKorea #SpearPhishing #bot #AlienVault

  20. July 2026 Threat Trend Report on APT Attacks (South Korea)

    During July 2026, multiple APT campaigns targeted entities in South Korea primarily through spear phishing attacks utilizing LNK files. Seven distinct attack types (A through G) were identified, each employing different techniques including PowerShell scripts, AutoIt programs, curl.exe downloads, and DLL side-loading. Attackers distributed malware through platforms like GitHub, Google Drive, and Dropbox, often disguised as legitimate documents or resumes. These campaigns deployed backdoors, infostealers, keyloggers, and XenoRAT malware to exfiltrate system information, credentials, virtual asset data, and maintain persistent access through Task Scheduler entries. Communications occurred via PubNub channels with data encoded in Base64. The attacks primarily began with phishing emails containing work-related content designed to deceive specific victims into executing malicious files.

    Pulse ID: 6a91687da8e6cd5cc16f64a6
    Pulse Link: otx.alienvault.com/pulse/6a916
    Pulse Author: AlienVault
    Created: 2026-08-28 10:52:45

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Autoit #BackDoor #CyberSecurity #Dropbox #Email #GitHub #Google #InfoSec #InfoStealer #KeyLogger #Korea #LNK #Malware #OTX #OpenThreatExchange #Phishing #PowerShell #RAT #SouthKorea #SpearPhishing #bot #AlienVault

  21. July 2026 Threat Trend Report on APT Attacks (South Korea)

    During July 2026, multiple APT campaigns targeted entities in South Korea primarily through spear phishing attacks utilizing LNK files. Seven distinct attack types (A through G) were identified, each employing different techniques including PowerShell scripts, AutoIt programs, curl.exe downloads, and DLL side-loading. Attackers distributed malware through platforms like GitHub, Google Drive, and Dropbox, often disguised as legitimate documents or resumes. These campaigns deployed backdoors, infostealers, keyloggers, and XenoRAT malware to exfiltrate system information, credentials, virtual asset data, and maintain persistent access through Task Scheduler entries. Communications occurred via PubNub channels with data encoded in Base64. The attacks primarily began with phishing emails containing work-related content designed to deceive specific victims into executing malicious files.

    Pulse ID: 6a91687da8e6cd5cc16f64a6
    Pulse Link: otx.alienvault.com/pulse/6a916
    Pulse Author: AlienVault
    Created: 2026-08-28 10:52:45

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Autoit #BackDoor #CyberSecurity #Dropbox #Email #GitHub #Google #InfoSec #InfoStealer #KeyLogger #Korea #LNK #Malware #OTX #OpenThreatExchange #Phishing #PowerShell #RAT #SouthKorea #SpearPhishing #bot #AlienVault

  22. 📢 Des hackers soutenus par des États ciblent des hauts fonctionnaires de l'UE via WhatsApp

    Le CERT-EU (EU Computer Emergency Response Team) a formellement identifié des campagnes de spearphishing étatique ciblant des hauts fonctionnaires de l'Union européenne via des applications de messagerie, notamment WhatsApp et Signal.

    📖 cyberveille : cyberveille.ch/posts/2026-08-2
    🌐 source : politico.eu/article/hackers-ta
    🟢 vérification factuelle haute
    #CERTEU #spearphishing #Cyberveille

  23. Inside Kimsuky's Abuse of Legitimate Remote Control Tools Across Northeast Asia

    Kimsuky conducted spear phishing campaigns against South Korean and Japanese targets during the first half of 2026, distributing LNK malware through OneDrive share links. The malicious files established scheduled tasks that periodically fetched PowerShell scripts from command-and-control servers to profile systems, exfiltrate Thunderbird and Outlook email data, and log keystrokes. The threat actor installed legitimate remote control software including Chrome Remote Desktop and AnyDesk to evade antivirus detection and maintain multiple access channels. A malicious Chrome extension designed to steal Gmail data exhibited characteristics of AI-generated code, featuring Korean comments, debug strings, and Unicode emoji throughout. The operation employed rotating infrastructure and compromised legitimate Korean servers as command-and-control nodes to impede tracking efforts.

    Pulse ID: 6a873495a873c0ec3c6d9880
    Pulse Link: otx.alienvault.com/pulse/6a873
    Pulse Author: AlienVault
    Created: 2026-08-20 17:08:37

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #AnyDesk #Asia #Chrome #ChromeExtension #CyberSecurity #EDR #Email #ICS #InfoSec #Japan #Kimsuky #Korea #LNK #Malware #OTX #OpenThreatExchange #Outlook #Phishing #PowerShell #RAT #SouthKorea #SpearPhishing #UK #bot #AlienVault

  24. Inside Kimsuky's Abuse of Legitimate Remote Control Tools Across Northeast Asia

    Kimsuky conducted spear phishing campaigns against South Korean and Japanese targets during the first half of 2026, distributing LNK malware through OneDrive share links. The malicious files established scheduled tasks that periodically fetched PowerShell scripts from command-and-control servers to profile systems, exfiltrate Thunderbird and Outlook email data, and log keystrokes. The threat actor installed legitimate remote control software including Chrome Remote Desktop and AnyDesk to evade antivirus detection and maintain multiple access channels. A malicious Chrome extension designed to steal Gmail data exhibited characteristics of AI-generated code, featuring Korean comments, debug strings, and Unicode emoji throughout. The operation employed rotating infrastructure and compromised legitimate Korean servers as command-and-control nodes to impede tracking efforts.

    Pulse ID: 6a873495a873c0ec3c6d9880
    Pulse Link: otx.alienvault.com/pulse/6a873
    Pulse Author: AlienVault
    Created: 2026-08-20 17:08:37

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #AnyDesk #Asia #Chrome #ChromeExtension #CyberSecurity #EDR #Email #ICS #InfoSec #Japan #Kimsuky #Korea #LNK #Malware #OTX #OpenThreatExchange #Outlook #Phishing #PowerShell #RAT #SouthKorea #SpearPhishing #UK #bot #AlienVault

  25. Inside Kimsuky's Abuse of Legitimate Remote Control Tools Across Northeast Asia

    Kimsuky conducted spear phishing campaigns against South Korean and Japanese targets during the first half of 2026, distributing LNK malware through OneDrive share links. The malicious files established scheduled tasks that periodically fetched PowerShell scripts from command-and-control servers to profile systems, exfiltrate Thunderbird and Outlook email data, and log keystrokes. The threat actor installed legitimate remote control software including Chrome Remote Desktop and AnyDesk to evade antivirus detection and maintain multiple access channels. A malicious Chrome extension designed to steal Gmail data exhibited characteristics of AI-generated code, featuring Korean comments, debug strings, and Unicode emoji throughout. The operation employed rotating infrastructure and compromised legitimate Korean servers as command-and-control nodes to impede tracking efforts.

    Pulse ID: 6a873495a873c0ec3c6d9880
    Pulse Link: otx.alienvault.com/pulse/6a873
    Pulse Author: AlienVault
    Created: 2026-08-20 17:08:37

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #AnyDesk #Asia #Chrome #ChromeExtension #CyberSecurity #EDR #Email #ICS #InfoSec #Japan #Kimsuky #Korea #LNK #Malware #OTX #OpenThreatExchange #Outlook #Phishing #PowerShell #RAT #SouthKorea #SpearPhishing #UK #bot #AlienVault

  26. Inside Kimsuky's Abuse of Legitimate Remote Control Tools Across Northeast Asia

    Kimsuky conducted spear phishing campaigns against South Korean and Japanese targets during the first half of 2026, distributing LNK malware through OneDrive share links. The malicious files established scheduled tasks that periodically fetched PowerShell scripts from command-and-control servers to profile systems, exfiltrate Thunderbird and Outlook email data, and log keystrokes. The threat actor installed legitimate remote control software including Chrome Remote Desktop and AnyDesk to evade antivirus detection and maintain multiple access channels. A malicious Chrome extension designed to steal Gmail data exhibited characteristics of AI-generated code, featuring Korean comments, debug strings, and Unicode emoji throughout. The operation employed rotating infrastructure and compromised legitimate Korean servers as command-and-control nodes to impede tracking efforts.

    Pulse ID: 6a873495a873c0ec3c6d9880
    Pulse Link: otx.alienvault.com/pulse/6a873
    Pulse Author: AlienVault
    Created: 2026-08-20 17:08:37

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #AnyDesk #Asia #Chrome #ChromeExtension #CyberSecurity #EDR #Email #ICS #InfoSec #Japan #Kimsuky #Korea #LNK #Malware #OTX #OpenThreatExchange #Outlook #Phishing #PowerShell #RAT #SouthKorea #SpearPhishing #UK #bot #AlienVault

  27. Inside Kimsuky's Abuse of Legitimate Remote Control Tools Across Northeast Asia

    Kimsuky conducted spear phishing campaigns against South Korean and Japanese targets during the first half of 2026, distributing LNK malware through OneDrive share links. The malicious files established scheduled tasks that periodically fetched PowerShell scripts from command-and-control servers to profile systems, exfiltrate Thunderbird and Outlook email data, and log keystrokes. The threat actor installed legitimate remote control software including Chrome Remote Desktop and AnyDesk to evade antivirus detection and maintain multiple access channels. A malicious Chrome extension designed to steal Gmail data exhibited characteristics of AI-generated code, featuring Korean comments, debug strings, and Unicode emoji throughout. The operation employed rotating infrastructure and compromised legitimate Korean servers as command-and-control nodes to impede tracking efforts.

    Pulse ID: 6a873495a873c0ec3c6d9880
    Pulse Link: otx.alienvault.com/pulse/6a873
    Pulse Author: AlienVault
    Created: 2026-08-20 17:08:37

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #AnyDesk #Asia #Chrome #ChromeExtension #CyberSecurity #EDR #Email #ICS #InfoSec #Japan #Kimsuky #Korea #LNK #Malware #OTX #OpenThreatExchange #Outlook #Phishing #PowerShell #RAT #SouthKorea #SpearPhishing #UK #bot #AlienVault

  28. SilkParasite: Tracking a China-Nexus APT Across Central Asia

    SilkParasite is a cyberespionage operation assessed with medium confidence as China-nexus that targeted government bodies across Central Asia. Seven remote access tool families were deployed, five of which were previously undocumented: DriveSilkRAT, CookiETagRAT, NomadRAT, GoginRAT, and NodeEdgeRAT. The toolset is small, modular, and professionally engineered with traces of AI-assisted development. Initial access occurred through malicious Microsoft Office documents delivered via spear-phishing, using regionally tailored lures impersonating government ministries. The operation leveraged DLL sideloading as the primary delivery mechanism and used Google Drive for command-and-control communications to hide within trusted services. Infrastructure analysis identified connections to China Unicom's backbone network, and operational patterns suggest a functioning software organization with maintained build pipelines and careful operational security.

    Pulse ID: 6a86a70eb8b57f155e62d4f7
    Pulse Link: otx.alienvault.com/pulse/6a86a
    Pulse Author: AlienVault
    Created: 2026-08-20 07:04:46

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Asia #CentralAsia #China #CyberSecurity #Cyberespionage #DRat #Edge #Espionage #Google #Government #InfoSec #Microsoft #MicrosoftOffice #OTX #Office #OpenThreatExchange #Phishing #RAT #Rust #SideLoading #SpearPhishing #bot #AlienVault

  29. SilkParasite: Tracking a China-Nexus APT Across Central Asia

    SilkParasite is a cyberespionage operation assessed with medium confidence as China-nexus that targeted government bodies across Central Asia. Seven remote access tool families were deployed, five of which were previously undocumented: DriveSilkRAT, CookiETagRAT, NomadRAT, GoginRAT, and NodeEdgeRAT. The toolset is small, modular, and professionally engineered with traces of AI-assisted development. Initial access occurred through malicious Microsoft Office documents delivered via spear-phishing, using regionally tailored lures impersonating government ministries. The operation leveraged DLL sideloading as the primary delivery mechanism and used Google Drive for command-and-control communications to hide within trusted services. Infrastructure analysis identified connections to China Unicom's backbone network, and operational patterns suggest a functioning software organization with maintained build pipelines and careful operational security.

    Pulse ID: 6a86a70eb8b57f155e62d4f7
    Pulse Link: otx.alienvault.com/pulse/6a86a
    Pulse Author: AlienVault
    Created: 2026-08-20 07:04:46

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Asia #CentralAsia #China #CyberSecurity #Cyberespionage #DRat #Edge #Espionage #Google #Government #InfoSec #Microsoft #MicrosoftOffice #OTX #Office #OpenThreatExchange #Phishing #RAT #Rust #SideLoading #SpearPhishing #bot #AlienVault

  30. SilkParasite: Tracking a China-Nexus APT Across Central Asia

    SilkParasite is a cyberespionage operation assessed with medium confidence as China-nexus that targeted government bodies across Central Asia. Seven remote access tool families were deployed, five of which were previously undocumented: DriveSilkRAT, CookiETagRAT, NomadRAT, GoginRAT, and NodeEdgeRAT. The toolset is small, modular, and professionally engineered with traces of AI-assisted development. Initial access occurred through malicious Microsoft Office documents delivered via spear-phishing, using regionally tailored lures impersonating government ministries. The operation leveraged DLL sideloading as the primary delivery mechanism and used Google Drive for command-and-control communications to hide within trusted services. Infrastructure analysis identified connections to China Unicom's backbone network, and operational patterns suggest a functioning software organization with maintained build pipelines and careful operational security.

    Pulse ID: 6a86a70eb8b57f155e62d4f7
    Pulse Link: otx.alienvault.com/pulse/6a86a
    Pulse Author: AlienVault
    Created: 2026-08-20 07:04:46

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Asia #CentralAsia #China #CyberSecurity #Cyberespionage #DRat #Edge #Espionage #Google #Government #InfoSec #Microsoft #MicrosoftOffice #OTX #Office #OpenThreatExchange #Phishing #RAT #Rust #SideLoading #SpearPhishing #bot #AlienVault

  31. SilkParasite: Tracking a China-Nexus APT Across Central Asia

    SilkParasite is a cyberespionage operation assessed with medium confidence as China-nexus that targeted government bodies across Central Asia. Seven remote access tool families were deployed, five of which were previously undocumented: DriveSilkRAT, CookiETagRAT, NomadRAT, GoginRAT, and NodeEdgeRAT. The toolset is small, modular, and professionally engineered with traces of AI-assisted development. Initial access occurred through malicious Microsoft Office documents delivered via spear-phishing, using regionally tailored lures impersonating government ministries. The operation leveraged DLL sideloading as the primary delivery mechanism and used Google Drive for command-and-control communications to hide within trusted services. Infrastructure analysis identified connections to China Unicom's backbone network, and operational patterns suggest a functioning software organization with maintained build pipelines and careful operational security.

    Pulse ID: 6a86a70eb8b57f155e62d4f7
    Pulse Link: otx.alienvault.com/pulse/6a86a
    Pulse Author: AlienVault
    Created: 2026-08-20 07:04:46

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Asia #CentralAsia #China #CyberSecurity #Cyberespionage #DRat #Edge #Espionage #Google #Government #InfoSec #Microsoft #MicrosoftOffice #OTX #Office #OpenThreatExchange #Phishing #RAT #Rust #SideLoading #SpearPhishing #bot #AlienVault

  32. SilkParasite: Tracking a China-Nexus APT Across Central Asia

    SilkParasite is a cyberespionage operation assessed with medium confidence as China-nexus that targeted government bodies across Central Asia. Seven remote access tool families were deployed, five of which were previously undocumented: DriveSilkRAT, CookiETagRAT, NomadRAT, GoginRAT, and NodeEdgeRAT. The toolset is small, modular, and professionally engineered with traces of AI-assisted development. Initial access occurred through malicious Microsoft Office documents delivered via spear-phishing, using regionally tailored lures impersonating government ministries. The operation leveraged DLL sideloading as the primary delivery mechanism and used Google Drive for command-and-control communications to hide within trusted services. Infrastructure analysis identified connections to China Unicom's backbone network, and operational patterns suggest a functioning software organization with maintained build pipelines and careful operational security.

    Pulse ID: 6a86a70eb8b57f155e62d4f7
    Pulse Link: otx.alienvault.com/pulse/6a86a
    Pulse Author: AlienVault
    Created: 2026-08-20 07:04:46

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Asia #CentralAsia #China #CyberSecurity #Cyberespionage #DRat #Edge #Espionage #Google #Government #InfoSec #Microsoft #MicrosoftOffice #OTX #Office #OpenThreatExchange #Phishing #RAT #Rust #SideLoading #SpearPhishing #bot #AlienVault

  33. #Cyberkriminelle nutzen #KI nicht nur zur Skalierung von #Phishing Mails, sondern auch zur Individualisierung - kombiniert mit #OSINT ein effektives Instrument, um Social Engineering voranzutreiben.

    In einem groß angelegten Feldexperiment mit über 7.700 Beschäftigten der TU Braunschweig haben jetzt Forschende der TU Berlin, von Inria und der Ruhr-Universität Bochum getestet, wie gefährlich automatisiertes #Spearphishing mit Sprachmodellen wirklich ist:

    usenix.org/system/files/confer #cybersecurity

  34. #Cyberkriminelle nutzen #KI nicht nur zur Skalierung von #Phishing Mails, sondern auch zur Individualisierung - kombiniert mit #OSINT ein effektives Instrument, um Social Engineering voranzutreiben.

    In einem groß angelegten Feldexperiment mit über 7.700 Beschäftigten der TU Braunschweig haben jetzt Forschende der TU Berlin, von Inria und der Ruhr-Universität Bochum getestet, wie gefährlich automatisiertes #Spearphishing mit Sprachmodellen wirklich ist:

    usenix.org/system/files/confer #cybersecurity

  35. #Cyberkriminelle nutzen #KI nicht nur zur Skalierung von #Phishing Mails, sondern auch zur Individualisierung - kombiniert mit #OSINT ein effektives Instrument, um Social Engineering voranzutreiben.

    In einem groß angelegten Feldexperiment mit über 7.700 Beschäftigten der TU Braunschweig haben jetzt Forschende der TU Berlin, von Inria und der Ruhr-Universität Bochum getestet, wie gefährlich automatisiertes #Spearphishing mit Sprachmodellen wirklich ist:

    usenix.org/system/files/confer #cybersecurity

  36. #Cyberkriminelle nutzen #KI nicht nur zur Skalierung von #Phishing Mails, sondern auch zur Individualisierung - kombiniert mit #OSINT ein effektives Instrument, um Social Engineering voranzutreiben.

    In einem groß angelegten Feldexperiment mit über 7.700 Beschäftigten der TU Braunschweig haben jetzt Forschende der TU Berlin, von Inria und der Ruhr-Universität Bochum getestet, wie gefährlich automatisiertes #Spearphishing mit Sprachmodellen wirklich ist:

    usenix.org/system/files/confer #cybersecurity

  37. #Cyberkriminelle nutzen #KI nicht nur zur Skalierung von #Phishing Mails, sondern auch zur Individualisierung - kombiniert mit #OSINT ein effektives Instrument, um Social Engineering voranzutreiben.

    In einem groß angelegten Feldexperiment mit über 7.700 Beschäftigten der TU Braunschweig haben jetzt Forschende der TU Berlin, von Inria und der Ruhr-Universität Bochum getestet, wie gefährlich automatisiertes #Spearphishing mit Sprachmodellen wirklich ist:

    usenix.org/system/files/confer #cybersecurity

  38. Xiamen Empress Information Technology: come Pechino ha affittato account LINE per spiare giornalisti e attivisti a Taiwan

    Le autorità taiwanesi hanno incriminato due imprenditori per aver affittato account LINE a Xiamen Empress Information Technology, usati da operatori legati a Pechino per impersonare giornalisti e colpire funzionari, accademici e attivisti. Il caso conferma le inchieste di ICIJ e Citizen Lab sulla repressione transnazionale cinese.

    insicurezzadigitale.com/xiamen

  39. Xiamen Empress Information Technology: come Pechino ha affittato account LINE per spiare giornalisti e attivisti a Taiwan

    Le autorità taiwanesi hanno incriminato due imprenditori per aver affittato account LINE a Xiamen Empress Information Technology, usati da operatori legati a Pechino per impersonare giornalisti e colpire funzionari, accademici e attivisti. Il caso conferma le inchieste di ICIJ e Citizen Lab sulla repressione transnazionale cinese.

    insicurezzadigitale.com/xiamen