#spearphishing — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #spearphishing, aggregated by home.social.
-
Inside Kimsuky's Abuse of Legitimate Remote Control Tools Across Northeast Asia
Kimsuky conducted spear phishing campaigns against South Korean and Japanese targets during the first half of 2026, distributing LNK malware through OneDrive share links. The malicious files established scheduled tasks that periodically fetched PowerShell scripts from command-and-control servers to profile systems, exfiltrate Thunderbird and Outlook email data, and log keystrokes. The threat actor installed legitimate remote control software including Chrome Remote Desktop and AnyDesk to evade antivirus detection and maintain multiple access channels. A malicious Chrome extension designed to steal Gmail data exhibited characteristics of AI-generated code, featuring Korean comments, debug strings, and Unicode emoji throughout. The operation employed rotating infrastructure and compromised legitimate Korean servers as command-and-control nodes to impede tracking efforts.
Pulse ID: 6a873495a873c0ec3c6d9880
Pulse Link: https://otx.alienvault.com/pulse/6a873495a873c0ec3c6d9880
Pulse Author: AlienVault
Created: 2026-08-20 17:08:37Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#AnyDesk #Asia #Chrome #ChromeExtension #CyberSecurity #EDR #Email #ICS #InfoSec #Japan #Kimsuky #Korea #LNK #Malware #OTX #OpenThreatExchange #Outlook #Phishing #PowerShell #RAT #SouthKorea #SpearPhishing #UK #bot #AlienVault
-
SilkParasite: Tracking a China-Nexus APT Across Central Asia
SilkParasite is a cyberespionage operation assessed with medium confidence as China-nexus that targeted government bodies across Central Asia. Seven remote access tool families were deployed, five of which were previously undocumented: DriveSilkRAT, CookiETagRAT, NomadRAT, GoginRAT, and NodeEdgeRAT. The toolset is small, modular, and professionally engineered with traces of AI-assisted development. Initial access occurred through malicious Microsoft Office documents delivered via spear-phishing, using regionally tailored lures impersonating government ministries. The operation leveraged DLL sideloading as the primary delivery mechanism and used Google Drive for command-and-control communications to hide within trusted services. Infrastructure analysis identified connections to China Unicom's backbone network, and operational patterns suggest a functioning software organization with maintained build pipelines and careful operational security.
Pulse ID: 6a86a70eb8b57f155e62d4f7
Pulse Link: https://otx.alienvault.com/pulse/6a86a70eb8b57f155e62d4f7
Pulse Author: AlienVault
Created: 2026-08-20 07:04:46Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Asia #CentralAsia #China #CyberSecurity #Cyberespionage #DRat #Edge #Espionage #Google #Government #InfoSec #Microsoft #MicrosoftOffice #OTX #Office #OpenThreatExchange #Phishing #RAT #Rust #SideLoading #SpearPhishing #bot #AlienVault
-
Iran's Mabna Institute ran a 3-phase spearphishing campaign against university professors for a decade. The 50-page superseding indictmen...
Indicators extracted from public reporting. Source: https://www.reddit.com/r/netsec/comments/1vsrji8/irans_mabna_institute_ran_a_3phase_spearphishing/
Pulse ID: 6a85e02d9151a30aa821db6a
Pulse Link: https://otx.alienvault.com/pulse/6a85e02d9151a30aa821db6a
Pulse Author: CyberHunter_NL
Created: 2026-08-19 16:56:13Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #HTTP #HTTPS #InfoSec #Iran #OTX #OpenThreatExchange #Phishing #RCE #SpearPhishing #bot #CyberHunter_NL
-
#Cyberkriminelle nutzen #KI nicht nur zur Skalierung von #Phishing Mails, sondern auch zur Individualisierung - kombiniert mit #OSINT ein effektives Instrument, um Social Engineering voranzutreiben.
In einem groß angelegten Feldexperiment mit über 7.700 Beschäftigten der TU Braunschweig haben jetzt Forschende der TU Berlin, von Inria und der Ruhr-Universität Bochum getestet, wie gefährlich automatisiertes #Spearphishing mit Sprachmodellen wirklich ist:
https://www.usenix.org/system/files/conference/usenixsecurity26/sec26_prepub_czybik.pdf #cybersecurity
-
El lado del mal - Cómo los Agentes IA de Red Team hacen ataques de Ingeniería Social con Fake Accounts https://www.elladodelmal.com/2026/08/como-los-agentes-ia-de-red-team-hacen.html #IA #AI #AgenticAI #RedTeam #Hacking #Pentest #Pentesting #GitHub #SpearPhishing #IngenieriaSocial
-
Analysis of the Connection Between Xctdoor and Past CRAT Attack Cases
A threat actor designated as Larva-26005, linked to North Korea, has been distributing Xctdoor backdoor malware to users in Korea since at least 2020. The campaign evolved from using CRAT malware alongside Hansom ransomware to deploying Xctdoor variants written in C++ and Go. Distribution methods include spear phishing emails with LNK files disguised as documents and security software installers. The malware utilizes DLL side-loading, deploys multiple script-based droppers, and installs XcLoader and Xctdoor backdoors in AppX package paths. Both CRAT and Xctdoor share identical code obfuscation techniques and installation paths. The backdoors provide comprehensive remote access capabilities including file operations, command execution, keylogging, screenshot capture, and credential theft. Recent attacks target corporate users through compromised web servers and ERP solutions.
Pulse ID: 6a748055fc990bd246b92b6c
Pulse Link: https://otx.alienvault.com/pulse/6a748055fc990bd246b92b6c
Pulse Author: AlienVault
Created: 2026-08-06 12:38:45Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#BackDoor #CyberSecurity #Email #InfoSec #Korea #LNK #Malware #NorthKorea #OTX #OpenThreatExchange #Phishing #RAT #RansomWare #SpearPhishing #bot #AlienVault
-
NightLedger Backdoor Deployed in Espionage Campaign Targeting the Middle East and Africa
An advanced persistent threat group, Mirage Kitten, is conducting cyber-espionage operations across the Middle East and Africa using three previously undocumented malware families: NightLedger, BridgeHead, and ArcBridge. These tools provide reconnaissance, command execution, covert tunneling, and persistent access capabilities. The campaign targets organizations in Egypt, Jordan, Tanzania, Pakistan, Ethiopia, and Burkina Faso across aerospace, aviation, defense, telecommunications, government, financial services, and SMB sectors. Initial access is gained through targeted spear-phishing with recruitment-themed lures and fake videoconferencing pages. The malware demonstrates sophisticated operational security features including victim-specific execution controls, WebSocket-based tunneling, and Cloudflare-backed infrastructure, reflecting the group's investment in bespoke tooling for long-term intelligence collection.
Pulse ID: 6a71aa488c89bfcbd2814692
Pulse Link: https://otx.alienvault.com/pulse/6a71aa488c89bfcbd2814692
Pulse Author: AlienVault
Created: 2026-08-04 09:00:56Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Africa #BackDoor #Cloud #CyberSecurity #Edge #Espionage #Government #InfoSec #Malware #MiddleEast #OTX #OpenThreatExchange #Pakistan #Phishing #RAT #SMB #SpearPhishing #Telecom #Telecommunication #bot #cyberespionage #AlienVault
-
Mirage Kitten targets Middle East and Africa region with new malware
Mirage Kitten, an advanced persistent threat group also known as UNC1549, Smoke Sandstorm, and Nimbus Manticore, has been observed deploying a previously undocumented malware set targeting aerospace, aviation, defense, and telecommunications sectors across the Middle East and Africa. The toolset includes NightLedger, a Windows backdoor with reconnaissance, command execution, file operations, process discovery, and screenshot capture capabilities. Two custom WebSocket-based tunneling tools, ArcBridge and BridgeHead, enable covert network access and operator-controlled tunneling through victim networks. The group employs highly targeted spear-phishing campaigns, fake recruitment portals, and lookalike videoconferencing pages. Victims were identified in Egypt, Jordan, Tanzania, Pakistan, Ethiopia, and Burkina Faso. The malware demonstrates operational security through username-based execution checks and advanced proxy traversal capabilities.
Pulse ID: 6a689c34d4df4bb1475d80c7
Pulse Link: https://otx.alienvault.com/pulse/6a689c34d4df4bb1475d80c7
Pulse Author: AlienVault
Created: 2026-07-28 12:10:28Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Africa #BackDoor #CyberSecurity #Edge #InfoSec #Malware #MiddleEast #Nim #OTX #OpenThreatExchange #Pakistan #Phishing #Proxy #RAT #SpearPhishing #Telecom #Telecommunication #Troll #UNC1549 #Windows #bot #AlienVault
-
June 2026 Threat Trend Report on APT Attacks (South Korea)
AhnLab monitored Advanced Persistent Threat attacks targeting South Korea during June 2026, identifying multiple attack types distributed primarily through spear phishing campaigns. Threat actors disguised malicious files as work-related documents, with LNK files being the most common delivery method. Six distinct attack types were observed, employing various techniques including malicious PowerShell commands, AutoIt malware, curl.exe abuse, GitHub repository exploitation, Task Scheduler persistence, DLL side-loading, and Python backdoors. These attacks deployed Infostealers, keyloggers, backdoors, and remote access tools like XenoRAT. Once executed, the malware established persistence, exfiltrated system information, and enabled remote control of compromised systems. Organizations are advised to verify email senders, avoid opening files from unknown sources, apply security patches, and maintain updated antivirus software to mitigate these persistent threats.
Pulse ID: 6a635bdf995351cf539c3b56
Pulse Link: https://otx.alienvault.com/pulse/6a635bdf995351cf539c3b56
Pulse Author: AlienVault
Created: 2026-07-24 12:34:39Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#AhnLab #Autoit #BackDoor #CyberSecurity #Email #GitHub #InfoSec #InfoStealer #KeyLogger #Korea #LNK #Malware #OTX #OpenThreatExchange #Phishing #PowerShell #Python #RAT #RCE #SouthKorea #SpearPhishing #bot #AlienVault
-
Xiamen Empress Information Technology: come Pechino ha affittato account LINE per spiare giornalisti e attivisti a Taiwan
Le autorità taiwanesi hanno incriminato due imprenditori per aver affittato account LINE a Xiamen Empress Information Technology, usati da operatori legati a Pechino per impersonare giornalisti e colpire funzionari, accademici e attivisti. Il caso conferma le inchieste di ICIJ e Citizen Lab sulla repressione transnazionale cinese. -
Once, during an #awareness session, I brought a jar into the room.
One of those old-school glass jars with a metal lid.
I put it on the table and asked the executives (not the CISOs) to drop a poker chip inside.
Yes, poker chips. Don’t laugh. That’s what I had.
The value of each chip was supposed to reflect two things: perceived risk and willingness to spend.
At the beginning, the jar looked miserable.
Two or three 50s.
One brave 500.
Fewer than ten 100s.Then came lunch.
Paid for, obviously.
But lunch was also the exercise.Heavy #socialengineering. Casual conversation. Names, routines, vendors, habits, internal friction, travel plans, tools, weak points, ego, trust.
Then the last two hours began.
Real risk demonstration.#spearphishing built with information collected during lunch.
Fake WhatsApp chats after recon.
#OSINT before the session even restarted.
QR codes everywhere.Then we talked about recovery costs.
Regulatory fines.
Production downtime.
Loss of trust.
Reputational damage.
The unpleasant difference between “unlikely” and “not impossible”.And, magically, the jar filled up with 500 and 1000 chips.
You don’t fucking say.
My #Decoded for #Baited: https://blog.baited.io/2026/cost-of-phishing-shrinking-budgets/
-
Operation Dragon Weave: l’APT cinese usa Azure Blob Storage come C2 per colpire Repubblica Ceca e Taiwan
Seqrite ha identificato Operation Dragon Weave, una campagna APT attribuita con moderata confidenza a un attore cinese che colpisce funzionari e ricercatori in Repubblica Ceca e Taiwan. Il payload finale AZUREVEIL usa Azure Blob Storage come canale C2 dead-drop, mascherando il traffico malevolo tra le normali comunicazioni cloud enterprise. -
📬 Stalkerware-GAU: 86.859 private Screenshots lagen offen im Netz
#Cyberangriffe #Datenschutz #CloudRepository #Cocospy #KontrollApp #SpearPhishing #Spyic #Spyzie #StalkerwareGAU https://sc.tarnkappe.info/ecf82b -
#Signal reagiert auf deutsche Probleme | heise online https://www.heise.de/news/Signal-Angriffe-Signal-raet-zu-Obacht-und-Registrierungssperre-11274258.html #phishing #SocialEngineering #SpearPhishing #CyberCrime @signalapp
-
Фейковый грант от NED: анатомия таргетированного фишинга
18 февраля 2026 года сотрудник НКО получил таргетированное фишинговое письмо якобы от National Endowment for Democracy — американского фонда поддержки демократии. Обращение по полному имени, ссылка на «предыдущую заявку на грант» (которой никогда не было), и упоминание документа, которого физически нет в письме — классическая техника «фантомного вложения», при которой первое письмо устанавливает доверие, а вредоносный файл приходит уже в ответ на реакцию жертвы. В этой статье — разбор атаки по заголовкам, инфраструктуре и социальной инженерии. Материал будет полезен аналитикам SOC и сотрудникам НКО: в конце — IOC, kill chain и рекомендации для администраторов почты.
https://habr.com/ru/articles/1004156/
#информационная_безопасность #фишинг #spearphishing #threat_intelligence #социальная_инженерия #email_security
-
Фишинг под видом Meta: SPF pass, DKIM pass, входящие Gmail
2 марта 2026 года я получил на анализ фишинговое письмо. Отправитель - «M e t a», тема - «[Требуется действие] Завершите проверку, чтобы восстановить показ объявлений». SPF pass, DKIM pass, ARC pass - письмо прошло все проверки и лежало во входящих Gmail. Ключ - цепочка Resend.com → Amazon SES → Gmail, где каждый элемент легитимен. Разбираю, как атакующие этого добились и почему это работает.
https://habr.com/ru/articles/1005750/
#информационная_безопасность #фишинг #spearphishing #threat_intelligence #социальная_инженерия #email_security
-
Krasser Scheiß: Pine64 (ein Lieferant von uns) hat mich grad darüber informiert, dass anscheinend eine #spearPhishing attacke auf uns vorbereitet worden ist (zumindest stellt es sich mir so dar).
"Tom Milton" hat sich bei dem Lieferanten als neuer "Lead Accountant" vorgestellt.
ich gehe davon aus, dass der liebe Tom dann gefälschte Rechnungen an uns geschickt hätte....
Was denkt ihr?
-
A five-month spearphishing operation discovered by Socket has transformed the npm registry into a durable hosting layer for AiTM credential theft, specifically targeting sales teams in the manufacturing and healthcare industries.
#SecurityLand #Cybersecurity #Research #NPM #Phishing #CriticalInfrastructure #AiTM #Spearphishing #Dev
-
There's a new look to modern day #ransomware attacks (no) thanks to the Ransomware-as-a-Service (#RaaS) ecosystem. As attackers continue to automate spear #phishing and other processes, identifying and mitigating these email threats becomes both more important and more challenging. 😓 So, let's talk about how your team can improve their risk mitigation strategies.
In this article we review:
🎣 Phishing, spear phishing, and whaling
📧 Why ransomware email threats are so successful
🛡️ Best practices for mitigating these threatsDig into the details of implementing email security, centralizing security data, integrating threat intelligence, identifying very attacked persons (VAPs), and more.
https://graylog.org/post/understanding-ransomware-email-threats/ #SpearPhishing #ThreatIntel #SIEM #CyberSecurity
-
🚨 The OpenAI/Mixpanel breach is not just a "vendor issue"—it's a systemic failure. We analyzed 3 years of security incidents at OpenAI and compared them to the fortified architectures of Google Gemini and Anthropic Claude.
#SecurityLand #ExpertDecode #AI #SecurityBreach #Cyberattack #OpenAI #ChatGPT #Claude #Gemini #SpearPhishing #Business #Enterprise #Mixpanel
Read More: https://www.security.land/openai-mixpanel-breach-security-analysis-2025/
-
North Korean hackers are using Google’s own tools to remotely wipe Android devices and hijack messaging apps. Think your account is safe? Dive into how a single breach can trigger a digital meltdown.
#konni
#apt37
#cyberespionage
#androidsecurity
#googlefindhub
#malware
#northkorea
#spearphishing
#infosec