home.social

#spearphishing — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #spearphishing, aggregated by home.social.

fetched live
  1. Analysis of the Connection Between Xctdoor and Past CRAT Attack Cases

    A threat actor designated as Larva-26005, linked to North Korea, has been distributing Xctdoor backdoor malware to users in Korea since at least 2020. The campaign evolved from using CRAT malware alongside Hansom ransomware to deploying Xctdoor variants written in C++ and Go. Distribution methods include spear phishing emails with LNK files disguised as documents and security software installers. The malware utilizes DLL side-loading, deploys multiple script-based droppers, and installs XcLoader and Xctdoor backdoors in AppX package paths. Both CRAT and Xctdoor share identical code obfuscation techniques and installation paths. The backdoors provide comprehensive remote access capabilities including file operations, command execution, keylogging, screenshot capture, and credential theft. Recent attacks target corporate users through compromised web servers and ERP solutions.

    Pulse ID: 6a748055fc990bd246b92b6c
    Pulse Link: otx.alienvault.com/pulse/6a748
    Pulse Author: AlienVault
    Created: 2026-08-06 12:38:45

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #BackDoor #CyberSecurity #Email #InfoSec #Korea #LNK #Malware #NorthKorea #OTX #OpenThreatExchange #Phishing #RAT #RansomWare #SpearPhishing #bot #AlienVault

  2. Analysis of the Connection Between Xctdoor and Past CRAT Attack Cases

    A threat actor designated as Larva-26005, linked to North Korea, has been distributing Xctdoor backdoor malware to users in Korea since at least 2020. The campaign evolved from using CRAT malware alongside Hansom ransomware to deploying Xctdoor variants written in C++ and Go. Distribution methods include spear phishing emails with LNK files disguised as documents and security software installers. The malware utilizes DLL side-loading, deploys multiple script-based droppers, and installs XcLoader and Xctdoor backdoors in AppX package paths. Both CRAT and Xctdoor share identical code obfuscation techniques and installation paths. The backdoors provide comprehensive remote access capabilities including file operations, command execution, keylogging, screenshot capture, and credential theft. Recent attacks target corporate users through compromised web servers and ERP solutions.

    Pulse ID: 6a748055fc990bd246b92b6c
    Pulse Link: otx.alienvault.com/pulse/6a748
    Pulse Author: AlienVault
    Created: 2026-08-06 12:38:45

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #BackDoor #CyberSecurity #Email #InfoSec #Korea #LNK #Malware #NorthKorea #OTX #OpenThreatExchange #Phishing #RAT #RansomWare #SpearPhishing #bot #AlienVault

  3. Analysis of the Connection Between Xctdoor and Past CRAT Attack Cases

    A threat actor designated as Larva-26005, linked to North Korea, has been distributing Xctdoor backdoor malware to users in Korea since at least 2020. The campaign evolved from using CRAT malware alongside Hansom ransomware to deploying Xctdoor variants written in C++ and Go. Distribution methods include spear phishing emails with LNK files disguised as documents and security software installers. The malware utilizes DLL side-loading, deploys multiple script-based droppers, and installs XcLoader and Xctdoor backdoors in AppX package paths. Both CRAT and Xctdoor share identical code obfuscation techniques and installation paths. The backdoors provide comprehensive remote access capabilities including file operations, command execution, keylogging, screenshot capture, and credential theft. Recent attacks target corporate users through compromised web servers and ERP solutions.

    Pulse ID: 6a748055fc990bd246b92b6c
    Pulse Link: otx.alienvault.com/pulse/6a748
    Pulse Author: AlienVault
    Created: 2026-08-06 12:38:45

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #BackDoor #CyberSecurity #Email #InfoSec #Korea #LNK #Malware #NorthKorea #OTX #OpenThreatExchange #Phishing #RAT #RansomWare #SpearPhishing #bot #AlienVault

  4. Analysis of the Connection Between Xctdoor and Past CRAT Attack Cases

    A threat actor designated as Larva-26005, linked to North Korea, has been distributing Xctdoor backdoor malware to users in Korea since at least 2020. The campaign evolved from using CRAT malware alongside Hansom ransomware to deploying Xctdoor variants written in C++ and Go. Distribution methods include spear phishing emails with LNK files disguised as documents and security software installers. The malware utilizes DLL side-loading, deploys multiple script-based droppers, and installs XcLoader and Xctdoor backdoors in AppX package paths. Both CRAT and Xctdoor share identical code obfuscation techniques and installation paths. The backdoors provide comprehensive remote access capabilities including file operations, command execution, keylogging, screenshot capture, and credential theft. Recent attacks target corporate users through compromised web servers and ERP solutions.

    Pulse ID: 6a748055fc990bd246b92b6c
    Pulse Link: otx.alienvault.com/pulse/6a748
    Pulse Author: AlienVault
    Created: 2026-08-06 12:38:45

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #BackDoor #CyberSecurity #Email #InfoSec #Korea #LNK #Malware #NorthKorea #OTX #OpenThreatExchange #Phishing #RAT #RansomWare #SpearPhishing #bot #AlienVault

  5. Analysis of the Connection Between Xctdoor and Past CRAT Attack Cases

    A threat actor designated as Larva-26005, linked to North Korea, has been distributing Xctdoor backdoor malware to users in Korea since at least 2020. The campaign evolved from using CRAT malware alongside Hansom ransomware to deploying Xctdoor variants written in C++ and Go. Distribution methods include spear phishing emails with LNK files disguised as documents and security software installers. The malware utilizes DLL side-loading, deploys multiple script-based droppers, and installs XcLoader and Xctdoor backdoors in AppX package paths. Both CRAT and Xctdoor share identical code obfuscation techniques and installation paths. The backdoors provide comprehensive remote access capabilities including file operations, command execution, keylogging, screenshot capture, and credential theft. Recent attacks target corporate users through compromised web servers and ERP solutions.

    Pulse ID: 6a748055fc990bd246b92b6c
    Pulse Link: otx.alienvault.com/pulse/6a748
    Pulse Author: AlienVault
    Created: 2026-08-06 12:38:45

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #BackDoor #CyberSecurity #Email #InfoSec #Korea #LNK #Malware #NorthKorea #OTX #OpenThreatExchange #Phishing #RAT #RansomWare #SpearPhishing #bot #AlienVault

  6. NightLedger Backdoor Deployed in Espionage Campaign Targeting the Middle East and Africa

    An advanced persistent threat group, Mirage Kitten, is conducting cyber-espionage operations across the Middle East and Africa using three previously undocumented malware families: NightLedger, BridgeHead, and ArcBridge. These tools provide reconnaissance, command execution, covert tunneling, and persistent access capabilities. The campaign targets organizations in Egypt, Jordan, Tanzania, Pakistan, Ethiopia, and Burkina Faso across aerospace, aviation, defense, telecommunications, government, financial services, and SMB sectors. Initial access is gained through targeted spear-phishing with recruitment-themed lures and fake videoconferencing pages. The malware demonstrates sophisticated operational security features including victim-specific execution controls, WebSocket-based tunneling, and Cloudflare-backed infrastructure, reflecting the group's investment in bespoke tooling for long-term intelligence collection.

    Pulse ID: 6a71aa488c89bfcbd2814692
    Pulse Link: otx.alienvault.com/pulse/6a71a
    Pulse Author: AlienVault
    Created: 2026-08-04 09:00:56

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Africa #BackDoor #Cloud #CyberSecurity #Edge #Espionage #Government #InfoSec #Malware #MiddleEast #OTX #OpenThreatExchange #Pakistan #Phishing #RAT #SMB #SpearPhishing #Telecom #Telecommunication #bot #cyberespionage #AlienVault

  7. NightLedger Backdoor Deployed in Espionage Campaign Targeting the Middle East and Africa

    An advanced persistent threat group, Mirage Kitten, is conducting cyber-espionage operations across the Middle East and Africa using three previously undocumented malware families: NightLedger, BridgeHead, and ArcBridge. These tools provide reconnaissance, command execution, covert tunneling, and persistent access capabilities. The campaign targets organizations in Egypt, Jordan, Tanzania, Pakistan, Ethiopia, and Burkina Faso across aerospace, aviation, defense, telecommunications, government, financial services, and SMB sectors. Initial access is gained through targeted spear-phishing with recruitment-themed lures and fake videoconferencing pages. The malware demonstrates sophisticated operational security features including victim-specific execution controls, WebSocket-based tunneling, and Cloudflare-backed infrastructure, reflecting the group's investment in bespoke tooling for long-term intelligence collection.

    Pulse ID: 6a71aa488c89bfcbd2814692
    Pulse Link: otx.alienvault.com/pulse/6a71a
    Pulse Author: AlienVault
    Created: 2026-08-04 09:00:56

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Africa #BackDoor #Cloud #CyberSecurity #Edge #Espionage #Government #InfoSec #Malware #MiddleEast #OTX #OpenThreatExchange #Pakistan #Phishing #RAT #SMB #SpearPhishing #Telecom #Telecommunication #bot #cyberespionage #AlienVault

  8. NightLedger Backdoor Deployed in Espionage Campaign Targeting the Middle East and Africa

    An advanced persistent threat group, Mirage Kitten, is conducting cyber-espionage operations across the Middle East and Africa using three previously undocumented malware families: NightLedger, BridgeHead, and ArcBridge. These tools provide reconnaissance, command execution, covert tunneling, and persistent access capabilities. The campaign targets organizations in Egypt, Jordan, Tanzania, Pakistan, Ethiopia, and Burkina Faso across aerospace, aviation, defense, telecommunications, government, financial services, and SMB sectors. Initial access is gained through targeted spear-phishing with recruitment-themed lures and fake videoconferencing pages. The malware demonstrates sophisticated operational security features including victim-specific execution controls, WebSocket-based tunneling, and Cloudflare-backed infrastructure, reflecting the group's investment in bespoke tooling for long-term intelligence collection.

    Pulse ID: 6a71aa488c89bfcbd2814692
    Pulse Link: otx.alienvault.com/pulse/6a71a
    Pulse Author: AlienVault
    Created: 2026-08-04 09:00:56

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Africa #BackDoor #Cloud #CyberSecurity #Edge #Espionage #Government #InfoSec #Malware #MiddleEast #OTX #OpenThreatExchange #Pakistan #Phishing #RAT #SMB #SpearPhishing #Telecom #Telecommunication #bot #cyberespionage #AlienVault

  9. NightLedger Backdoor Deployed in Espionage Campaign Targeting the Middle East and Africa

    An advanced persistent threat group, Mirage Kitten, is conducting cyber-espionage operations across the Middle East and Africa using three previously undocumented malware families: NightLedger, BridgeHead, and ArcBridge. These tools provide reconnaissance, command execution, covert tunneling, and persistent access capabilities. The campaign targets organizations in Egypt, Jordan, Tanzania, Pakistan, Ethiopia, and Burkina Faso across aerospace, aviation, defense, telecommunications, government, financial services, and SMB sectors. Initial access is gained through targeted spear-phishing with recruitment-themed lures and fake videoconferencing pages. The malware demonstrates sophisticated operational security features including victim-specific execution controls, WebSocket-based tunneling, and Cloudflare-backed infrastructure, reflecting the group's investment in bespoke tooling for long-term intelligence collection.

    Pulse ID: 6a71aa488c89bfcbd2814692
    Pulse Link: otx.alienvault.com/pulse/6a71a
    Pulse Author: AlienVault
    Created: 2026-08-04 09:00:56

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Africa #BackDoor #Cloud #CyberSecurity #Edge #Espionage #Government #InfoSec #Malware #MiddleEast #OTX #OpenThreatExchange #Pakistan #Phishing #RAT #SMB #SpearPhishing #Telecom #Telecommunication #bot #cyberespionage #AlienVault

  10. NightLedger Backdoor Deployed in Espionage Campaign Targeting the Middle East and Africa

    An advanced persistent threat group, Mirage Kitten, is conducting cyber-espionage operations across the Middle East and Africa using three previously undocumented malware families: NightLedger, BridgeHead, and ArcBridge. These tools provide reconnaissance, command execution, covert tunneling, and persistent access capabilities. The campaign targets organizations in Egypt, Jordan, Tanzania, Pakistan, Ethiopia, and Burkina Faso across aerospace, aviation, defense, telecommunications, government, financial services, and SMB sectors. Initial access is gained through targeted spear-phishing with recruitment-themed lures and fake videoconferencing pages. The malware demonstrates sophisticated operational security features including victim-specific execution controls, WebSocket-based tunneling, and Cloudflare-backed infrastructure, reflecting the group's investment in bespoke tooling for long-term intelligence collection.

    Pulse ID: 6a71aa488c89bfcbd2814692
    Pulse Link: otx.alienvault.com/pulse/6a71a
    Pulse Author: AlienVault
    Created: 2026-08-04 09:00:56

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Africa #BackDoor #Cloud #CyberSecurity #Edge #Espionage #Government #InfoSec #Malware #MiddleEast #OTX #OpenThreatExchange #Pakistan #Phishing #RAT #SMB #SpearPhishing #Telecom #Telecommunication #bot #cyberespionage #AlienVault

  11. Mirage Kitten targets Middle East and Africa region with new malware

    Mirage Kitten, an advanced persistent threat group also known as UNC1549, Smoke Sandstorm, and Nimbus Manticore, has been observed deploying a previously undocumented malware set targeting aerospace, aviation, defense, and telecommunications sectors across the Middle East and Africa. The toolset includes NightLedger, a Windows backdoor with reconnaissance, command execution, file operations, process discovery, and screenshot capture capabilities. Two custom WebSocket-based tunneling tools, ArcBridge and BridgeHead, enable covert network access and operator-controlled tunneling through victim networks. The group employs highly targeted spear-phishing campaigns, fake recruitment portals, and lookalike videoconferencing pages. Victims were identified in Egypt, Jordan, Tanzania, Pakistan, Ethiopia, and Burkina Faso. The malware demonstrates operational security through username-based execution checks and advanced proxy traversal capabilities.

    Pulse ID: 6a689c34d4df4bb1475d80c7
    Pulse Link: otx.alienvault.com/pulse/6a689
    Pulse Author: AlienVault
    Created: 2026-07-28 12:10:28

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Africa #BackDoor #CyberSecurity #Edge #InfoSec #Malware #MiddleEast #Nim #OTX #OpenThreatExchange #Pakistan #Phishing #Proxy #RAT #SpearPhishing #Telecom #Telecommunication #Troll #UNC1549 #Windows #bot #AlienVault

  12. Mirage Kitten targets Middle East and Africa region with new malware

    Mirage Kitten, an advanced persistent threat group also known as UNC1549, Smoke Sandstorm, and Nimbus Manticore, has been observed deploying a previously undocumented malware set targeting aerospace, aviation, defense, and telecommunications sectors across the Middle East and Africa. The toolset includes NightLedger, a Windows backdoor with reconnaissance, command execution, file operations, process discovery, and screenshot capture capabilities. Two custom WebSocket-based tunneling tools, ArcBridge and BridgeHead, enable covert network access and operator-controlled tunneling through victim networks. The group employs highly targeted spear-phishing campaigns, fake recruitment portals, and lookalike videoconferencing pages. Victims were identified in Egypt, Jordan, Tanzania, Pakistan, Ethiopia, and Burkina Faso. The malware demonstrates operational security through username-based execution checks and advanced proxy traversal capabilities.

    Pulse ID: 6a689c34d4df4bb1475d80c7
    Pulse Link: otx.alienvault.com/pulse/6a689
    Pulse Author: AlienVault
    Created: 2026-07-28 12:10:28

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Africa #BackDoor #CyberSecurity #Edge #InfoSec #Malware #MiddleEast #Nim #OTX #OpenThreatExchange #Pakistan #Phishing #Proxy #RAT #SpearPhishing #Telecom #Telecommunication #Troll #UNC1549 #Windows #bot #AlienVault

  13. Mirage Kitten targets Middle East and Africa region with new malware

    Mirage Kitten, an advanced persistent threat group also known as UNC1549, Smoke Sandstorm, and Nimbus Manticore, has been observed deploying a previously undocumented malware set targeting aerospace, aviation, defense, and telecommunications sectors across the Middle East and Africa. The toolset includes NightLedger, a Windows backdoor with reconnaissance, command execution, file operations, process discovery, and screenshot capture capabilities. Two custom WebSocket-based tunneling tools, ArcBridge and BridgeHead, enable covert network access and operator-controlled tunneling through victim networks. The group employs highly targeted spear-phishing campaigns, fake recruitment portals, and lookalike videoconferencing pages. Victims were identified in Egypt, Jordan, Tanzania, Pakistan, Ethiopia, and Burkina Faso. The malware demonstrates operational security through username-based execution checks and advanced proxy traversal capabilities.

    Pulse ID: 6a689c34d4df4bb1475d80c7
    Pulse Link: otx.alienvault.com/pulse/6a689
    Pulse Author: AlienVault
    Created: 2026-07-28 12:10:28

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Africa #BackDoor #CyberSecurity #Edge #InfoSec #Malware #MiddleEast #Nim #OTX #OpenThreatExchange #Pakistan #Phishing #Proxy #RAT #SpearPhishing #Telecom #Telecommunication #Troll #UNC1549 #Windows #bot #AlienVault

  14. Mirage Kitten targets Middle East and Africa region with new malware

    Mirage Kitten, an advanced persistent threat group also known as UNC1549, Smoke Sandstorm, and Nimbus Manticore, has been observed deploying a previously undocumented malware set targeting aerospace, aviation, defense, and telecommunications sectors across the Middle East and Africa. The toolset includes NightLedger, a Windows backdoor with reconnaissance, command execution, file operations, process discovery, and screenshot capture capabilities. Two custom WebSocket-based tunneling tools, ArcBridge and BridgeHead, enable covert network access and operator-controlled tunneling through victim networks. The group employs highly targeted spear-phishing campaigns, fake recruitment portals, and lookalike videoconferencing pages. Victims were identified in Egypt, Jordan, Tanzania, Pakistan, Ethiopia, and Burkina Faso. The malware demonstrates operational security through username-based execution checks and advanced proxy traversal capabilities.

    Pulse ID: 6a689c34d4df4bb1475d80c7
    Pulse Link: otx.alienvault.com/pulse/6a689
    Pulse Author: AlienVault
    Created: 2026-07-28 12:10:28

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Africa #BackDoor #CyberSecurity #Edge #InfoSec #Malware #MiddleEast #Nim #OTX #OpenThreatExchange #Pakistan #Phishing #Proxy #RAT #SpearPhishing #Telecom #Telecommunication #Troll #UNC1549 #Windows #bot #AlienVault

  15. Mirage Kitten targets Middle East and Africa region with new malware

    Mirage Kitten, an advanced persistent threat group also known as UNC1549, Smoke Sandstorm, and Nimbus Manticore, has been observed deploying a previously undocumented malware set targeting aerospace, aviation, defense, and telecommunications sectors across the Middle East and Africa. The toolset includes NightLedger, a Windows backdoor with reconnaissance, command execution, file operations, process discovery, and screenshot capture capabilities. Two custom WebSocket-based tunneling tools, ArcBridge and BridgeHead, enable covert network access and operator-controlled tunneling through victim networks. The group employs highly targeted spear-phishing campaigns, fake recruitment portals, and lookalike videoconferencing pages. Victims were identified in Egypt, Jordan, Tanzania, Pakistan, Ethiopia, and Burkina Faso. The malware demonstrates operational security through username-based execution checks and advanced proxy traversal capabilities.

    Pulse ID: 6a689c34d4df4bb1475d80c7
    Pulse Link: otx.alienvault.com/pulse/6a689
    Pulse Author: AlienVault
    Created: 2026-07-28 12:10:28

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Africa #BackDoor #CyberSecurity #Edge #InfoSec #Malware #MiddleEast #Nim #OTX #OpenThreatExchange #Pakistan #Phishing #Proxy #RAT #SpearPhishing #Telecom #Telecommunication #Troll #UNC1549 #Windows #bot #AlienVault

  16. June 2026 Threat Trend Report on APT Attacks (South Korea)

    AhnLab monitored Advanced Persistent Threat attacks targeting South Korea during June 2026, identifying multiple attack types distributed primarily through spear phishing campaigns. Threat actors disguised malicious files as work-related documents, with LNK files being the most common delivery method. Six distinct attack types were observed, employing various techniques including malicious PowerShell commands, AutoIt malware, curl.exe abuse, GitHub repository exploitation, Task Scheduler persistence, DLL side-loading, and Python backdoors. These attacks deployed Infostealers, keyloggers, backdoors, and remote access tools like XenoRAT. Once executed, the malware established persistence, exfiltrated system information, and enabled remote control of compromised systems. Organizations are advised to verify email senders, avoid opening files from unknown sources, apply security patches, and maintain updated antivirus software to mitigate these persistent threats.

    Pulse ID: 6a635bdf995351cf539c3b56
    Pulse Link: otx.alienvault.com/pulse/6a635
    Pulse Author: AlienVault
    Created: 2026-07-24 12:34:39

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #AhnLab #Autoit #BackDoor #CyberSecurity #Email #GitHub #InfoSec #InfoStealer #KeyLogger #Korea #LNK #Malware #OTX #OpenThreatExchange #Phishing #PowerShell #Python #RAT #RCE #SouthKorea #SpearPhishing #bot #AlienVault

  17. June 2026 Threat Trend Report on APT Attacks (South Korea)

    AhnLab monitored Advanced Persistent Threat attacks targeting South Korea during June 2026, identifying multiple attack types distributed primarily through spear phishing campaigns. Threat actors disguised malicious files as work-related documents, with LNK files being the most common delivery method. Six distinct attack types were observed, employing various techniques including malicious PowerShell commands, AutoIt malware, curl.exe abuse, GitHub repository exploitation, Task Scheduler persistence, DLL side-loading, and Python backdoors. These attacks deployed Infostealers, keyloggers, backdoors, and remote access tools like XenoRAT. Once executed, the malware established persistence, exfiltrated system information, and enabled remote control of compromised systems. Organizations are advised to verify email senders, avoid opening files from unknown sources, apply security patches, and maintain updated antivirus software to mitigate these persistent threats.

    Pulse ID: 6a635bdf995351cf539c3b56
    Pulse Link: otx.alienvault.com/pulse/6a635
    Pulse Author: AlienVault
    Created: 2026-07-24 12:34:39

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #AhnLab #Autoit #BackDoor #CyberSecurity #Email #GitHub #InfoSec #InfoStealer #KeyLogger #Korea #LNK #Malware #OTX #OpenThreatExchange #Phishing #PowerShell #Python #RAT #RCE #SouthKorea #SpearPhishing #bot #AlienVault

  18. June 2026 Threat Trend Report on APT Attacks (South Korea)

    AhnLab monitored Advanced Persistent Threat attacks targeting South Korea during June 2026, identifying multiple attack types distributed primarily through spear phishing campaigns. Threat actors disguised malicious files as work-related documents, with LNK files being the most common delivery method. Six distinct attack types were observed, employing various techniques including malicious PowerShell commands, AutoIt malware, curl.exe abuse, GitHub repository exploitation, Task Scheduler persistence, DLL side-loading, and Python backdoors. These attacks deployed Infostealers, keyloggers, backdoors, and remote access tools like XenoRAT. Once executed, the malware established persistence, exfiltrated system information, and enabled remote control of compromised systems. Organizations are advised to verify email senders, avoid opening files from unknown sources, apply security patches, and maintain updated antivirus software to mitigate these persistent threats.

    Pulse ID: 6a635bdf995351cf539c3b56
    Pulse Link: otx.alienvault.com/pulse/6a635
    Pulse Author: AlienVault
    Created: 2026-07-24 12:34:39

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #AhnLab #Autoit #BackDoor #CyberSecurity #Email #GitHub #InfoSec #InfoStealer #KeyLogger #Korea #LNK #Malware #OTX #OpenThreatExchange #Phishing #PowerShell #Python #RAT #RCE #SouthKorea #SpearPhishing #bot #AlienVault

  19. June 2026 Threat Trend Report on APT Attacks (South Korea)

    AhnLab monitored Advanced Persistent Threat attacks targeting South Korea during June 2026, identifying multiple attack types distributed primarily through spear phishing campaigns. Threat actors disguised malicious files as work-related documents, with LNK files being the most common delivery method. Six distinct attack types were observed, employing various techniques including malicious PowerShell commands, AutoIt malware, curl.exe abuse, GitHub repository exploitation, Task Scheduler persistence, DLL side-loading, and Python backdoors. These attacks deployed Infostealers, keyloggers, backdoors, and remote access tools like XenoRAT. Once executed, the malware established persistence, exfiltrated system information, and enabled remote control of compromised systems. Organizations are advised to verify email senders, avoid opening files from unknown sources, apply security patches, and maintain updated antivirus software to mitigate these persistent threats.

    Pulse ID: 6a635bdf995351cf539c3b56
    Pulse Link: otx.alienvault.com/pulse/6a635
    Pulse Author: AlienVault
    Created: 2026-07-24 12:34:39

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #AhnLab #Autoit #BackDoor #CyberSecurity #Email #GitHub #InfoSec #InfoStealer #KeyLogger #Korea #LNK #Malware #OTX #OpenThreatExchange #Phishing #PowerShell #Python #RAT #RCE #SouthKorea #SpearPhishing #bot #AlienVault

  20. June 2026 Threat Trend Report on APT Attacks (South Korea)

    AhnLab monitored Advanced Persistent Threat attacks targeting South Korea during June 2026, identifying multiple attack types distributed primarily through spear phishing campaigns. Threat actors disguised malicious files as work-related documents, with LNK files being the most common delivery method. Six distinct attack types were observed, employing various techniques including malicious PowerShell commands, AutoIt malware, curl.exe abuse, GitHub repository exploitation, Task Scheduler persistence, DLL side-loading, and Python backdoors. These attacks deployed Infostealers, keyloggers, backdoors, and remote access tools like XenoRAT. Once executed, the malware established persistence, exfiltrated system information, and enabled remote control of compromised systems. Organizations are advised to verify email senders, avoid opening files from unknown sources, apply security patches, and maintain updated antivirus software to mitigate these persistent threats.

    Pulse ID: 6a635bdf995351cf539c3b56
    Pulse Link: otx.alienvault.com/pulse/6a635
    Pulse Author: AlienVault
    Created: 2026-07-24 12:34:39

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #AhnLab #Autoit #BackDoor #CyberSecurity #Email #GitHub #InfoSec #InfoStealer #KeyLogger #Korea #LNK #Malware #OTX #OpenThreatExchange #Phishing #PowerShell #Python #RAT #RCE #SouthKorea #SpearPhishing #bot #AlienVault

  21. Analysis of Kimsuky's Attack on a South Korean Groupware Vendor Using a New Gomir Family Variant

    Between 2025 and early 2026, the North Korean-linked Kimsuky group infiltrated South Korean groupware vendors through vulnerability exploitation and spear-phishing. They deployed two new malware variants, BirdTroy and DriveTroy, based on the Gomir/HttpTroy family. BirdTroy uses custom protocols and HTTP/3 (QUIC) for command-and-control communication, while DriveTroy abuses Google Drive as a C2 channel to evade detection. Following initial compromise, Kimsuky conducted aggressive lateral movement, compromising customer groupware servers and tampering with vendor login pages to harvest credentials. The attackers leveraged legitimate tools like DWAgent for remote access and custom proxy tools for lateral movement. Attribution is supported by malware characteristics, infrastructure patterns including default XAMPP certificates, and historical ASN usage consistent with previous Kimsuky operations.

    Pulse ID: 6a5e7a9e8b20b763327b0d2d
    Pulse Link: otx.alienvault.com/pulse/6a5e7
    Pulse Author: AlienVault
    Created: 2026-07-20 19:44:30

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #Google #HTTP #ICS #InfoSec #Kimsuky #Korea #Malware #NorthKorea #OTX #OpenThreatExchange #Phishing #Proxy #RAT #SouthKorea #SpearPhishing #UK #Vulnerability #bot #AlienVault

  22. Analysis of Kimsuky's Attack on a South Korean Groupware Vendor Using a New Gomir Family Variant

    Between 2025 and early 2026, the North Korean-linked Kimsuky group infiltrated South Korean groupware vendors through vulnerability exploitation and spear-phishing. They deployed two new malware variants, BirdTroy and DriveTroy, based on the Gomir/HttpTroy family. BirdTroy uses custom protocols and HTTP/3 (QUIC) for command-and-control communication, while DriveTroy abuses Google Drive as a C2 channel to evade detection. Following initial compromise, Kimsuky conducted aggressive lateral movement, compromising customer groupware servers and tampering with vendor login pages to harvest credentials. The attackers leveraged legitimate tools like DWAgent for remote access and custom proxy tools for lateral movement. Attribution is supported by malware characteristics, infrastructure patterns including default XAMPP certificates, and historical ASN usage consistent with previous Kimsuky operations.

    Pulse ID: 6a5e7a9e8b20b763327b0d2d
    Pulse Link: otx.alienvault.com/pulse/6a5e7
    Pulse Author: AlienVault
    Created: 2026-07-20 19:44:30

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #Google #HTTP #ICS #InfoSec #Kimsuky #Korea #Malware #NorthKorea #OTX #OpenThreatExchange #Phishing #Proxy #RAT #SouthKorea #SpearPhishing #UK #Vulnerability #bot #AlienVault

  23. Analysis of Kimsuky's Attack on a South Korean Groupware Vendor Using a New Gomir Family Variant

    Between 2025 and early 2026, the North Korean-linked Kimsuky group infiltrated South Korean groupware vendors through vulnerability exploitation and spear-phishing. They deployed two new malware variants, BirdTroy and DriveTroy, based on the Gomir/HttpTroy family. BirdTroy uses custom protocols and HTTP/3 (QUIC) for command-and-control communication, while DriveTroy abuses Google Drive as a C2 channel to evade detection. Following initial compromise, Kimsuky conducted aggressive lateral movement, compromising customer groupware servers and tampering with vendor login pages to harvest credentials. The attackers leveraged legitimate tools like DWAgent for remote access and custom proxy tools for lateral movement. Attribution is supported by malware characteristics, infrastructure patterns including default XAMPP certificates, and historical ASN usage consistent with previous Kimsuky operations.

    Pulse ID: 6a5e7a9e8b20b763327b0d2d
    Pulse Link: otx.alienvault.com/pulse/6a5e7
    Pulse Author: AlienVault
    Created: 2026-07-20 19:44:30

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #Google #HTTP #ICS #InfoSec #Kimsuky #Korea #Malware #NorthKorea #OTX #OpenThreatExchange #Phishing #Proxy #RAT #SouthKorea #SpearPhishing #UK #Vulnerability #bot #AlienVault

  24. Analysis of Kimsuky's Attack on a South Korean Groupware Vendor Using a New Gomir Family Variant

    Between 2025 and early 2026, the North Korean-linked Kimsuky group infiltrated South Korean groupware vendors through vulnerability exploitation and spear-phishing. They deployed two new malware variants, BirdTroy and DriveTroy, based on the Gomir/HttpTroy family. BirdTroy uses custom protocols and HTTP/3 (QUIC) for command-and-control communication, while DriveTroy abuses Google Drive as a C2 channel to evade detection. Following initial compromise, Kimsuky conducted aggressive lateral movement, compromising customer groupware servers and tampering with vendor login pages to harvest credentials. The attackers leveraged legitimate tools like DWAgent for remote access and custom proxy tools for lateral movement. Attribution is supported by malware characteristics, infrastructure patterns including default XAMPP certificates, and historical ASN usage consistent with previous Kimsuky operations.

    Pulse ID: 6a5e7a9e8b20b763327b0d2d
    Pulse Link: otx.alienvault.com/pulse/6a5e7
    Pulse Author: AlienVault
    Created: 2026-07-20 19:44:30

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #Google #HTTP #ICS #InfoSec #Kimsuky #Korea #Malware #NorthKorea #OTX #OpenThreatExchange #Phishing #Proxy #RAT #SouthKorea #SpearPhishing #UK #Vulnerability #bot #AlienVault

  25. Analysis of Kimsuky's Attack on a South Korean Groupware Vendor Using a New Gomir Family Variant

    Between 2025 and early 2026, the North Korean-linked Kimsuky group infiltrated South Korean groupware vendors through vulnerability exploitation and spear-phishing. They deployed two new malware variants, BirdTroy and DriveTroy, based on the Gomir/HttpTroy family. BirdTroy uses custom protocols and HTTP/3 (QUIC) for command-and-control communication, while DriveTroy abuses Google Drive as a C2 channel to evade detection. Following initial compromise, Kimsuky conducted aggressive lateral movement, compromising customer groupware servers and tampering with vendor login pages to harvest credentials. The attackers leveraged legitimate tools like DWAgent for remote access and custom proxy tools for lateral movement. Attribution is supported by malware characteristics, infrastructure patterns including default XAMPP certificates, and historical ASN usage consistent with previous Kimsuky operations.

    Pulse ID: 6a5e7a9e8b20b763327b0d2d
    Pulse Link: otx.alienvault.com/pulse/6a5e7
    Pulse Author: AlienVault
    Created: 2026-07-20 19:44:30

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #Google #HTTP #ICS #InfoSec #Kimsuky #Korea #Malware #NorthKorea #OTX #OpenThreatExchange #Phishing #Proxy #RAT #SouthKorea #SpearPhishing #UK #Vulnerability #bot #AlienVault

  26. Update on Attacks by Threat Group APT-C-60 in 2026

    APT-C-60 continues targeting organizations in Japan with evolved tactics observed throughout 2026. The threat group employs spear-phishing emails containing Proton Drive links or direct attachments with RAR archives. Victims extract LNK files that execute JavaScript via mshta.exe, leading to multi-stage payload delivery. The attackers abuse legitimate services including GitHub, GitLab, jsDelivr, and Codeberg as infrastructure for hosting malicious components. Git.exe is leveraged to execute scripts that deploy downloaders and loaders, ultimately delivering SpyGlace malware versions 3.1.15 through 3.1.18. The attack chain involves multiple obfuscated JavaScript files and persistence mechanisms similar to previous campaigns. By utilizing developer-oriented services and CDNs commonly allowed in corporate environments, the threat actor attempts to evade detection and blend malicious traffic with legitimate communications.

    Pulse ID: 6a54e01e0597d81e8ad9f7d0
    Pulse Link: otx.alienvault.com/pulse/6a54e
    Pulse Author: AlienVault
    Created: 2026-07-13 12:54:54

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CDN #CyberSecurity #DNS #Email #GitHub #ICS #InfoSec #Japan #Java #JavaScript #LNK #Malware #OTX #OpenThreatExchange #Phishing #RAT #SMS #SpearPhishing #bot #AlienVault

  27. Update on Attacks by Threat Group APT-C-60 in 2026

    APT-C-60 continues targeting organizations in Japan with evolved tactics observed throughout 2026. The threat group employs spear-phishing emails containing Proton Drive links or direct attachments with RAR archives. Victims extract LNK files that execute JavaScript via mshta.exe, leading to multi-stage payload delivery. The attackers abuse legitimate services including GitHub, GitLab, jsDelivr, and Codeberg as infrastructure for hosting malicious components. Git.exe is leveraged to execute scripts that deploy downloaders and loaders, ultimately delivering SpyGlace malware versions 3.1.15 through 3.1.18. The attack chain involves multiple obfuscated JavaScript files and persistence mechanisms similar to previous campaigns. By utilizing developer-oriented services and CDNs commonly allowed in corporate environments, the threat actor attempts to evade detection and blend malicious traffic with legitimate communications.

    Pulse ID: 6a54e01e0597d81e8ad9f7d0
    Pulse Link: otx.alienvault.com/pulse/6a54e
    Pulse Author: AlienVault
    Created: 2026-07-13 12:54:54

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CDN #CyberSecurity #DNS #Email #GitHub #ICS #InfoSec #Japan #Java #JavaScript #LNK #Malware #OTX #OpenThreatExchange #Phishing #RAT #SMS #SpearPhishing #bot #AlienVault

  28. Update on Attacks by Threat Group APT-C-60 in 2026

    APT-C-60 continues targeting organizations in Japan with evolved tactics observed throughout 2026. The threat group employs spear-phishing emails containing Proton Drive links or direct attachments with RAR archives. Victims extract LNK files that execute JavaScript via mshta.exe, leading to multi-stage payload delivery. The attackers abuse legitimate services including GitHub, GitLab, jsDelivr, and Codeberg as infrastructure for hosting malicious components. Git.exe is leveraged to execute scripts that deploy downloaders and loaders, ultimately delivering SpyGlace malware versions 3.1.15 through 3.1.18. The attack chain involves multiple obfuscated JavaScript files and persistence mechanisms similar to previous campaigns. By utilizing developer-oriented services and CDNs commonly allowed in corporate environments, the threat actor attempts to evade detection and blend malicious traffic with legitimate communications.

    Pulse ID: 6a54e01e0597d81e8ad9f7d0
    Pulse Link: otx.alienvault.com/pulse/6a54e
    Pulse Author: AlienVault
    Created: 2026-07-13 12:54:54

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CDN #CyberSecurity #DNS #Email #GitHub #ICS #InfoSec #Japan #Java #JavaScript #LNK #Malware #OTX #OpenThreatExchange #Phishing #RAT #SMS #SpearPhishing #bot #AlienVault

  29. Update on Attacks by Threat Group APT-C-60 in 2026

    APT-C-60 continues targeting organizations in Japan with evolved tactics observed throughout 2026. The threat group employs spear-phishing emails containing Proton Drive links or direct attachments with RAR archives. Victims extract LNK files that execute JavaScript via mshta.exe, leading to multi-stage payload delivery. The attackers abuse legitimate services including GitHub, GitLab, jsDelivr, and Codeberg as infrastructure for hosting malicious components. Git.exe is leveraged to execute scripts that deploy downloaders and loaders, ultimately delivering SpyGlace malware versions 3.1.15 through 3.1.18. The attack chain involves multiple obfuscated JavaScript files and persistence mechanisms similar to previous campaigns. By utilizing developer-oriented services and CDNs commonly allowed in corporate environments, the threat actor attempts to evade detection and blend malicious traffic with legitimate communications.

    Pulse ID: 6a54e01e0597d81e8ad9f7d0
    Pulse Link: otx.alienvault.com/pulse/6a54e
    Pulse Author: AlienVault
    Created: 2026-07-13 12:54:54

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CDN #CyberSecurity #DNS #Email #GitHub #ICS #InfoSec #Japan #Java #JavaScript #LNK #Malware #OTX #OpenThreatExchange #Phishing #RAT #SMS #SpearPhishing #bot #AlienVault

  30. Update on Attacks by Threat Group APT-C-60 in 2026

    APT-C-60 continues targeting organizations in Japan with evolved tactics observed throughout 2026. The threat group employs spear-phishing emails containing Proton Drive links or direct attachments with RAR archives. Victims extract LNK files that execute JavaScript via mshta.exe, leading to multi-stage payload delivery. The attackers abuse legitimate services including GitHub, GitLab, jsDelivr, and Codeberg as infrastructure for hosting malicious components. Git.exe is leveraged to execute scripts that deploy downloaders and loaders, ultimately delivering SpyGlace malware versions 3.1.15 through 3.1.18. The attack chain involves multiple obfuscated JavaScript files and persistence mechanisms similar to previous campaigns. By utilizing developer-oriented services and CDNs commonly allowed in corporate environments, the threat actor attempts to evade detection and blend malicious traffic with legitimate communications.

    Pulse ID: 6a54e01e0597d81e8ad9f7d0
    Pulse Link: otx.alienvault.com/pulse/6a54e
    Pulse Author: AlienVault
    Created: 2026-07-13 12:54:54

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CDN #CyberSecurity #DNS #Email #GitHub #ICS #InfoSec #Japan #Java #JavaScript #LNK #Malware #OTX #OpenThreatExchange #Phishing #RAT #SMS #SpearPhishing #bot #AlienVault

  31. Operation Capsule Vault: RokRAT Attack Chain Analysis Using EMBED_PAYLOAD_v2

    A sophisticated spear-phishing campaign targeted individuals in research, policy, and academic fields through emails disguised as materials from an actual academic conference. The attack leveraged a cloud storage link delivering a malicious ISO file containing a PIF executable disguised as a PDF document. The multi-stage loader used EMBED_PAYLOAD_v2 structure to embed both legitimate documents and malicious payloads, which were sequentially extracted and executed in memory. Shellcode injection into explorer.exe ultimately deployed a RokRAT variant communicating with cloud-based C2 infrastructure via pCloud, Dropbox, and Yandex Cloud. The campaign demonstrated advanced social engineering by exploiting information from a real event, combined with sophisticated evasion techniques including process injection and cloud-based command-and-control operations. Attribution analysis linked the activity to APT37 based on infrastructure overlap, code similarities, and operational patterns.

    Pulse ID: 6a5414fab18f9d7456d7eda8
    Pulse Link: otx.alienvault.com/pulse/6a541
    Pulse Author: AlienVault
    Created: 2026-07-12 22:28:10

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #APT37 #Cloud #CodeInjection #CyberSecurity #Dropbox #Email #InfoSec #OTX #OpenThreatExchange #PDF #Phishing #RAT #ShellCode #SocialEngineering #SpearPhishing #bot #pCloud #AlienVault

  32. Operation Capsule Vault: RokRAT Attack Chain Analysis Using EMBED_PAYLOAD_v2

    A sophisticated spear-phishing campaign targeted individuals in research, policy, and academic fields through emails disguised as materials from an actual academic conference. The attack leveraged a cloud storage link delivering a malicious ISO file containing a PIF executable disguised as a PDF document. The multi-stage loader used EMBED_PAYLOAD_v2 structure to embed both legitimate documents and malicious payloads, which were sequentially extracted and executed in memory. Shellcode injection into explorer.exe ultimately deployed a RokRAT variant communicating with cloud-based C2 infrastructure via pCloud, Dropbox, and Yandex Cloud. The campaign demonstrated advanced social engineering by exploiting information from a real event, combined with sophisticated evasion techniques including process injection and cloud-based command-and-control operations. Attribution analysis linked the activity to APT37 based on infrastructure overlap, code similarities, and operational patterns.

    Pulse ID: 6a5414fab18f9d7456d7eda8
    Pulse Link: otx.alienvault.com/pulse/6a541
    Pulse Author: AlienVault
    Created: 2026-07-12 22:28:10

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #APT37 #Cloud #CodeInjection #CyberSecurity #Dropbox #Email #InfoSec #OTX #OpenThreatExchange #PDF #Phishing #RAT #ShellCode #SocialEngineering #SpearPhishing #bot #pCloud #AlienVault

  33. Operation Capsule Vault: RokRAT Attack Chain Analysis Using EMBED_PAYLOAD_v2

    A sophisticated spear-phishing campaign targeted individuals in research, policy, and academic fields through emails disguised as materials from an actual academic conference. The attack leveraged a cloud storage link delivering a malicious ISO file containing a PIF executable disguised as a PDF document. The multi-stage loader used EMBED_PAYLOAD_v2 structure to embed both legitimate documents and malicious payloads, which were sequentially extracted and executed in memory. Shellcode injection into explorer.exe ultimately deployed a RokRAT variant communicating with cloud-based C2 infrastructure via pCloud, Dropbox, and Yandex Cloud. The campaign demonstrated advanced social engineering by exploiting information from a real event, combined with sophisticated evasion techniques including process injection and cloud-based command-and-control operations. Attribution analysis linked the activity to APT37 based on infrastructure overlap, code similarities, and operational patterns.

    Pulse ID: 6a5414fab18f9d7456d7eda8
    Pulse Link: otx.alienvault.com/pulse/6a541
    Pulse Author: AlienVault
    Created: 2026-07-12 22:28:10

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #APT37 #Cloud #CodeInjection #CyberSecurity #Dropbox #Email #InfoSec #OTX #OpenThreatExchange #PDF #Phishing #RAT #ShellCode #SocialEngineering #SpearPhishing #bot #pCloud #AlienVault

  34. Operation Capsule Vault: RokRAT Attack Chain Analysis Using EMBED_PAYLOAD_v2

    A sophisticated spear-phishing campaign targeted individuals in research, policy, and academic fields through emails disguised as materials from an actual academic conference. The attack leveraged a cloud storage link delivering a malicious ISO file containing a PIF executable disguised as a PDF document. The multi-stage loader used EMBED_PAYLOAD_v2 structure to embed both legitimate documents and malicious payloads, which were sequentially extracted and executed in memory. Shellcode injection into explorer.exe ultimately deployed a RokRAT variant communicating with cloud-based C2 infrastructure via pCloud, Dropbox, and Yandex Cloud. The campaign demonstrated advanced social engineering by exploiting information from a real event, combined with sophisticated evasion techniques including process injection and cloud-based command-and-control operations. Attribution analysis linked the activity to APT37 based on infrastructure overlap, code similarities, and operational patterns.

    Pulse ID: 6a5414fab18f9d7456d7eda8
    Pulse Link: otx.alienvault.com/pulse/6a541
    Pulse Author: AlienVault
    Created: 2026-07-12 22:28:10

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #APT37 #Cloud #CodeInjection #CyberSecurity #Dropbox #Email #InfoSec #OTX #OpenThreatExchange #PDF #Phishing #RAT #ShellCode #SocialEngineering #SpearPhishing #bot #pCloud #AlienVault

  35. Operation Capsule Vault: RokRAT Attack Chain Analysis Using EMBED_PAYLOAD_v2

    A sophisticated spear-phishing campaign targeted individuals in research, policy, and academic fields through emails disguised as materials from an actual academic conference. The attack leveraged a cloud storage link delivering a malicious ISO file containing a PIF executable disguised as a PDF document. The multi-stage loader used EMBED_PAYLOAD_v2 structure to embed both legitimate documents and malicious payloads, which were sequentially extracted and executed in memory. Shellcode injection into explorer.exe ultimately deployed a RokRAT variant communicating with cloud-based C2 infrastructure via pCloud, Dropbox, and Yandex Cloud. The campaign demonstrated advanced social engineering by exploiting information from a real event, combined with sophisticated evasion techniques including process injection and cloud-based command-and-control operations. Attribution analysis linked the activity to APT37 based on infrastructure overlap, code similarities, and operational patterns.

    Pulse ID: 6a5414fab18f9d7456d7eda8
    Pulse Link: otx.alienvault.com/pulse/6a541
    Pulse Author: AlienVault
    Created: 2026-07-12 22:28:10

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #APT37 #Cloud #CodeInjection #CyberSecurity #Dropbox #Email #InfoSec #OTX #OpenThreatExchange #PDF #Phishing #RAT #ShellCode #SocialEngineering #SpearPhishing #bot #pCloud #AlienVault

  36. Xiamen Empress Information Technology: come Pechino ha affittato account LINE per spiare giornalisti e attivisti a Taiwan

    Le autorità taiwanesi hanno incriminato due imprenditori per aver affittato account LINE a Xiamen Empress Information Technology, usati da operatori legati a Pechino per impersonare giornalisti e colpire funzionari, accademici e attivisti. Il caso conferma le inchieste di ICIJ e Citizen Lab sulla repressione transnazionale cinese.

    insicurezzadigitale.com/xiamen

  37. Xiamen Empress Information Technology: come Pechino ha affittato account LINE per spiare giornalisti e attivisti a Taiwan

    Le autorità taiwanesi hanno incriminato due imprenditori per aver affittato account LINE a Xiamen Empress Information Technology, usati da operatori legati a Pechino per impersonare giornalisti e colpire funzionari, accademici e attivisti. Il caso conferma le inchieste di ICIJ e Citizen Lab sulla repressione transnazionale cinese.

    insicurezzadigitale.com/xiamen

  38. Xiamen Empress Information Technology: come Pechino ha affittato account LINE per spiare giornalisti e attivisti a Taiwan

    Le autorità taiwanesi hanno incriminato due imprenditori per aver affittato account LINE a Xiamen Empress Information Technology, usati da operatori legati a Pechino per impersonare giornalisti e colpire funzionari, accademici e attivisti. Il caso conferma le inchieste di ICIJ e Citizen Lab sulla repressione transnazionale cinese.

    insicurezzadigitale.com/xiamen

  39. Xiamen Empress Information Technology: come Pechino ha affittato account LINE per spiare giornalisti e attivisti a Taiwan

    Le autorità taiwanesi hanno incriminato due imprenditori per aver affittato account LINE a Xiamen Empress Information Technology, usati da operatori legati a Pechino per impersonare giornalisti e colpire funzionari, accademici e attivisti. Il caso conferma le inchieste di ICIJ e Citizen Lab sulla repressione transnazionale cinese.

    insicurezzadigitale.com/xiamen

  40. Xiamen Empress Information Technology: come Pechino ha affittato account LINE per spiare giornalisti e attivisti a Taiwan

    Le autorità taiwanesi hanno incriminato due imprenditori per aver affittato account LINE a Xiamen Empress Information Technology, usati da operatori legati a Pechino per impersonare giornalisti e colpire funzionari, accademici e attivisti. Il caso conferma le inchieste di ICIJ e Citizen Lab sulla repressione transnazionale cinese.

    insicurezzadigitale.com/xiamen

  41. Once, during an #awareness session, I brought a jar into the room.

    One of those old-school glass jars with a metal lid.

    I put it on the table and asked the executives (not the CISOs) to drop a poker chip inside.

    Yes, poker chips. Don’t laugh. That’s what I had.

    The value of each chip was supposed to reflect two things: perceived risk and willingness to spend.

    At the beginning, the jar looked miserable.

    Two or three 50s.
    One brave 500.
    Fewer than ten 100s.

    Then came lunch.
    Paid for, obviously.
    But lunch was also the exercise.

    Heavy #socialengineering. Casual conversation. Names, routines, vendors, habits, internal friction, travel plans, tools, weak points, ego, trust.

    Then the last two hours began.
    Real risk demonstration.

    #spearphishing built with information collected during lunch.
    Fake WhatsApp chats after recon.
    #OSINT before the session even restarted.
    QR codes everywhere.

    Then we talked about recovery costs.

    Regulatory fines.
    Production downtime.
    Loss of trust.
    Reputational damage.
    The unpleasant difference between “unlikely” and “not impossible”.

    And, magically, the jar filled up with 500 and 1000 chips.

    You don’t fucking say.

    My #Decoded for #Baited: blog.baited.io/2026/cost-of-ph

  42. Once, during an #awareness session, I brought a jar into the room.

    One of those old-school glass jars with a metal lid.

    I put it on the table and asked the executives (not the CISOs) to drop a poker chip inside.

    Yes, poker chips. Don’t laugh. That’s what I had.

    The value of each chip was supposed to reflect two things: perceived risk and willingness to spend.

    At the beginning, the jar looked miserable.

    Two or three 50s.
    One brave 500.
    Fewer than ten 100s.

    Then came lunch.
    Paid for, obviously.
    But lunch was also the exercise.

    Heavy #socialengineering. Casual conversation. Names, routines, vendors, habits, internal friction, travel plans, tools, weak points, ego, trust.

    Then the last two hours began.
    Real risk demonstration.

    #spearphishing built with information collected during lunch.
    Fake WhatsApp chats after recon.
    #OSINT before the session even restarted.
    QR codes everywhere.

    Then we talked about recovery costs.

    Regulatory fines.
    Production downtime.
    Loss of trust.
    Reputational damage.
    The unpleasant difference between “unlikely” and “not impossible”.

    And, magically, the jar filled up with 500 and 1000 chips.

    You don’t fucking say.

    My #Decoded for #Baited: blog.baited.io/2026/cost-of-ph

  43. Once, during an #awareness session, I brought a jar into the room.

    One of those old-school glass jars with a metal lid.

    I put it on the table and asked the executives (not the CISOs) to drop a poker chip inside.

    Yes, poker chips. Don’t laugh. That’s what I had.

    The value of each chip was supposed to reflect two things: perceived risk and willingness to spend.

    At the beginning, the jar looked miserable.

    Two or three 50s.
    One brave 500.
    Fewer than ten 100s.

    Then came lunch.
    Paid for, obviously.
    But lunch was also the exercise.

    Heavy #socialengineering. Casual conversation. Names, routines, vendors, habits, internal friction, travel plans, tools, weak points, ego, trust.

    Then the last two hours began.
    Real risk demonstration.

    #spearphishing built with information collected during lunch.
    Fake WhatsApp chats after recon.
    #OSINT before the session even restarted.
    QR codes everywhere.

    Then we talked about recovery costs.

    Regulatory fines.
    Production downtime.
    Loss of trust.
    Reputational damage.
    The unpleasant difference between “unlikely” and “not impossible”.

    And, magically, the jar filled up with 500 and 1000 chips.

    You don’t fucking say.

    My #Decoded for #Baited: blog.baited.io/2026/cost-of-ph

  44. Once, during an #awareness session, I brought a jar into the room.

    One of those old-school glass jars with a metal lid.

    I put it on the table and asked the executives (not the CISOs) to drop a poker chip inside.

    Yes, poker chips. Don’t laugh. That’s what I had.

    The value of each chip was supposed to reflect two things: perceived risk and willingness to spend.

    At the beginning, the jar looked miserable.

    Two or three 50s.
    One brave 500.
    Fewer than ten 100s.

    Then came lunch.
    Paid for, obviously.
    But lunch was also the exercise.

    Heavy #socialengineering. Casual conversation. Names, routines, vendors, habits, internal friction, travel plans, tools, weak points, ego, trust.

    Then the last two hours began.
    Real risk demonstration.

    #spearphishing built with information collected during lunch.
    Fake WhatsApp chats after recon.
    #OSINT before the session even restarted.
    QR codes everywhere.

    Then we talked about recovery costs.

    Regulatory fines.
    Production downtime.
    Loss of trust.
    Reputational damage.
    The unpleasant difference between “unlikely” and “not impossible”.

    And, magically, the jar filled up with 500 and 1000 chips.

    You don’t fucking say.

    My #Decoded for #Baited: blog.baited.io/2026/cost-of-ph

  45. Once, during an #awareness session, I brought a jar into the room.

    One of those old-school glass jars with a metal lid.

    I put it on the table and asked the executives (not the CISOs) to drop a poker chip inside.

    Yes, poker chips. Don’t laugh. That’s what I had.

    The value of each chip was supposed to reflect two things: perceived risk and willingness to spend.

    At the beginning, the jar looked miserable.

    Two or three 50s.
    One brave 500.
    Fewer than ten 100s.

    Then came lunch.
    Paid for, obviously.
    But lunch was also the exercise.

    Heavy #socialengineering. Casual conversation. Names, routines, vendors, habits, internal friction, travel plans, tools, weak points, ego, trust.

    Then the last two hours began.
    Real risk demonstration.

    #spearphishing built with information collected during lunch.
    Fake WhatsApp chats after recon.
    #OSINT before the session even restarted.
    QR codes everywhere.

    Then we talked about recovery costs.

    Regulatory fines.
    Production downtime.
    Loss of trust.
    Reputational damage.
    The unpleasant difference between “unlikely” and “not impossible”.

    And, magically, the jar filled up with 500 and 1000 chips.

    You don’t fucking say.

    My #Decoded for #Baited: blog.baited.io/2026/cost-of-ph

  46. The New Frontier: Securing Japan’s Hybrid Digital Workforce (2026 & Beyond)

    As Japan navigates the mid-point of the decade, its cybersecurity landscape is undergoing a fundamental transformation. Driven by…
    #EuropeSays #Japan #JP #anti-phishingtraining #cryptolocker #Florida #hackers #hacking #kevinmitnick #knowbe4 #Nihon #on-linetraining #phish-prone #phishing #ransomware #securityawarenesstraining #socialengineering #spearphishing #stusjouwerman #tampabay #Training
    europesays.com/japan/37843/

  47. Meta Disrupts NSO Group's WhatsApp Phishing Campaign

    Meta detected and blocked a sneaky WhatsApp phishing campaign linked to NSO Group, where attackers tried to trick people into clicking malicious links that led to external websites. The company also filed a contempt order against NSO for allegedly violating a court injunction by targeting WhatsApp users.

    osintsights.com/meta-disrupts-

    #WhatsappPhishing #NsoGroup #SpearPhishing #Meta #1clickPhishing

  48. SideCopy Targets Afghan Finance Ministry with Xeno RAT Malware

    Seqrite Labs researchers uncovered a sneaky malware attack, dubbed Operation XENOFISCAL, where the Pakistan-aligned SideCopy group targeted Afghanistan's Ministry of Finance and government officials with a cleverly crafted phishing lure written in Pashto. The attack used Xeno RAT Malware, delivered through a ZIP archive with a malicious…

    osintsights.com/sidecopy-targe

    #XenoRatMalware #Sidecopy #Afghanistan #FinanceSector #SpearPhishing

  49. Operation Dragon Weave: l’APT cinese usa Azure Blob Storage come C2 per colpire Repubblica Ceca e Taiwan

    Seqrite ha identificato Operation Dragon Weave, una campagna APT attribuita con moderata confidenza a un attore cinese che colpisce funzionari e ricercatori in Repubblica Ceca e Taiwan. Il payload finale AZUREVEIL usa Azure Blob Storage come canale C2 dead-drop, mascherando il traffico malevolo tra le normali comunicazioni cloud enterprise.

    insicurezzadigitale.com/operat