#spearphishing — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #spearphishing, aggregated by home.social.
-
El lado del mal - Cómo los Agentes IA de Red Team hacen ataques de Ingeniería Social con Fake Accounts https://www.elladodelmal.com/2026/08/como-los-agentes-ia-de-red-team-hacen.html #IA #AI #AgenticAI #RedTeam #Hacking #Pentest #Pentesting #GitHub #SpearPhishing #IngenieriaSocial
-
El lado del mal - Cómo los Agentes IA de Red Team hacen ataques de Ingeniería Social con Fake Accounts https://www.elladodelmal.com/2026/08/como-los-agentes-ia-de-red-team-hacen.html #IA #AI #AgenticAI #RedTeam #Hacking #Pentest #Pentesting #GitHub #SpearPhishing #IngenieriaSocial
-
El lado del mal - Cómo los Agentes IA de Red Team hacen ataques de Ingeniería Social con Fake Accounts https://www.elladodelmal.com/2026/08/como-los-agentes-ia-de-red-team-hacen.html #IA #AI #AgenticAI #RedTeam #Hacking #Pentest #Pentesting #GitHub #SpearPhishing #IngenieriaSocial
-
El lado del mal - Cómo los Agentes IA de Red Team hacen ataques de Ingeniería Social con Fake Accounts https://www.elladodelmal.com/2026/08/como-los-agentes-ia-de-red-team-hacen.html #IA #AI #AgenticAI #RedTeam #Hacking #Pentest #Pentesting #GitHub #SpearPhishing #IngenieriaSocial
-
El lado del mal - Cómo los Agentes IA de Red Team hacen ataques de Ingeniería Social con Fake Accounts https://www.elladodelmal.com/2026/08/como-los-agentes-ia-de-red-team-hacen.html #IA #AI #AgenticAI #RedTeam #Hacking #Pentest #Pentesting #GitHub #SpearPhishing #IngenieriaSocial
-
Analysis of the Connection Between Xctdoor and Past CRAT Attack Cases
A threat actor designated as Larva-26005, linked to North Korea, has been distributing Xctdoor backdoor malware to users in Korea since at least 2020. The campaign evolved from using CRAT malware alongside Hansom ransomware to deploying Xctdoor variants written in C++ and Go. Distribution methods include spear phishing emails with LNK files disguised as documents and security software installers. The malware utilizes DLL side-loading, deploys multiple script-based droppers, and installs XcLoader and Xctdoor backdoors in AppX package paths. Both CRAT and Xctdoor share identical code obfuscation techniques and installation paths. The backdoors provide comprehensive remote access capabilities including file operations, command execution, keylogging, screenshot capture, and credential theft. Recent attacks target corporate users through compromised web servers and ERP solutions.
Pulse ID: 6a748055fc990bd246b92b6c
Pulse Link: https://otx.alienvault.com/pulse/6a748055fc990bd246b92b6c
Pulse Author: AlienVault
Created: 2026-08-06 12:38:45Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#BackDoor #CyberSecurity #Email #InfoSec #Korea #LNK #Malware #NorthKorea #OTX #OpenThreatExchange #Phishing #RAT #RansomWare #SpearPhishing #bot #AlienVault
-
Analysis of the Connection Between Xctdoor and Past CRAT Attack Cases
A threat actor designated as Larva-26005, linked to North Korea, has been distributing Xctdoor backdoor malware to users in Korea since at least 2020. The campaign evolved from using CRAT malware alongside Hansom ransomware to deploying Xctdoor variants written in C++ and Go. Distribution methods include spear phishing emails with LNK files disguised as documents and security software installers. The malware utilizes DLL side-loading, deploys multiple script-based droppers, and installs XcLoader and Xctdoor backdoors in AppX package paths. Both CRAT and Xctdoor share identical code obfuscation techniques and installation paths. The backdoors provide comprehensive remote access capabilities including file operations, command execution, keylogging, screenshot capture, and credential theft. Recent attacks target corporate users through compromised web servers and ERP solutions.
Pulse ID: 6a748055fc990bd246b92b6c
Pulse Link: https://otx.alienvault.com/pulse/6a748055fc990bd246b92b6c
Pulse Author: AlienVault
Created: 2026-08-06 12:38:45Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#BackDoor #CyberSecurity #Email #InfoSec #Korea #LNK #Malware #NorthKorea #OTX #OpenThreatExchange #Phishing #RAT #RansomWare #SpearPhishing #bot #AlienVault
-
Analysis of the Connection Between Xctdoor and Past CRAT Attack Cases
A threat actor designated as Larva-26005, linked to North Korea, has been distributing Xctdoor backdoor malware to users in Korea since at least 2020. The campaign evolved from using CRAT malware alongside Hansom ransomware to deploying Xctdoor variants written in C++ and Go. Distribution methods include spear phishing emails with LNK files disguised as documents and security software installers. The malware utilizes DLL side-loading, deploys multiple script-based droppers, and installs XcLoader and Xctdoor backdoors in AppX package paths. Both CRAT and Xctdoor share identical code obfuscation techniques and installation paths. The backdoors provide comprehensive remote access capabilities including file operations, command execution, keylogging, screenshot capture, and credential theft. Recent attacks target corporate users through compromised web servers and ERP solutions.
Pulse ID: 6a748055fc990bd246b92b6c
Pulse Link: https://otx.alienvault.com/pulse/6a748055fc990bd246b92b6c
Pulse Author: AlienVault
Created: 2026-08-06 12:38:45Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#BackDoor #CyberSecurity #Email #InfoSec #Korea #LNK #Malware #NorthKorea #OTX #OpenThreatExchange #Phishing #RAT #RansomWare #SpearPhishing #bot #AlienVault
-
Analysis of the Connection Between Xctdoor and Past CRAT Attack Cases
A threat actor designated as Larva-26005, linked to North Korea, has been distributing Xctdoor backdoor malware to users in Korea since at least 2020. The campaign evolved from using CRAT malware alongside Hansom ransomware to deploying Xctdoor variants written in C++ and Go. Distribution methods include spear phishing emails with LNK files disguised as documents and security software installers. The malware utilizes DLL side-loading, deploys multiple script-based droppers, and installs XcLoader and Xctdoor backdoors in AppX package paths. Both CRAT and Xctdoor share identical code obfuscation techniques and installation paths. The backdoors provide comprehensive remote access capabilities including file operations, command execution, keylogging, screenshot capture, and credential theft. Recent attacks target corporate users through compromised web servers and ERP solutions.
Pulse ID: 6a748055fc990bd246b92b6c
Pulse Link: https://otx.alienvault.com/pulse/6a748055fc990bd246b92b6c
Pulse Author: AlienVault
Created: 2026-08-06 12:38:45Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#BackDoor #CyberSecurity #Email #InfoSec #Korea #LNK #Malware #NorthKorea #OTX #OpenThreatExchange #Phishing #RAT #RansomWare #SpearPhishing #bot #AlienVault
-
Analysis of the Connection Between Xctdoor and Past CRAT Attack Cases
A threat actor designated as Larva-26005, linked to North Korea, has been distributing Xctdoor backdoor malware to users in Korea since at least 2020. The campaign evolved from using CRAT malware alongside Hansom ransomware to deploying Xctdoor variants written in C++ and Go. Distribution methods include spear phishing emails with LNK files disguised as documents and security software installers. The malware utilizes DLL side-loading, deploys multiple script-based droppers, and installs XcLoader and Xctdoor backdoors in AppX package paths. Both CRAT and Xctdoor share identical code obfuscation techniques and installation paths. The backdoors provide comprehensive remote access capabilities including file operations, command execution, keylogging, screenshot capture, and credential theft. Recent attacks target corporate users through compromised web servers and ERP solutions.
Pulse ID: 6a748055fc990bd246b92b6c
Pulse Link: https://otx.alienvault.com/pulse/6a748055fc990bd246b92b6c
Pulse Author: AlienVault
Created: 2026-08-06 12:38:45Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#BackDoor #CyberSecurity #Email #InfoSec #Korea #LNK #Malware #NorthKorea #OTX #OpenThreatExchange #Phishing #RAT #RansomWare #SpearPhishing #bot #AlienVault
-
NightLedger Backdoor Deployed in Espionage Campaign Targeting the Middle East and Africa
An advanced persistent threat group, Mirage Kitten, is conducting cyber-espionage operations across the Middle East and Africa using three previously undocumented malware families: NightLedger, BridgeHead, and ArcBridge. These tools provide reconnaissance, command execution, covert tunneling, and persistent access capabilities. The campaign targets organizations in Egypt, Jordan, Tanzania, Pakistan, Ethiopia, and Burkina Faso across aerospace, aviation, defense, telecommunications, government, financial services, and SMB sectors. Initial access is gained through targeted spear-phishing with recruitment-themed lures and fake videoconferencing pages. The malware demonstrates sophisticated operational security features including victim-specific execution controls, WebSocket-based tunneling, and Cloudflare-backed infrastructure, reflecting the group's investment in bespoke tooling for long-term intelligence collection.
Pulse ID: 6a71aa488c89bfcbd2814692
Pulse Link: https://otx.alienvault.com/pulse/6a71aa488c89bfcbd2814692
Pulse Author: AlienVault
Created: 2026-08-04 09:00:56Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Africa #BackDoor #Cloud #CyberSecurity #Edge #Espionage #Government #InfoSec #Malware #MiddleEast #OTX #OpenThreatExchange #Pakistan #Phishing #RAT #SMB #SpearPhishing #Telecom #Telecommunication #bot #cyberespionage #AlienVault
-
NightLedger Backdoor Deployed in Espionage Campaign Targeting the Middle East and Africa
An advanced persistent threat group, Mirage Kitten, is conducting cyber-espionage operations across the Middle East and Africa using three previously undocumented malware families: NightLedger, BridgeHead, and ArcBridge. These tools provide reconnaissance, command execution, covert tunneling, and persistent access capabilities. The campaign targets organizations in Egypt, Jordan, Tanzania, Pakistan, Ethiopia, and Burkina Faso across aerospace, aviation, defense, telecommunications, government, financial services, and SMB sectors. Initial access is gained through targeted spear-phishing with recruitment-themed lures and fake videoconferencing pages. The malware demonstrates sophisticated operational security features including victim-specific execution controls, WebSocket-based tunneling, and Cloudflare-backed infrastructure, reflecting the group's investment in bespoke tooling for long-term intelligence collection.
Pulse ID: 6a71aa488c89bfcbd2814692
Pulse Link: https://otx.alienvault.com/pulse/6a71aa488c89bfcbd2814692
Pulse Author: AlienVault
Created: 2026-08-04 09:00:56Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Africa #BackDoor #Cloud #CyberSecurity #Edge #Espionage #Government #InfoSec #Malware #MiddleEast #OTX #OpenThreatExchange #Pakistan #Phishing #RAT #SMB #SpearPhishing #Telecom #Telecommunication #bot #cyberespionage #AlienVault
-
NightLedger Backdoor Deployed in Espionage Campaign Targeting the Middle East and Africa
An advanced persistent threat group, Mirage Kitten, is conducting cyber-espionage operations across the Middle East and Africa using three previously undocumented malware families: NightLedger, BridgeHead, and ArcBridge. These tools provide reconnaissance, command execution, covert tunneling, and persistent access capabilities. The campaign targets organizations in Egypt, Jordan, Tanzania, Pakistan, Ethiopia, and Burkina Faso across aerospace, aviation, defense, telecommunications, government, financial services, and SMB sectors. Initial access is gained through targeted spear-phishing with recruitment-themed lures and fake videoconferencing pages. The malware demonstrates sophisticated operational security features including victim-specific execution controls, WebSocket-based tunneling, and Cloudflare-backed infrastructure, reflecting the group's investment in bespoke tooling for long-term intelligence collection.
Pulse ID: 6a71aa488c89bfcbd2814692
Pulse Link: https://otx.alienvault.com/pulse/6a71aa488c89bfcbd2814692
Pulse Author: AlienVault
Created: 2026-08-04 09:00:56Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Africa #BackDoor #Cloud #CyberSecurity #Edge #Espionage #Government #InfoSec #Malware #MiddleEast #OTX #OpenThreatExchange #Pakistan #Phishing #RAT #SMB #SpearPhishing #Telecom #Telecommunication #bot #cyberespionage #AlienVault
-
NightLedger Backdoor Deployed in Espionage Campaign Targeting the Middle East and Africa
An advanced persistent threat group, Mirage Kitten, is conducting cyber-espionage operations across the Middle East and Africa using three previously undocumented malware families: NightLedger, BridgeHead, and ArcBridge. These tools provide reconnaissance, command execution, covert tunneling, and persistent access capabilities. The campaign targets organizations in Egypt, Jordan, Tanzania, Pakistan, Ethiopia, and Burkina Faso across aerospace, aviation, defense, telecommunications, government, financial services, and SMB sectors. Initial access is gained through targeted spear-phishing with recruitment-themed lures and fake videoconferencing pages. The malware demonstrates sophisticated operational security features including victim-specific execution controls, WebSocket-based tunneling, and Cloudflare-backed infrastructure, reflecting the group's investment in bespoke tooling for long-term intelligence collection.
Pulse ID: 6a71aa488c89bfcbd2814692
Pulse Link: https://otx.alienvault.com/pulse/6a71aa488c89bfcbd2814692
Pulse Author: AlienVault
Created: 2026-08-04 09:00:56Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Africa #BackDoor #Cloud #CyberSecurity #Edge #Espionage #Government #InfoSec #Malware #MiddleEast #OTX #OpenThreatExchange #Pakistan #Phishing #RAT #SMB #SpearPhishing #Telecom #Telecommunication #bot #cyberespionage #AlienVault
-
NightLedger Backdoor Deployed in Espionage Campaign Targeting the Middle East and Africa
An advanced persistent threat group, Mirage Kitten, is conducting cyber-espionage operations across the Middle East and Africa using three previously undocumented malware families: NightLedger, BridgeHead, and ArcBridge. These tools provide reconnaissance, command execution, covert tunneling, and persistent access capabilities. The campaign targets organizations in Egypt, Jordan, Tanzania, Pakistan, Ethiopia, and Burkina Faso across aerospace, aviation, defense, telecommunications, government, financial services, and SMB sectors. Initial access is gained through targeted spear-phishing with recruitment-themed lures and fake videoconferencing pages. The malware demonstrates sophisticated operational security features including victim-specific execution controls, WebSocket-based tunneling, and Cloudflare-backed infrastructure, reflecting the group's investment in bespoke tooling for long-term intelligence collection.
Pulse ID: 6a71aa488c89bfcbd2814692
Pulse Link: https://otx.alienvault.com/pulse/6a71aa488c89bfcbd2814692
Pulse Author: AlienVault
Created: 2026-08-04 09:00:56Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Africa #BackDoor #Cloud #CyberSecurity #Edge #Espionage #Government #InfoSec #Malware #MiddleEast #OTX #OpenThreatExchange #Pakistan #Phishing #RAT #SMB #SpearPhishing #Telecom #Telecommunication #bot #cyberespionage #AlienVault
-
Mirage Kitten targets Middle East and Africa region with new malware
Mirage Kitten, an advanced persistent threat group also known as UNC1549, Smoke Sandstorm, and Nimbus Manticore, has been observed deploying a previously undocumented malware set targeting aerospace, aviation, defense, and telecommunications sectors across the Middle East and Africa. The toolset includes NightLedger, a Windows backdoor with reconnaissance, command execution, file operations, process discovery, and screenshot capture capabilities. Two custom WebSocket-based tunneling tools, ArcBridge and BridgeHead, enable covert network access and operator-controlled tunneling through victim networks. The group employs highly targeted spear-phishing campaigns, fake recruitment portals, and lookalike videoconferencing pages. Victims were identified in Egypt, Jordan, Tanzania, Pakistan, Ethiopia, and Burkina Faso. The malware demonstrates operational security through username-based execution checks and advanced proxy traversal capabilities.
Pulse ID: 6a689c34d4df4bb1475d80c7
Pulse Link: https://otx.alienvault.com/pulse/6a689c34d4df4bb1475d80c7
Pulse Author: AlienVault
Created: 2026-07-28 12:10:28Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Africa #BackDoor #CyberSecurity #Edge #InfoSec #Malware #MiddleEast #Nim #OTX #OpenThreatExchange #Pakistan #Phishing #Proxy #RAT #SpearPhishing #Telecom #Telecommunication #Troll #UNC1549 #Windows #bot #AlienVault
-
Mirage Kitten targets Middle East and Africa region with new malware
Mirage Kitten, an advanced persistent threat group also known as UNC1549, Smoke Sandstorm, and Nimbus Manticore, has been observed deploying a previously undocumented malware set targeting aerospace, aviation, defense, and telecommunications sectors across the Middle East and Africa. The toolset includes NightLedger, a Windows backdoor with reconnaissance, command execution, file operations, process discovery, and screenshot capture capabilities. Two custom WebSocket-based tunneling tools, ArcBridge and BridgeHead, enable covert network access and operator-controlled tunneling through victim networks. The group employs highly targeted spear-phishing campaigns, fake recruitment portals, and lookalike videoconferencing pages. Victims were identified in Egypt, Jordan, Tanzania, Pakistan, Ethiopia, and Burkina Faso. The malware demonstrates operational security through username-based execution checks and advanced proxy traversal capabilities.
Pulse ID: 6a689c34d4df4bb1475d80c7
Pulse Link: https://otx.alienvault.com/pulse/6a689c34d4df4bb1475d80c7
Pulse Author: AlienVault
Created: 2026-07-28 12:10:28Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Africa #BackDoor #CyberSecurity #Edge #InfoSec #Malware #MiddleEast #Nim #OTX #OpenThreatExchange #Pakistan #Phishing #Proxy #RAT #SpearPhishing #Telecom #Telecommunication #Troll #UNC1549 #Windows #bot #AlienVault
-
Mirage Kitten targets Middle East and Africa region with new malware
Mirage Kitten, an advanced persistent threat group also known as UNC1549, Smoke Sandstorm, and Nimbus Manticore, has been observed deploying a previously undocumented malware set targeting aerospace, aviation, defense, and telecommunications sectors across the Middle East and Africa. The toolset includes NightLedger, a Windows backdoor with reconnaissance, command execution, file operations, process discovery, and screenshot capture capabilities. Two custom WebSocket-based tunneling tools, ArcBridge and BridgeHead, enable covert network access and operator-controlled tunneling through victim networks. The group employs highly targeted spear-phishing campaigns, fake recruitment portals, and lookalike videoconferencing pages. Victims were identified in Egypt, Jordan, Tanzania, Pakistan, Ethiopia, and Burkina Faso. The malware demonstrates operational security through username-based execution checks and advanced proxy traversal capabilities.
Pulse ID: 6a689c34d4df4bb1475d80c7
Pulse Link: https://otx.alienvault.com/pulse/6a689c34d4df4bb1475d80c7
Pulse Author: AlienVault
Created: 2026-07-28 12:10:28Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Africa #BackDoor #CyberSecurity #Edge #InfoSec #Malware #MiddleEast #Nim #OTX #OpenThreatExchange #Pakistan #Phishing #Proxy #RAT #SpearPhishing #Telecom #Telecommunication #Troll #UNC1549 #Windows #bot #AlienVault
-
Mirage Kitten targets Middle East and Africa region with new malware
Mirage Kitten, an advanced persistent threat group also known as UNC1549, Smoke Sandstorm, and Nimbus Manticore, has been observed deploying a previously undocumented malware set targeting aerospace, aviation, defense, and telecommunications sectors across the Middle East and Africa. The toolset includes NightLedger, a Windows backdoor with reconnaissance, command execution, file operations, process discovery, and screenshot capture capabilities. Two custom WebSocket-based tunneling tools, ArcBridge and BridgeHead, enable covert network access and operator-controlled tunneling through victim networks. The group employs highly targeted spear-phishing campaigns, fake recruitment portals, and lookalike videoconferencing pages. Victims were identified in Egypt, Jordan, Tanzania, Pakistan, Ethiopia, and Burkina Faso. The malware demonstrates operational security through username-based execution checks and advanced proxy traversal capabilities.
Pulse ID: 6a689c34d4df4bb1475d80c7
Pulse Link: https://otx.alienvault.com/pulse/6a689c34d4df4bb1475d80c7
Pulse Author: AlienVault
Created: 2026-07-28 12:10:28Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Africa #BackDoor #CyberSecurity #Edge #InfoSec #Malware #MiddleEast #Nim #OTX #OpenThreatExchange #Pakistan #Phishing #Proxy #RAT #SpearPhishing #Telecom #Telecommunication #Troll #UNC1549 #Windows #bot #AlienVault
-
Mirage Kitten targets Middle East and Africa region with new malware
Mirage Kitten, an advanced persistent threat group also known as UNC1549, Smoke Sandstorm, and Nimbus Manticore, has been observed deploying a previously undocumented malware set targeting aerospace, aviation, defense, and telecommunications sectors across the Middle East and Africa. The toolset includes NightLedger, a Windows backdoor with reconnaissance, command execution, file operations, process discovery, and screenshot capture capabilities. Two custom WebSocket-based tunneling tools, ArcBridge and BridgeHead, enable covert network access and operator-controlled tunneling through victim networks. The group employs highly targeted spear-phishing campaigns, fake recruitment portals, and lookalike videoconferencing pages. Victims were identified in Egypt, Jordan, Tanzania, Pakistan, Ethiopia, and Burkina Faso. The malware demonstrates operational security through username-based execution checks and advanced proxy traversal capabilities.
Pulse ID: 6a689c34d4df4bb1475d80c7
Pulse Link: https://otx.alienvault.com/pulse/6a689c34d4df4bb1475d80c7
Pulse Author: AlienVault
Created: 2026-07-28 12:10:28Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Africa #BackDoor #CyberSecurity #Edge #InfoSec #Malware #MiddleEast #Nim #OTX #OpenThreatExchange #Pakistan #Phishing #Proxy #RAT #SpearPhishing #Telecom #Telecommunication #Troll #UNC1549 #Windows #bot #AlienVault
-
June 2026 Threat Trend Report on APT Attacks (South Korea)
AhnLab monitored Advanced Persistent Threat attacks targeting South Korea during June 2026, identifying multiple attack types distributed primarily through spear phishing campaigns. Threat actors disguised malicious files as work-related documents, with LNK files being the most common delivery method. Six distinct attack types were observed, employing various techniques including malicious PowerShell commands, AutoIt malware, curl.exe abuse, GitHub repository exploitation, Task Scheduler persistence, DLL side-loading, and Python backdoors. These attacks deployed Infostealers, keyloggers, backdoors, and remote access tools like XenoRAT. Once executed, the malware established persistence, exfiltrated system information, and enabled remote control of compromised systems. Organizations are advised to verify email senders, avoid opening files from unknown sources, apply security patches, and maintain updated antivirus software to mitigate these persistent threats.
Pulse ID: 6a635bdf995351cf539c3b56
Pulse Link: https://otx.alienvault.com/pulse/6a635bdf995351cf539c3b56
Pulse Author: AlienVault
Created: 2026-07-24 12:34:39Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#AhnLab #Autoit #BackDoor #CyberSecurity #Email #GitHub #InfoSec #InfoStealer #KeyLogger #Korea #LNK #Malware #OTX #OpenThreatExchange #Phishing #PowerShell #Python #RAT #RCE #SouthKorea #SpearPhishing #bot #AlienVault
-
June 2026 Threat Trend Report on APT Attacks (South Korea)
AhnLab monitored Advanced Persistent Threat attacks targeting South Korea during June 2026, identifying multiple attack types distributed primarily through spear phishing campaigns. Threat actors disguised malicious files as work-related documents, with LNK files being the most common delivery method. Six distinct attack types were observed, employing various techniques including malicious PowerShell commands, AutoIt malware, curl.exe abuse, GitHub repository exploitation, Task Scheduler persistence, DLL side-loading, and Python backdoors. These attacks deployed Infostealers, keyloggers, backdoors, and remote access tools like XenoRAT. Once executed, the malware established persistence, exfiltrated system information, and enabled remote control of compromised systems. Organizations are advised to verify email senders, avoid opening files from unknown sources, apply security patches, and maintain updated antivirus software to mitigate these persistent threats.
Pulse ID: 6a635bdf995351cf539c3b56
Pulse Link: https://otx.alienvault.com/pulse/6a635bdf995351cf539c3b56
Pulse Author: AlienVault
Created: 2026-07-24 12:34:39Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#AhnLab #Autoit #BackDoor #CyberSecurity #Email #GitHub #InfoSec #InfoStealer #KeyLogger #Korea #LNK #Malware #OTX #OpenThreatExchange #Phishing #PowerShell #Python #RAT #RCE #SouthKorea #SpearPhishing #bot #AlienVault
-
June 2026 Threat Trend Report on APT Attacks (South Korea)
AhnLab monitored Advanced Persistent Threat attacks targeting South Korea during June 2026, identifying multiple attack types distributed primarily through spear phishing campaigns. Threat actors disguised malicious files as work-related documents, with LNK files being the most common delivery method. Six distinct attack types were observed, employing various techniques including malicious PowerShell commands, AutoIt malware, curl.exe abuse, GitHub repository exploitation, Task Scheduler persistence, DLL side-loading, and Python backdoors. These attacks deployed Infostealers, keyloggers, backdoors, and remote access tools like XenoRAT. Once executed, the malware established persistence, exfiltrated system information, and enabled remote control of compromised systems. Organizations are advised to verify email senders, avoid opening files from unknown sources, apply security patches, and maintain updated antivirus software to mitigate these persistent threats.
Pulse ID: 6a635bdf995351cf539c3b56
Pulse Link: https://otx.alienvault.com/pulse/6a635bdf995351cf539c3b56
Pulse Author: AlienVault
Created: 2026-07-24 12:34:39Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#AhnLab #Autoit #BackDoor #CyberSecurity #Email #GitHub #InfoSec #InfoStealer #KeyLogger #Korea #LNK #Malware #OTX #OpenThreatExchange #Phishing #PowerShell #Python #RAT #RCE #SouthKorea #SpearPhishing #bot #AlienVault
-
June 2026 Threat Trend Report on APT Attacks (South Korea)
AhnLab monitored Advanced Persistent Threat attacks targeting South Korea during June 2026, identifying multiple attack types distributed primarily through spear phishing campaigns. Threat actors disguised malicious files as work-related documents, with LNK files being the most common delivery method. Six distinct attack types were observed, employing various techniques including malicious PowerShell commands, AutoIt malware, curl.exe abuse, GitHub repository exploitation, Task Scheduler persistence, DLL side-loading, and Python backdoors. These attacks deployed Infostealers, keyloggers, backdoors, and remote access tools like XenoRAT. Once executed, the malware established persistence, exfiltrated system information, and enabled remote control of compromised systems. Organizations are advised to verify email senders, avoid opening files from unknown sources, apply security patches, and maintain updated antivirus software to mitigate these persistent threats.
Pulse ID: 6a635bdf995351cf539c3b56
Pulse Link: https://otx.alienvault.com/pulse/6a635bdf995351cf539c3b56
Pulse Author: AlienVault
Created: 2026-07-24 12:34:39Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#AhnLab #Autoit #BackDoor #CyberSecurity #Email #GitHub #InfoSec #InfoStealer #KeyLogger #Korea #LNK #Malware #OTX #OpenThreatExchange #Phishing #PowerShell #Python #RAT #RCE #SouthKorea #SpearPhishing #bot #AlienVault
-
June 2026 Threat Trend Report on APT Attacks (South Korea)
AhnLab monitored Advanced Persistent Threat attacks targeting South Korea during June 2026, identifying multiple attack types distributed primarily through spear phishing campaigns. Threat actors disguised malicious files as work-related documents, with LNK files being the most common delivery method. Six distinct attack types were observed, employing various techniques including malicious PowerShell commands, AutoIt malware, curl.exe abuse, GitHub repository exploitation, Task Scheduler persistence, DLL side-loading, and Python backdoors. These attacks deployed Infostealers, keyloggers, backdoors, and remote access tools like XenoRAT. Once executed, the malware established persistence, exfiltrated system information, and enabled remote control of compromised systems. Organizations are advised to verify email senders, avoid opening files from unknown sources, apply security patches, and maintain updated antivirus software to mitigate these persistent threats.
Pulse ID: 6a635bdf995351cf539c3b56
Pulse Link: https://otx.alienvault.com/pulse/6a635bdf995351cf539c3b56
Pulse Author: AlienVault
Created: 2026-07-24 12:34:39Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#AhnLab #Autoit #BackDoor #CyberSecurity #Email #GitHub #InfoSec #InfoStealer #KeyLogger #Korea #LNK #Malware #OTX #OpenThreatExchange #Phishing #PowerShell #Python #RAT #RCE #SouthKorea #SpearPhishing #bot #AlienVault
-
Analysis of Kimsuky's Attack on a South Korean Groupware Vendor Using a New Gomir Family Variant
Between 2025 and early 2026, the North Korean-linked Kimsuky group infiltrated South Korean groupware vendors through vulnerability exploitation and spear-phishing. They deployed two new malware variants, BirdTroy and DriveTroy, based on the Gomir/HttpTroy family. BirdTroy uses custom protocols and HTTP/3 (QUIC) for command-and-control communication, while DriveTroy abuses Google Drive as a C2 channel to evade detection. Following initial compromise, Kimsuky conducted aggressive lateral movement, compromising customer groupware servers and tampering with vendor login pages to harvest credentials. The attackers leveraged legitimate tools like DWAgent for remote access and custom proxy tools for lateral movement. Attribution is supported by malware characteristics, infrastructure patterns including default XAMPP certificates, and historical ASN usage consistent with previous Kimsuky operations.
Pulse ID: 6a5e7a9e8b20b763327b0d2d
Pulse Link: https://otx.alienvault.com/pulse/6a5e7a9e8b20b763327b0d2d
Pulse Author: AlienVault
Created: 2026-07-20 19:44:30Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #Google #HTTP #ICS #InfoSec #Kimsuky #Korea #Malware #NorthKorea #OTX #OpenThreatExchange #Phishing #Proxy #RAT #SouthKorea #SpearPhishing #UK #Vulnerability #bot #AlienVault
-
Analysis of Kimsuky's Attack on a South Korean Groupware Vendor Using a New Gomir Family Variant
Between 2025 and early 2026, the North Korean-linked Kimsuky group infiltrated South Korean groupware vendors through vulnerability exploitation and spear-phishing. They deployed two new malware variants, BirdTroy and DriveTroy, based on the Gomir/HttpTroy family. BirdTroy uses custom protocols and HTTP/3 (QUIC) for command-and-control communication, while DriveTroy abuses Google Drive as a C2 channel to evade detection. Following initial compromise, Kimsuky conducted aggressive lateral movement, compromising customer groupware servers and tampering with vendor login pages to harvest credentials. The attackers leveraged legitimate tools like DWAgent for remote access and custom proxy tools for lateral movement. Attribution is supported by malware characteristics, infrastructure patterns including default XAMPP certificates, and historical ASN usage consistent with previous Kimsuky operations.
Pulse ID: 6a5e7a9e8b20b763327b0d2d
Pulse Link: https://otx.alienvault.com/pulse/6a5e7a9e8b20b763327b0d2d
Pulse Author: AlienVault
Created: 2026-07-20 19:44:30Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #Google #HTTP #ICS #InfoSec #Kimsuky #Korea #Malware #NorthKorea #OTX #OpenThreatExchange #Phishing #Proxy #RAT #SouthKorea #SpearPhishing #UK #Vulnerability #bot #AlienVault
-
Analysis of Kimsuky's Attack on a South Korean Groupware Vendor Using a New Gomir Family Variant
Between 2025 and early 2026, the North Korean-linked Kimsuky group infiltrated South Korean groupware vendors through vulnerability exploitation and spear-phishing. They deployed two new malware variants, BirdTroy and DriveTroy, based on the Gomir/HttpTroy family. BirdTroy uses custom protocols and HTTP/3 (QUIC) for command-and-control communication, while DriveTroy abuses Google Drive as a C2 channel to evade detection. Following initial compromise, Kimsuky conducted aggressive lateral movement, compromising customer groupware servers and tampering with vendor login pages to harvest credentials. The attackers leveraged legitimate tools like DWAgent for remote access and custom proxy tools for lateral movement. Attribution is supported by malware characteristics, infrastructure patterns including default XAMPP certificates, and historical ASN usage consistent with previous Kimsuky operations.
Pulse ID: 6a5e7a9e8b20b763327b0d2d
Pulse Link: https://otx.alienvault.com/pulse/6a5e7a9e8b20b763327b0d2d
Pulse Author: AlienVault
Created: 2026-07-20 19:44:30Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #Google #HTTP #ICS #InfoSec #Kimsuky #Korea #Malware #NorthKorea #OTX #OpenThreatExchange #Phishing #Proxy #RAT #SouthKorea #SpearPhishing #UK #Vulnerability #bot #AlienVault
-
Analysis of Kimsuky's Attack on a South Korean Groupware Vendor Using a New Gomir Family Variant
Between 2025 and early 2026, the North Korean-linked Kimsuky group infiltrated South Korean groupware vendors through vulnerability exploitation and spear-phishing. They deployed two new malware variants, BirdTroy and DriveTroy, based on the Gomir/HttpTroy family. BirdTroy uses custom protocols and HTTP/3 (QUIC) for command-and-control communication, while DriveTroy abuses Google Drive as a C2 channel to evade detection. Following initial compromise, Kimsuky conducted aggressive lateral movement, compromising customer groupware servers and tampering with vendor login pages to harvest credentials. The attackers leveraged legitimate tools like DWAgent for remote access and custom proxy tools for lateral movement. Attribution is supported by malware characteristics, infrastructure patterns including default XAMPP certificates, and historical ASN usage consistent with previous Kimsuky operations.
Pulse ID: 6a5e7a9e8b20b763327b0d2d
Pulse Link: https://otx.alienvault.com/pulse/6a5e7a9e8b20b763327b0d2d
Pulse Author: AlienVault
Created: 2026-07-20 19:44:30Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #Google #HTTP #ICS #InfoSec #Kimsuky #Korea #Malware #NorthKorea #OTX #OpenThreatExchange #Phishing #Proxy #RAT #SouthKorea #SpearPhishing #UK #Vulnerability #bot #AlienVault
-
Analysis of Kimsuky's Attack on a South Korean Groupware Vendor Using a New Gomir Family Variant
Between 2025 and early 2026, the North Korean-linked Kimsuky group infiltrated South Korean groupware vendors through vulnerability exploitation and spear-phishing. They deployed two new malware variants, BirdTroy and DriveTroy, based on the Gomir/HttpTroy family. BirdTroy uses custom protocols and HTTP/3 (QUIC) for command-and-control communication, while DriveTroy abuses Google Drive as a C2 channel to evade detection. Following initial compromise, Kimsuky conducted aggressive lateral movement, compromising customer groupware servers and tampering with vendor login pages to harvest credentials. The attackers leveraged legitimate tools like DWAgent for remote access and custom proxy tools for lateral movement. Attribution is supported by malware characteristics, infrastructure patterns including default XAMPP certificates, and historical ASN usage consistent with previous Kimsuky operations.
Pulse ID: 6a5e7a9e8b20b763327b0d2d
Pulse Link: https://otx.alienvault.com/pulse/6a5e7a9e8b20b763327b0d2d
Pulse Author: AlienVault
Created: 2026-07-20 19:44:30Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #Google #HTTP #ICS #InfoSec #Kimsuky #Korea #Malware #NorthKorea #OTX #OpenThreatExchange #Phishing #Proxy #RAT #SouthKorea #SpearPhishing #UK #Vulnerability #bot #AlienVault
-
Genians exposed Operation Capsule Vault, an APT37 campaign. The RokRAT malware hides inside a fake PDF to spy on academics and researchers.
-
Update on Attacks by Threat Group APT-C-60 in 2026
APT-C-60 continues targeting organizations in Japan with evolved tactics observed throughout 2026. The threat group employs spear-phishing emails containing Proton Drive links or direct attachments with RAR archives. Victims extract LNK files that execute JavaScript via mshta.exe, leading to multi-stage payload delivery. The attackers abuse legitimate services including GitHub, GitLab, jsDelivr, and Codeberg as infrastructure for hosting malicious components. Git.exe is leveraged to execute scripts that deploy downloaders and loaders, ultimately delivering SpyGlace malware versions 3.1.15 through 3.1.18. The attack chain involves multiple obfuscated JavaScript files and persistence mechanisms similar to previous campaigns. By utilizing developer-oriented services and CDNs commonly allowed in corporate environments, the threat actor attempts to evade detection and blend malicious traffic with legitimate communications.
Pulse ID: 6a54e01e0597d81e8ad9f7d0
Pulse Link: https://otx.alienvault.com/pulse/6a54e01e0597d81e8ad9f7d0
Pulse Author: AlienVault
Created: 2026-07-13 12:54:54Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CDN #CyberSecurity #DNS #Email #GitHub #ICS #InfoSec #Japan #Java #JavaScript #LNK #Malware #OTX #OpenThreatExchange #Phishing #RAT #SMS #SpearPhishing #bot #AlienVault
-
Update on Attacks by Threat Group APT-C-60 in 2026
APT-C-60 continues targeting organizations in Japan with evolved tactics observed throughout 2026. The threat group employs spear-phishing emails containing Proton Drive links or direct attachments with RAR archives. Victims extract LNK files that execute JavaScript via mshta.exe, leading to multi-stage payload delivery. The attackers abuse legitimate services including GitHub, GitLab, jsDelivr, and Codeberg as infrastructure for hosting malicious components. Git.exe is leveraged to execute scripts that deploy downloaders and loaders, ultimately delivering SpyGlace malware versions 3.1.15 through 3.1.18. The attack chain involves multiple obfuscated JavaScript files and persistence mechanisms similar to previous campaigns. By utilizing developer-oriented services and CDNs commonly allowed in corporate environments, the threat actor attempts to evade detection and blend malicious traffic with legitimate communications.
Pulse ID: 6a54e01e0597d81e8ad9f7d0
Pulse Link: https://otx.alienvault.com/pulse/6a54e01e0597d81e8ad9f7d0
Pulse Author: AlienVault
Created: 2026-07-13 12:54:54Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CDN #CyberSecurity #DNS #Email #GitHub #ICS #InfoSec #Japan #Java #JavaScript #LNK #Malware #OTX #OpenThreatExchange #Phishing #RAT #SMS #SpearPhishing #bot #AlienVault
-
Update on Attacks by Threat Group APT-C-60 in 2026
APT-C-60 continues targeting organizations in Japan with evolved tactics observed throughout 2026. The threat group employs spear-phishing emails containing Proton Drive links or direct attachments with RAR archives. Victims extract LNK files that execute JavaScript via mshta.exe, leading to multi-stage payload delivery. The attackers abuse legitimate services including GitHub, GitLab, jsDelivr, and Codeberg as infrastructure for hosting malicious components. Git.exe is leveraged to execute scripts that deploy downloaders and loaders, ultimately delivering SpyGlace malware versions 3.1.15 through 3.1.18. The attack chain involves multiple obfuscated JavaScript files and persistence mechanisms similar to previous campaigns. By utilizing developer-oriented services and CDNs commonly allowed in corporate environments, the threat actor attempts to evade detection and blend malicious traffic with legitimate communications.
Pulse ID: 6a54e01e0597d81e8ad9f7d0
Pulse Link: https://otx.alienvault.com/pulse/6a54e01e0597d81e8ad9f7d0
Pulse Author: AlienVault
Created: 2026-07-13 12:54:54Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CDN #CyberSecurity #DNS #Email #GitHub #ICS #InfoSec #Japan #Java #JavaScript #LNK #Malware #OTX #OpenThreatExchange #Phishing #RAT #SMS #SpearPhishing #bot #AlienVault
-
Update on Attacks by Threat Group APT-C-60 in 2026
APT-C-60 continues targeting organizations in Japan with evolved tactics observed throughout 2026. The threat group employs spear-phishing emails containing Proton Drive links or direct attachments with RAR archives. Victims extract LNK files that execute JavaScript via mshta.exe, leading to multi-stage payload delivery. The attackers abuse legitimate services including GitHub, GitLab, jsDelivr, and Codeberg as infrastructure for hosting malicious components. Git.exe is leveraged to execute scripts that deploy downloaders and loaders, ultimately delivering SpyGlace malware versions 3.1.15 through 3.1.18. The attack chain involves multiple obfuscated JavaScript files and persistence mechanisms similar to previous campaigns. By utilizing developer-oriented services and CDNs commonly allowed in corporate environments, the threat actor attempts to evade detection and blend malicious traffic with legitimate communications.
Pulse ID: 6a54e01e0597d81e8ad9f7d0
Pulse Link: https://otx.alienvault.com/pulse/6a54e01e0597d81e8ad9f7d0
Pulse Author: AlienVault
Created: 2026-07-13 12:54:54Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CDN #CyberSecurity #DNS #Email #GitHub #ICS #InfoSec #Japan #Java #JavaScript #LNK #Malware #OTX #OpenThreatExchange #Phishing #RAT #SMS #SpearPhishing #bot #AlienVault
-
Update on Attacks by Threat Group APT-C-60 in 2026
APT-C-60 continues targeting organizations in Japan with evolved tactics observed throughout 2026. The threat group employs spear-phishing emails containing Proton Drive links or direct attachments with RAR archives. Victims extract LNK files that execute JavaScript via mshta.exe, leading to multi-stage payload delivery. The attackers abuse legitimate services including GitHub, GitLab, jsDelivr, and Codeberg as infrastructure for hosting malicious components. Git.exe is leveraged to execute scripts that deploy downloaders and loaders, ultimately delivering SpyGlace malware versions 3.1.15 through 3.1.18. The attack chain involves multiple obfuscated JavaScript files and persistence mechanisms similar to previous campaigns. By utilizing developer-oriented services and CDNs commonly allowed in corporate environments, the threat actor attempts to evade detection and blend malicious traffic with legitimate communications.
Pulse ID: 6a54e01e0597d81e8ad9f7d0
Pulse Link: https://otx.alienvault.com/pulse/6a54e01e0597d81e8ad9f7d0
Pulse Author: AlienVault
Created: 2026-07-13 12:54:54Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CDN #CyberSecurity #DNS #Email #GitHub #ICS #InfoSec #Japan #Java #JavaScript #LNK #Malware #OTX #OpenThreatExchange #Phishing #RAT #SMS #SpearPhishing #bot #AlienVault
-
Operation Capsule Vault: RokRAT Attack Chain Analysis Using EMBED_PAYLOAD_v2
A sophisticated spear-phishing campaign targeted individuals in research, policy, and academic fields through emails disguised as materials from an actual academic conference. The attack leveraged a cloud storage link delivering a malicious ISO file containing a PIF executable disguised as a PDF document. The multi-stage loader used EMBED_PAYLOAD_v2 structure to embed both legitimate documents and malicious payloads, which were sequentially extracted and executed in memory. Shellcode injection into explorer.exe ultimately deployed a RokRAT variant communicating with cloud-based C2 infrastructure via pCloud, Dropbox, and Yandex Cloud. The campaign demonstrated advanced social engineering by exploiting information from a real event, combined with sophisticated evasion techniques including process injection and cloud-based command-and-control operations. Attribution analysis linked the activity to APT37 based on infrastructure overlap, code similarities, and operational patterns.
Pulse ID: 6a5414fab18f9d7456d7eda8
Pulse Link: https://otx.alienvault.com/pulse/6a5414fab18f9d7456d7eda8
Pulse Author: AlienVault
Created: 2026-07-12 22:28:10Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#APT37 #Cloud #CodeInjection #CyberSecurity #Dropbox #Email #InfoSec #OTX #OpenThreatExchange #PDF #Phishing #RAT #ShellCode #SocialEngineering #SpearPhishing #bot #pCloud #AlienVault
-
Operation Capsule Vault: RokRAT Attack Chain Analysis Using EMBED_PAYLOAD_v2
A sophisticated spear-phishing campaign targeted individuals in research, policy, and academic fields through emails disguised as materials from an actual academic conference. The attack leveraged a cloud storage link delivering a malicious ISO file containing a PIF executable disguised as a PDF document. The multi-stage loader used EMBED_PAYLOAD_v2 structure to embed both legitimate documents and malicious payloads, which were sequentially extracted and executed in memory. Shellcode injection into explorer.exe ultimately deployed a RokRAT variant communicating with cloud-based C2 infrastructure via pCloud, Dropbox, and Yandex Cloud. The campaign demonstrated advanced social engineering by exploiting information from a real event, combined with sophisticated evasion techniques including process injection and cloud-based command-and-control operations. Attribution analysis linked the activity to APT37 based on infrastructure overlap, code similarities, and operational patterns.
Pulse ID: 6a5414fab18f9d7456d7eda8
Pulse Link: https://otx.alienvault.com/pulse/6a5414fab18f9d7456d7eda8
Pulse Author: AlienVault
Created: 2026-07-12 22:28:10Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#APT37 #Cloud #CodeInjection #CyberSecurity #Dropbox #Email #InfoSec #OTX #OpenThreatExchange #PDF #Phishing #RAT #ShellCode #SocialEngineering #SpearPhishing #bot #pCloud #AlienVault
-
Operation Capsule Vault: RokRAT Attack Chain Analysis Using EMBED_PAYLOAD_v2
A sophisticated spear-phishing campaign targeted individuals in research, policy, and academic fields through emails disguised as materials from an actual academic conference. The attack leveraged a cloud storage link delivering a malicious ISO file containing a PIF executable disguised as a PDF document. The multi-stage loader used EMBED_PAYLOAD_v2 structure to embed both legitimate documents and malicious payloads, which were sequentially extracted and executed in memory. Shellcode injection into explorer.exe ultimately deployed a RokRAT variant communicating with cloud-based C2 infrastructure via pCloud, Dropbox, and Yandex Cloud. The campaign demonstrated advanced social engineering by exploiting information from a real event, combined with sophisticated evasion techniques including process injection and cloud-based command-and-control operations. Attribution analysis linked the activity to APT37 based on infrastructure overlap, code similarities, and operational patterns.
Pulse ID: 6a5414fab18f9d7456d7eda8
Pulse Link: https://otx.alienvault.com/pulse/6a5414fab18f9d7456d7eda8
Pulse Author: AlienVault
Created: 2026-07-12 22:28:10Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#APT37 #Cloud #CodeInjection #CyberSecurity #Dropbox #Email #InfoSec #OTX #OpenThreatExchange #PDF #Phishing #RAT #ShellCode #SocialEngineering #SpearPhishing #bot #pCloud #AlienVault
-
Operation Capsule Vault: RokRAT Attack Chain Analysis Using EMBED_PAYLOAD_v2
A sophisticated spear-phishing campaign targeted individuals in research, policy, and academic fields through emails disguised as materials from an actual academic conference. The attack leveraged a cloud storage link delivering a malicious ISO file containing a PIF executable disguised as a PDF document. The multi-stage loader used EMBED_PAYLOAD_v2 structure to embed both legitimate documents and malicious payloads, which were sequentially extracted and executed in memory. Shellcode injection into explorer.exe ultimately deployed a RokRAT variant communicating with cloud-based C2 infrastructure via pCloud, Dropbox, and Yandex Cloud. The campaign demonstrated advanced social engineering by exploiting information from a real event, combined with sophisticated evasion techniques including process injection and cloud-based command-and-control operations. Attribution analysis linked the activity to APT37 based on infrastructure overlap, code similarities, and operational patterns.
Pulse ID: 6a5414fab18f9d7456d7eda8
Pulse Link: https://otx.alienvault.com/pulse/6a5414fab18f9d7456d7eda8
Pulse Author: AlienVault
Created: 2026-07-12 22:28:10Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#APT37 #Cloud #CodeInjection #CyberSecurity #Dropbox #Email #InfoSec #OTX #OpenThreatExchange #PDF #Phishing #RAT #ShellCode #SocialEngineering #SpearPhishing #bot #pCloud #AlienVault
-
Operation Capsule Vault: RokRAT Attack Chain Analysis Using EMBED_PAYLOAD_v2
A sophisticated spear-phishing campaign targeted individuals in research, policy, and academic fields through emails disguised as materials from an actual academic conference. The attack leveraged a cloud storage link delivering a malicious ISO file containing a PIF executable disguised as a PDF document. The multi-stage loader used EMBED_PAYLOAD_v2 structure to embed both legitimate documents and malicious payloads, which were sequentially extracted and executed in memory. Shellcode injection into explorer.exe ultimately deployed a RokRAT variant communicating with cloud-based C2 infrastructure via pCloud, Dropbox, and Yandex Cloud. The campaign demonstrated advanced social engineering by exploiting information from a real event, combined with sophisticated evasion techniques including process injection and cloud-based command-and-control operations. Attribution analysis linked the activity to APT37 based on infrastructure overlap, code similarities, and operational patterns.
Pulse ID: 6a5414fab18f9d7456d7eda8
Pulse Link: https://otx.alienvault.com/pulse/6a5414fab18f9d7456d7eda8
Pulse Author: AlienVault
Created: 2026-07-12 22:28:10Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#APT37 #Cloud #CodeInjection #CyberSecurity #Dropbox #Email #InfoSec #OTX #OpenThreatExchange #PDF #Phishing #RAT #ShellCode #SocialEngineering #SpearPhishing #bot #pCloud #AlienVault
-
Xiamen Empress Information Technology: come Pechino ha affittato account LINE per spiare giornalisti e attivisti a Taiwan
Le autorità taiwanesi hanno incriminato due imprenditori per aver affittato account LINE a Xiamen Empress Information Technology, usati da operatori legati a Pechino per impersonare giornalisti e colpire funzionari, accademici e attivisti. Il caso conferma le inchieste di ICIJ e Citizen Lab sulla repressione transnazionale cinese. -
Xiamen Empress Information Technology: come Pechino ha affittato account LINE per spiare giornalisti e attivisti a Taiwan
Le autorità taiwanesi hanno incriminato due imprenditori per aver affittato account LINE a Xiamen Empress Information Technology, usati da operatori legati a Pechino per impersonare giornalisti e colpire funzionari, accademici e attivisti. Il caso conferma le inchieste di ICIJ e Citizen Lab sulla repressione transnazionale cinese. -
Xiamen Empress Information Technology: come Pechino ha affittato account LINE per spiare giornalisti e attivisti a Taiwan
Le autorità taiwanesi hanno incriminato due imprenditori per aver affittato account LINE a Xiamen Empress Information Technology, usati da operatori legati a Pechino per impersonare giornalisti e colpire funzionari, accademici e attivisti. Il caso conferma le inchieste di ICIJ e Citizen Lab sulla repressione transnazionale cinese. -
Xiamen Empress Information Technology: come Pechino ha affittato account LINE per spiare giornalisti e attivisti a Taiwan
Le autorità taiwanesi hanno incriminato due imprenditori per aver affittato account LINE a Xiamen Empress Information Technology, usati da operatori legati a Pechino per impersonare giornalisti e colpire funzionari, accademici e attivisti. Il caso conferma le inchieste di ICIJ e Citizen Lab sulla repressione transnazionale cinese. -
Xiamen Empress Information Technology: come Pechino ha affittato account LINE per spiare giornalisti e attivisti a Taiwan
Le autorità taiwanesi hanno incriminato due imprenditori per aver affittato account LINE a Xiamen Empress Information Technology, usati da operatori legati a Pechino per impersonare giornalisti e colpire funzionari, accademici e attivisti. Il caso conferma le inchieste di ICIJ e Citizen Lab sulla repressione transnazionale cinese. -
Once, during an #awareness session, I brought a jar into the room.
One of those old-school glass jars with a metal lid.
I put it on the table and asked the executives (not the CISOs) to drop a poker chip inside.
Yes, poker chips. Don’t laugh. That’s what I had.
The value of each chip was supposed to reflect two things: perceived risk and willingness to spend.
At the beginning, the jar looked miserable.
Two or three 50s.
One brave 500.
Fewer than ten 100s.Then came lunch.
Paid for, obviously.
But lunch was also the exercise.Heavy #socialengineering. Casual conversation. Names, routines, vendors, habits, internal friction, travel plans, tools, weak points, ego, trust.
Then the last two hours began.
Real risk demonstration.#spearphishing built with information collected during lunch.
Fake WhatsApp chats after recon.
#OSINT before the session even restarted.
QR codes everywhere.Then we talked about recovery costs.
Regulatory fines.
Production downtime.
Loss of trust.
Reputational damage.
The unpleasant difference between “unlikely” and “not impossible”.And, magically, the jar filled up with 500 and 1000 chips.
You don’t fucking say.
My #Decoded for #Baited: https://blog.baited.io/2026/cost-of-phishing-shrinking-budgets/
-
Once, during an #awareness session, I brought a jar into the room.
One of those old-school glass jars with a metal lid.
I put it on the table and asked the executives (not the CISOs) to drop a poker chip inside.
Yes, poker chips. Don’t laugh. That’s what I had.
The value of each chip was supposed to reflect two things: perceived risk and willingness to spend.
At the beginning, the jar looked miserable.
Two or three 50s.
One brave 500.
Fewer than ten 100s.Then came lunch.
Paid for, obviously.
But lunch was also the exercise.Heavy #socialengineering. Casual conversation. Names, routines, vendors, habits, internal friction, travel plans, tools, weak points, ego, trust.
Then the last two hours began.
Real risk demonstration.#spearphishing built with information collected during lunch.
Fake WhatsApp chats after recon.
#OSINT before the session even restarted.
QR codes everywhere.Then we talked about recovery costs.
Regulatory fines.
Production downtime.
Loss of trust.
Reputational damage.
The unpleasant difference between “unlikely” and “not impossible”.And, magically, the jar filled up with 500 and 1000 chips.
You don’t fucking say.
My #Decoded for #Baited: https://blog.baited.io/2026/cost-of-phishing-shrinking-budgets/
-
Once, during an #awareness session, I brought a jar into the room.
One of those old-school glass jars with a metal lid.
I put it on the table and asked the executives (not the CISOs) to drop a poker chip inside.
Yes, poker chips. Don’t laugh. That’s what I had.
The value of each chip was supposed to reflect two things: perceived risk and willingness to spend.
At the beginning, the jar looked miserable.
Two or three 50s.
One brave 500.
Fewer than ten 100s.Then came lunch.
Paid for, obviously.
But lunch was also the exercise.Heavy #socialengineering. Casual conversation. Names, routines, vendors, habits, internal friction, travel plans, tools, weak points, ego, trust.
Then the last two hours began.
Real risk demonstration.#spearphishing built with information collected during lunch.
Fake WhatsApp chats after recon.
#OSINT before the session even restarted.
QR codes everywhere.Then we talked about recovery costs.
Regulatory fines.
Production downtime.
Loss of trust.
Reputational damage.
The unpleasant difference between “unlikely” and “not impossible”.And, magically, the jar filled up with 500 and 1000 chips.
You don’t fucking say.
My #Decoded for #Baited: https://blog.baited.io/2026/cost-of-phishing-shrinking-budgets/
-
Once, during an #awareness session, I brought a jar into the room.
One of those old-school glass jars with a metal lid.
I put it on the table and asked the executives (not the CISOs) to drop a poker chip inside.
Yes, poker chips. Don’t laugh. That’s what I had.
The value of each chip was supposed to reflect two things: perceived risk and willingness to spend.
At the beginning, the jar looked miserable.
Two or three 50s.
One brave 500.
Fewer than ten 100s.Then came lunch.
Paid for, obviously.
But lunch was also the exercise.Heavy #socialengineering. Casual conversation. Names, routines, vendors, habits, internal friction, travel plans, tools, weak points, ego, trust.
Then the last two hours began.
Real risk demonstration.#spearphishing built with information collected during lunch.
Fake WhatsApp chats after recon.
#OSINT before the session even restarted.
QR codes everywhere.Then we talked about recovery costs.
Regulatory fines.
Production downtime.
Loss of trust.
Reputational damage.
The unpleasant difference between “unlikely” and “not impossible”.And, magically, the jar filled up with 500 and 1000 chips.
You don’t fucking say.
My #Decoded for #Baited: https://blog.baited.io/2026/cost-of-phishing-shrinking-budgets/
-
Once, during an #awareness session, I brought a jar into the room.
One of those old-school glass jars with a metal lid.
I put it on the table and asked the executives (not the CISOs) to drop a poker chip inside.
Yes, poker chips. Don’t laugh. That’s what I had.
The value of each chip was supposed to reflect two things: perceived risk and willingness to spend.
At the beginning, the jar looked miserable.
Two or three 50s.
One brave 500.
Fewer than ten 100s.Then came lunch.
Paid for, obviously.
But lunch was also the exercise.Heavy #socialengineering. Casual conversation. Names, routines, vendors, habits, internal friction, travel plans, tools, weak points, ego, trust.
Then the last two hours began.
Real risk demonstration.#spearphishing built with information collected during lunch.
Fake WhatsApp chats after recon.
#OSINT before the session even restarted.
QR codes everywhere.Then we talked about recovery costs.
Regulatory fines.
Production downtime.
Loss of trust.
Reputational damage.
The unpleasant difference between “unlikely” and “not impossible”.And, magically, the jar filled up with 500 and 1000 chips.
You don’t fucking say.
My #Decoded for #Baited: https://blog.baited.io/2026/cost-of-phishing-shrinking-budgets/
-
https://www.europesays.com/si/142358/ Ena pika je bila dovolj: 41-letni računovodja goljufom nevede nakazal 5000 evrov #Business #DirektorskePrevare #Economic #FinančneGoljufije #IzobraževanjeZaposlenih #KibernetskaVarnost #Poslovni #PoslovniSvet #SI #Slovene #Slovenia #Slovenija #Slovenščina #SocialniInženiring #SpearPhishing #VarnostniProtokoli
-
The New Frontier: Securing Japan’s Hybrid Digital Workforce (2026 & Beyond)
As Japan navigates the mid-point of the decade, its cybersecurity landscape is undergoing a fundamental transformation. Driven by…
#EuropeSays #Japan #JP #anti-phishingtraining #cryptolocker #Florida #hackers #hacking #kevinmitnick #knowbe4 #Nihon #on-linetraining #phish-prone #phishing #ransomware #securityawarenesstraining #socialengineering #spearphishing #stusjouwerman #tampabay #Training
https://www.europesays.com/japan/37843/ -
The New Frontier: Securing Japan’s Hybrid Digital Workforce (2026 & Beyond)
As Japan navigates the mid-point of the decade, its cyb…
#Japan #JP #JapanNews #anti-phishingtraining #cryptolocker #florida #hackers #hacking #kevinmitnick #knowbe4 #news #on-linetraining #phish-prone #phishing #ransomware #securityawarenesstraining #socialengineering #spearphishing #stusjouwerman #tampabay #training
https://www.alojapan.com/1496415/the-new-frontier-securing-japans-hybrid-digital-workforce-2026-beyond/ -
The New Frontier: Securing Japan’s Hybrid Digital Workforce (2026 & Beyond)
As Japan navigates the mid-point of the decade, its cyb…
#Japan #JP #JapanNews #anti-phishingtraining #cryptolocker #florida #hackers #hacking #kevinmitnick #knowbe4 #news #on-linetraining #phish-prone #phishing #ransomware #securityawarenesstraining #socialengineering #spearphishing #stusjouwerman #tampabay #training
https://www.alojapan.com/1496415/the-new-frontier-securing-japans-hybrid-digital-workforce-2026-beyond/ -
https://www.alojapan.com/1496415/the-new-frontier-securing-japans-hybrid-digital-workforce-2026-beyond/ The New Frontier: Securing Japan’s Hybrid Digital Workforce (2026 & Beyond) #AntiPhishingTraining #cryptolocker #florida #hackers #hacking #Japan #JapanNews #KevinMitnick #knowbe4 #news #OnLineTraining #PhishProne #phishing #ransomware #SecurityAwarenessTraining #SocialEngineering #SpearPhishing #StuSjouwerman #TampaBay #training As Japan navigates the mid-point of the decade, its cybersecurity landscape is undergoing a fundamental trans
-
https://www.alojapan.com/1496415/the-new-frontier-securing-japans-hybrid-digital-workforce-2026-beyond/ The New Frontier: Securing Japan’s Hybrid Digital Workforce (2026 & Beyond) #AntiPhishingTraining #cryptolocker #florida #hackers #hacking #Japan #JapanNews #KevinMitnick #knowbe4 #news #OnLineTraining #PhishProne #phishing #ransomware #SecurityAwarenessTraining #SocialEngineering #SpearPhishing #StuSjouwerman #TampaBay #training As Japan navigates the mid-point of the decade, its cybersecurity landscape is undergoing a fundamental trans
-
Meta Disrupts NSO Group's WhatsApp Phishing Campaign
Meta detected and blocked a sneaky WhatsApp phishing campaign linked to NSO Group, where attackers tried to trick people into clicking malicious links that led to external websites. The company also filed a contempt order against NSO for allegedly violating a court injunction by targeting WhatsApp users.
#WhatsappPhishing #NsoGroup #SpearPhishing #Meta #1clickPhishing
-
SideCopy Targets Afghan Finance Ministry with Xeno RAT Malware
Seqrite Labs researchers uncovered a sneaky malware attack, dubbed Operation XENOFISCAL, where the Pakistan-aligned SideCopy group targeted Afghanistan's Ministry of Finance and government officials with a cleverly crafted phishing lure written in Pashto. The attack used Xeno RAT Malware, delivered through a ZIP archive with a malicious…
#XenoRatMalware #Sidecopy #Afghanistan #FinanceSector #SpearPhishing
-
Operation Dragon Weave: l’APT cinese usa Azure Blob Storage come C2 per colpire Repubblica Ceca e Taiwan
Seqrite ha identificato Operation Dragon Weave, una campagna APT attribuita con moderata confidenza a un attore cinese che colpisce funzionari e ricercatori in Repubblica Ceca e Taiwan. Il payload finale AZUREVEIL usa Azure Blob Storage come canale C2 dead-drop, mascherando il traffico malevolo tra le normali comunicazioni cloud enterprise.