#spearphishing — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #spearphishing, aggregated by home.social.
-
Mind the (Patch) Gap: Multiple Chinese Threat Actors Chain 0-day Exploits in Chrome & Windows
In September 2026, two Chinese threat actors, UTA0560 and JungleBamboo, were observed exploiting an identical Chrome zero-day vulnerability chain targeting NGOs and other organizations. The exploitation leveraged CVE-2026-85046 and CVE-2026-87491 in Chrome alongside CVE-2026-85880 in Windows kernel. These vulnerabilities had been patched in Chromium source code but not yet released to Chrome users, creating a patch-gap exploitation window. UTA0560 conducted spear-phishing campaigns using financial lures to deliver GRIMWEDGE JScript backdoor for reconnaissance and command execution. JungleBamboo employed generic phishing themes to deploy SUPERSTOMP loader, which installed the LONGTALE Chrome extension designed for credential theft, keylogging, and surveillance. Both actors used byte-for-byte identical shellcode, suggesting a shared exploit supply chain while deploying distinct post-exploitation tools tailored to their operational objectives.
Pulse ID: 6aa2707076e8a9dd36706bde
Pulse Link: https://otx.alienvault.com/pulse/6aa2707076e8a9dd36706bde
Pulse Author: AlienVault
Created: 2026-09-10 08:55:12Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#0Day #BackDoor #Chinese #Chrome #ChromeExtension #CyberSecurity #Edge #InfoSec #OTX #OpenThreatExchange #Phishing #RAT #RCE #ShellCode #SpearPhishing #SupplyChain #Vulnerability #Windows #ZeroDay #bot #AlienVault
-
Mind the (Patch) Gap: Multiple Chinese Threat Actors Chain 0-day Exploits in Chrome & Windows
In September 2026, two Chinese threat actors, UTA0560 and JungleBamboo, were observed exploiting an identical Chrome zero-day vulnerability chain targeting NGOs and other organizations. The exploitation leveraged CVE-2026-85046 and CVE-2026-87491 in Chrome alongside CVE-2026-85880 in Windows kernel. These vulnerabilities had been patched in Chromium source code but not yet released to Chrome users, creating a patch-gap exploitation window. UTA0560 conducted spear-phishing campaigns using financial lures to deliver GRIMWEDGE JScript backdoor for reconnaissance and command execution. JungleBamboo employed generic phishing themes to deploy SUPERSTOMP loader, which installed the LONGTALE Chrome extension designed for credential theft, keylogging, and surveillance. Both actors used byte-for-byte identical shellcode, suggesting a shared exploit supply chain while deploying distinct post-exploitation tools tailored to their operational objectives.
Pulse ID: 6aa2707076e8a9dd36706bde
Pulse Link: https://otx.alienvault.com/pulse/6aa2707076e8a9dd36706bde
Pulse Author: AlienVault
Created: 2026-09-10 08:55:12Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#0Day #BackDoor #Chinese #Chrome #ChromeExtension #CyberSecurity #Edge #InfoSec #OTX #OpenThreatExchange #Phishing #RAT #RCE #ShellCode #SpearPhishing #SupplyChain #Vulnerability #Windows #ZeroDay #bot #AlienVault
-
Mind the (Patch) Gap: Multiple Chinese Threat Actors Chain 0-day Exploits in Chrome & Windows
In September 2026, two Chinese threat actors, UTA0560 and JungleBamboo, were observed exploiting an identical Chrome zero-day vulnerability chain targeting NGOs and other organizations. The exploitation leveraged CVE-2026-85046 and CVE-2026-87491 in Chrome alongside CVE-2026-85880 in Windows kernel. These vulnerabilities had been patched in Chromium source code but not yet released to Chrome users, creating a patch-gap exploitation window. UTA0560 conducted spear-phishing campaigns using financial lures to deliver GRIMWEDGE JScript backdoor for reconnaissance and command execution. JungleBamboo employed generic phishing themes to deploy SUPERSTOMP loader, which installed the LONGTALE Chrome extension designed for credential theft, keylogging, and surveillance. Both actors used byte-for-byte identical shellcode, suggesting a shared exploit supply chain while deploying distinct post-exploitation tools tailored to their operational objectives.
Pulse ID: 6aa2707076e8a9dd36706bde
Pulse Link: https://otx.alienvault.com/pulse/6aa2707076e8a9dd36706bde
Pulse Author: AlienVault
Created: 2026-09-10 08:55:12Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#0Day #BackDoor #Chinese #Chrome #ChromeExtension #CyberSecurity #Edge #InfoSec #OTX #OpenThreatExchange #Phishing #RAT #RCE #ShellCode #SpearPhishing #SupplyChain #Vulnerability #Windows #ZeroDay #bot #AlienVault
-
Mind the (Patch) Gap: Multiple Chinese Threat Actors Chain 0-day Exploits in Chrome & Windows
In September 2026, two Chinese threat actors, UTA0560 and JungleBamboo, were observed exploiting an identical Chrome zero-day vulnerability chain targeting NGOs and other organizations. The exploitation leveraged CVE-2026-85046 and CVE-2026-87491 in Chrome alongside CVE-2026-85880 in Windows kernel. These vulnerabilities had been patched in Chromium source code but not yet released to Chrome users, creating a patch-gap exploitation window. UTA0560 conducted spear-phishing campaigns using financial lures to deliver GRIMWEDGE JScript backdoor for reconnaissance and command execution. JungleBamboo employed generic phishing themes to deploy SUPERSTOMP loader, which installed the LONGTALE Chrome extension designed for credential theft, keylogging, and surveillance. Both actors used byte-for-byte identical shellcode, suggesting a shared exploit supply chain while deploying distinct post-exploitation tools tailored to their operational objectives.
Pulse ID: 6aa2707076e8a9dd36706bde
Pulse Link: https://otx.alienvault.com/pulse/6aa2707076e8a9dd36706bde
Pulse Author: AlienVault
Created: 2026-09-10 08:55:12Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#0Day #BackDoor #Chinese #Chrome #ChromeExtension #CyberSecurity #Edge #InfoSec #OTX #OpenThreatExchange #Phishing #RAT #RCE #ShellCode #SpearPhishing #SupplyChain #Vulnerability #Windows #ZeroDay #bot #AlienVault
-
Mind the (Patch) Gap: Multiple Chinese Threat Actors Chain 0-day Exploits in Chrome & Windows
In September 2026, two Chinese threat actors, UTA0560 and JungleBamboo, were observed exploiting an identical Chrome zero-day vulnerability chain targeting NGOs and other organizations. The exploitation leveraged CVE-2026-85046 and CVE-2026-87491 in Chrome alongside CVE-2026-85880 in Windows kernel. These vulnerabilities had been patched in Chromium source code but not yet released to Chrome users, creating a patch-gap exploitation window. UTA0560 conducted spear-phishing campaigns using financial lures to deliver GRIMWEDGE JScript backdoor for reconnaissance and command execution. JungleBamboo employed generic phishing themes to deploy SUPERSTOMP loader, which installed the LONGTALE Chrome extension designed for credential theft, keylogging, and surveillance. Both actors used byte-for-byte identical shellcode, suggesting a shared exploit supply chain while deploying distinct post-exploitation tools tailored to their operational objectives.
Pulse ID: 6aa2707076e8a9dd36706bde
Pulse Link: https://otx.alienvault.com/pulse/6aa2707076e8a9dd36706bde
Pulse Author: AlienVault
Created: 2026-09-10 08:55:12Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#0Day #BackDoor #Chinese #Chrome #ChromeExtension #CyberSecurity #Edge #InfoSec #OTX #OpenThreatExchange #Phishing #RAT #RCE #ShellCode #SpearPhishing #SupplyChain #Vulnerability #Windows #ZeroDay #bot #AlienVault
-
BigBear 2.0: la piattaforma di phishing-as-a-service che aggira anche l’MFA di Microsoft 365
CloudSEK smaschera BigBear 2.0, un kit AiTM basato su Evilginx2 che ha compromesso 258 organizzazioni in 40 paesi, rubando 474 sessioni con secondo fattore già superato e disabilitando via JavaScript le chiavi di sicurezza FIDO2/WebAuthn. -
BigBear 2.0: la piattaforma di phishing-as-a-service che aggira anche l’MFA di Microsoft 365
CloudSEK smaschera BigBear 2.0, un kit AiTM basato su Evilginx2 che ha compromesso 258 organizzazioni in 40 paesi, rubando 474 sessioni con secondo fattore già superato e disabilitando via JavaScript le chiavi di sicurezza FIDO2/WebAuthn. -
BigBear 2.0: la piattaforma di phishing-as-a-service che aggira anche l’MFA di Microsoft 365
CloudSEK smaschera BigBear 2.0, un kit AiTM basato su Evilginx2 che ha compromesso 258 organizzazioni in 40 paesi, rubando 474 sessioni con secondo fattore già superato e disabilitando via JavaScript le chiavi di sicurezza FIDO2/WebAuthn. -
BigBear 2.0: la piattaforma di phishing-as-a-service che aggira anche l’MFA di Microsoft 365
CloudSEK smaschera BigBear 2.0, un kit AiTM basato su Evilginx2 che ha compromesso 258 organizzazioni in 40 paesi, rubando 474 sessioni con secondo fattore già superato e disabilitando via JavaScript le chiavi di sicurezza FIDO2/WebAuthn. -
BigBear 2.0: la piattaforma di phishing-as-a-service che aggira anche l’MFA di Microsoft 365
CloudSEK smaschera BigBear 2.0, un kit AiTM basato su Evilginx2 che ha compromesso 258 organizzazioni in 40 paesi, rubando 474 sessioni con secondo fattore già superato e disabilitando via JavaScript le chiavi di sicurezza FIDO2/WebAuthn. -
Inside Kimsuky's Abuse of Legitimate Remote Control Tools Across Northeast Asia
Kimsuky conducted spear phishing campaigns against South Korean and Japanese targets during the first half of 2026, distributing LNK malware through OneDrive share links. The malicious files established scheduled tasks that periodically fetched PowerShell scripts from command-and-control servers to profile systems, exfiltrate Thunderbird and Outlook email data, and log keystrokes. The threat actor installed legitimate remote control software including Chrome Remote Desktop and AnyDesk to evade antivirus detection and maintain multiple access channels. A malicious Chrome extension designed to steal Gmail data exhibited characteristics of AI-generated code, featuring Korean comments, debug strings, and Unicode emoji throughout. The operation employed rotating infrastructure and compromised legitimate Korean servers as command-and-control nodes to impede tracking efforts.
Pulse ID: 6a873495a873c0ec3c6d9880
Pulse Link: https://otx.alienvault.com/pulse/6a873495a873c0ec3c6d9880
Pulse Author: AlienVault
Created: 2026-08-20 17:08:37Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#AnyDesk #Asia #Chrome #ChromeExtension #CyberSecurity #EDR #Email #ICS #InfoSec #Japan #Kimsuky #Korea #LNK #Malware #OTX #OpenThreatExchange #Outlook #Phishing #PowerShell #RAT #SouthKorea #SpearPhishing #UK #bot #AlienVault
-
SilkParasite: Tracking a China-Nexus APT Across Central Asia
SilkParasite is a cyberespionage operation assessed with medium confidence as China-nexus that targeted government bodies across Central Asia. Seven remote access tool families were deployed, five of which were previously undocumented: DriveSilkRAT, CookiETagRAT, NomadRAT, GoginRAT, and NodeEdgeRAT. The toolset is small, modular, and professionally engineered with traces of AI-assisted development. Initial access occurred through malicious Microsoft Office documents delivered via spear-phishing, using regionally tailored lures impersonating government ministries. The operation leveraged DLL sideloading as the primary delivery mechanism and used Google Drive for command-and-control communications to hide within trusted services. Infrastructure analysis identified connections to China Unicom's backbone network, and operational patterns suggest a functioning software organization with maintained build pipelines and careful operational security.
Pulse ID: 6a86a70eb8b57f155e62d4f7
Pulse Link: https://otx.alienvault.com/pulse/6a86a70eb8b57f155e62d4f7
Pulse Author: AlienVault
Created: 2026-08-20 07:04:46Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Asia #CentralAsia #China #CyberSecurity #Cyberespionage #DRat #Edge #Espionage #Google #Government #InfoSec #Microsoft #MicrosoftOffice #OTX #Office #OpenThreatExchange #Phishing #RAT #Rust #SideLoading #SpearPhishing #bot #AlienVault
-
The Stark Truth Behind the Resurgence of Russia’s Fin7
https://krebsonsecurity.com/2024/07/the-stark-truth-behind-the-resurgence-of-russias-fin7/
#StarkIndustriesSolutions #Russia'sWaronUkraine #ProtectedPDFViewer #Ne'er-Do-WellNews #AdvancedIPScanner #BastionSecure #CombiSecurity #spearphishing #typosquatting #Malwarebytes #WebFraud2.0 #SublimeText #ZachEdwards #Ransomware #Blackberry #SilentPush #Bitwarden #microsoft #Notepad++ #RestProxy #AutoDesk #eSentire #AnyDesk #Node.js #pgAdmin #AIMP
-
📬 Phishing-Angriff auf Pepco: Millionenverlust für Einzelhandelskonzern
#ITSicherheit #Dealz #Pepco #Phishing #PhishingAngriff #Poundland #socialengineering #SpearPhishing #Typosquatting https://sc.tarnkappe.info/0d115d -
📬 Schutz vor Phishing: Die Tricks der Betrüger und wie man sich schützt
#Datenschutz #ITSicherheit #Datendiebstahl #EMailPhishing #Pharming #Phishing #PhishingAngriff #Smishing #socialengineering #SpearPhishing #Vishing https://tarnkappe.info/artikel/it-sicherheit/schutz-vor-phishing-die-tricks-der-betrueger-und-wie-man-sich-schuetzt-280852.html