Advertisement
China-Linked UAT-8302 Targets Governments with Custom APT Malware
UAT-8302, a China-linked threat group, targets government entities in South America and SE Europe using custom malware and shared APT toolsets.
Silver Fox APT: Tax-Themed Phishing Delivers ABCDoor to India, Russia
China-backed Silver Fox APT targets organizations in India and Russia with over 1,600 tax-themed phishing messages to deploy ABCDoor backdoor and ValleyRAT.
20 Years of Threat Intel: Analyzing Adversarial Evolution Since 2006
Historical analysis of cybersecurity threat evolution over two decades, focusing on the transition from simple exploits to complex APT campaigns.
Lazarus Group's $2B+ Crypto Theft: Defending Against Supply Chain Attacks
An analysis of Lazarus Group's persistent and financially motivated cyber operations, highlighting over $2B in crypto theft and critical supply chain attack risks.
Alleged Silk Typhoon Hacker Extradited: Cyberespionage Threat
An alleged Silk Typhoon hacker, associated with Chinese intelligence, has been extradited to the US, highlighting persistent nation-state cyberespionage threats.
Chinese State-Backed Actors Industrialize Botnets for Covert Ops
Chinese state-backed groups are adopting industrialized botnets, utilizing compromised devices for low-cost, low-risk, and deniable cyber operations.
Advertisement
FIRESTARTER Backdoor: Persistent Threat to Cisco Firepower & Secure Firewall
CISA and NCSC warn of FIRESTARTER, an APT-deployed backdoor maintaining persistence on Cisco Firepower and Secure Firewall devices post-patching.
GopherWhisper APT Abuses Outlook and Slack for Stealthy C2
Newly discovered GopherWhisper APT group uses a Go-based toolkit and legitimate SaaS platforms like Slack and Outlook to conduct espionage against governments.
Sapphire Sleet's ClickFix: North Korea Targets macOS Users
North Korea-backed Sapphire Sleet is deploying ClickFix malware via fake job offers and phony Zoom updates to steal macOS user credentials and data.
Iran Geopolitical Tensions: Cyber Implications & Preparedness
Examine the potential cybersecurity implications of escalating geopolitical tensions involving Iran, focusing on nation-state TTPs and organizational preparedness…
UAT-10362 Targets Taiwanese NGOs with LucidRook Malware
Runtime Rebel analyzes UAT-10362's sophisticated spear-phishing campaigns deploying new Lua-based LucidRook malware against Taiwanese NGOs and universities.
TA416 Targets European Govts with PlugX & OAuth Phishing
China-linked TA416 has resumed targeting European government and diplomatic entities since mid-2025 using PlugX and OAuth-based phishing attacks.
Quantum Geopolitics: Cyber Threats in an Era of Iran Conflict
Analyze how the shift toward quantum geopolitics and Iranian proxy conflicts impact global cyber stability and critical infrastructure protection.
Iranian Hackers Target Kash Patel: US Offers $10M Bounty
The FBI confirms Iranian state-sponsored hackers compromised Kash Patel’s personal email, leading the U.S. to offer a $10M reward for information.
China-Linked APT Clusters Target SE Asian Government via HIUPAN
Three China-linked threat clusters targeted a Southeast Asian government in 2025 using HIUPAN, PUBLOAD, and EggStremeFuel malware in a complex espionage operation.
Red Menshen APT Deploys Upgraded BPFdoor Backdoor Against Telcos
Chinese APT Red Menshen utilizes an upgraded BPFdoor backdoor to target global telecommunication companies, bypassing traditional defenses.
Red Menshen BPFDoor Implants Target Telecom Networks for Espionage
Analysis of China-linked Red Menshen's long-term campaign using stealthy BPFDoor implants within telecom networks to conduct espionage against government entities.
Russian Intelligence Phishing Targets Signal and WhatsApp Users
The FBI warns of sophisticated phishing campaigns by Russian intelligence targeting Signal and WhatsApp users to harvest credentials and bypass encryption.
Bitrefill Attributes Cyberattack to North Korean Lazarus Group
Bitrefill identifies North Korean Lazarus Group as the perpetrator of a recent cyberattack, underscoring the persistent threat to crypto-focused businesses.
SideWinder APT Expands Southeast Asia Espionage Campaign
SideWinder APT targets government and telecom sectors in Southeast Asia using spear-phishing and rotating infrastructure for persistent espionage operations.
Konni Group Deploys EndRAT via Phishing and KakaoTalk Hijacking
North Korean threat actor Konni leverages spear-phishing and KakaoTalk desktop exploitation to distribute EndRAT malware and facilitate lateral movement.
Poland’s Nuclear Center Targeted in Suspected Iranian Cyberattack
Polish officials investigate a cyberattack at the NCBJ nuclear center. Initial evidence points to Iran, but investigators warn of potential false flag tactics.
Iranian MOIS Collusion with Cybercriminals: Evolving Hybrid Threat
Iranian state-sponsored APTs, linked to MOIS, are now directly collaborating with cybercriminal organizations, escalating hybrid cyber operations. Defenders must adapt.
TfL Data Breach and Avira Security Flaws: Weekly Threat Briefing
Analysis of the Transport for London breach affecting 10 million users, Avira antivirus security flaws, and North Korean cyber actor attribution.