Advertisement
U.S. Sanctions Iran-Linked Hackers Targeting Critical Infrastructure
U.S. Treasury sanctions Iran-linked cyber actors, including Mabna Institute members, for critical infrastructure breaches and cyber theft.
Transparent Tribe Targets Afghan and Indian Organizations
Pakistan-linked Transparent Tribe updates its malware toolset to target Afghan organizations and government agencies in India.
US Charges Iranian Hackers in $3.4B Intellectual Property Theft
US charges 17 Iranian hackers from Mabna Institute for a state-sponsored campaign stealing 31.5 TB of academic and corporate intellectual property since 2013.
AI-Driven Cyberattack Targets APAC Government Agencies
A China-linked actor reportedly deployed a near-autonomous AI framework to compromise government agencies in the APAC region, signaling a new threat landscape.
Jewelbug APT: Dual-Motivation Espionage & Crypto Heists
Jewelbug APT, a unique 'hackers-for-hire' group, conducts state-sponsored espionage and financially motivated cryptocurrency heists from a single operational panel.
CVE-2025-66376: APT28 Exploits Zimbra Zero-Click for Espionage
Russian state-sponsored actors exploit a zero-click Zimbra vulnerability (CVE-2025-66376) to exfiltrate sensitive webmail data from targeted organizations.
Advertisement
EU Sanctions Russian Intel Officers for APT28 Cyber Operations
The EU imposes sanctions on Russian GRU officers linked to APT28 for long-term cyber espionage and sabotage targeting government and infrastructure.
Parallel APT Cyber Espionage Targets Balochistan Police
Analysis of parallel cyber espionage campaigns by China and India-linked APTs against Pakistan's Balochistan Police, detailed by SentinelOne.
Iran Cyber Focus Expands: Securing Internet-Facing Vulnerabilities
Iranian state-sponsored cyber operations are broadening targets beyond critical infrastructure. All organizations must secure Internet-facing systems.
Armored Likho Leverages BusySnake Stealer Against Critical Sectors
Undocumented threat actor Armored Likho targets government and electric power sectors in Russia, Brazil, and Kazakhstan with BusySnake Stealer.
Turla's STOCKSTAY Backdoor: Analysis of Campaigns & WinRAR Exploit
Google Threat Intelligence details STOCKSTAY, Turla's .NET backdoor for espionage targeting Ukraine and Europe, leveraging RDP & CVE-2025-8088.
Chinese Espionage: Google Workspace Rule Abuse in Research Sectors
China-linked threat actors exploited REDCap server backdoors and manipulated Google Workspace mail rules to exfiltrate North American research data.
UNC6508: Chinese Cyberespionage Targets North American Research
Google's Threat Intelligence Group tracks UNC6508, a Chinese cyberespionage group targeting North American medical, military, and AI research sectors.
Iranian Handala Group Claims Cal Water Hack, Exposing PII
Iranian cyber group Handala claims responsibility for breaching Cal Water, exposing 5GB of customer PII and RTKBase platform credentials.
OceanLotus Targets Vietnam with SPECTRALVIPER Backdoor in FireAnt Attack
OceanLotus APT targets Vietnamese infrastructure and stock investors with SPECTRALVIPER backdoor in multi-year cyber espionage and supply chain campaigns.
Chinese and North Korean APT Activity Surges Across APAC Markets
Chinese and North Korean threat groups are intensifying operations in Asia-Pacific, impacting regional economies and targeting financial institutions for profit.
Pakistan-Linked Espionage Targets Afghan Finance Ministry via Xeno RAT
Analysis of a Pakistan-linked cyber espionage campaign targeting the Afghan Ministry of Finance using the Xeno RAT malware and malicious LNK files.
China-Linked APTs Target Latin American Critical Infrastructure
China-linked APTs are conducting widespread cyber espionage against maritime shipping, oil production, and government sectors in Latin America, impacting over a dozen…
Iranian APT33 Targets Aviation with Updated MimicC2 and PowerLess
Iranian APT Nimbus Manticore (APT33) targets aviation and software firms using new MimicC2 framework and updated PowerLess tools for stealthy operations.
MuddyWater Targets South Korean Electronics Maker in Espionage Campaign
Iran-linked MuddyWater (Seedworm) group launched a cyber-espionage campaign against a major South Korean electronics maker and other global entities.
PamDOORa Backdoor and Windows Phone Link OTP Theft Analysis
Recent intelligence highlights the PamDOORa Linux backdoor and malware leveraging Windows Phone Link to bypass OTP-based authentication mechanisms.
China-Linked UAT-8302 Targets Governments with Custom APT Malware
UAT-8302, a China-linked threat group, targets government entities in South America and SE Europe using custom malware and shared APT toolsets.
Alleged Silk Typhoon Hacker Extradited: Cyberespionage Threat
An alleged Silk Typhoon hacker, associated with Chinese intelligence, has been extradited to the US, highlighting persistent nation-state cyberespionage threats.
Chinese State-Backed Actors Industrialize Botnets for Covert Ops
Chinese state-backed groups are adopting industrialized botnets, utilizing compromised devices for low-cost, low-risk, and deniable cyber operations.