Skip to main content
← All Articles

Tag

#Espionage

45 articles

Advertisement

SilkParasite Espionage Campaign Targets Central Asian Governments
MEDIUM
Threat Intel

SilkParasite Espionage Campaign Targets Central Asian Governments

SilkParasite espionage campaign targets Central Asian governments with seven remote access tools, including five newly documented RAT families.

Runtime Rebel Intel
3 min read · Aug 19, 2026
Suspected Chinese-Speaking Hackers Deploy OctLurk, SilkLurk Backdoors
HIGH
Threat Intel

Suspected Chinese-Speaking Hackers Deploy OctLurk, SilkLurk Backdoors

Ongoing cyberattacks by a suspected Chinese-speaking threat actor target Central Asian governments with OctLurk and SilkLurk backdoors for espionage and data theft.

Runtime Rebel Intel
3 min read · Aug 1, 2026
HIGH
Threat Intel

US Humanoid Robot Ban: Mitigating Chinese Supply Chain Risks

The U.S. ban on foreign-made humanoid robots highlights growing concerns over data exfiltration and national security risks linked to Chinese manufacturing.

Runtime Rebel Intel
4 min read · Jul 29, 2026
AI Agent Espionage Against Thai Ministry of Finance: Hermes YOLO Mode
HIGH
Threat Intel

AI Agent Espionage Against Thai Ministry of Finance: Hermes YOLO Mode

Attackers leveraged the Hermes AI agent in 'YOLO mode' to perform an espionage operation targeting Thailand's Ministry of Finance. Learn TTPs and defense.

Runtime Rebel Intel
5 min read · Jul 28, 2026
HollowGraph Malware Leverages Microsoft 365 Calendar for Stealthy C2
HIGH
Malware

HollowGraph Malware Leverages Microsoft 365 Calendar for Stealthy C2

HollowGraph, a new espionage malware, hides C2 commands and exfiltrates data via legitimate Microsoft 365 calendar events, mimicking normal Graph API traffic.

Runtime Rebel Intel
5 min read · Jul 20, 2026
Balochistan Police Portal Exploited in Multi-Group Espionage Campaign
HIGH
Threat Intel

Balochistan Police Portal Exploited in Multi-Group Espionage Campaign

Multiple threat actors weaponize Balochistan Police infrastructure, compromising criminal records and citizen data in a multi-year espionage operation.

Runtime Rebel Intel
4 min read · Jul 11, 2026

Advertisement

CRITICAL
Threat Intel

Roundcube Flaw Exploited by China-Linked Group Against Academics

A China-linked threat cluster is actively exploiting a Roundcube webmail vulnerability to steal credentials and deploy backdoors at U.S./Canadian universities.

Runtime Rebel Intel
4 min read · Jul 8, 2026
MEDIUM
Threat Intel

Google Disrupts NetNut Malicious Residential Proxy Network

Google, in coordination with the FBI and Lumen, has significantly disrupted the NetNut residential proxy network, impacting millions of compromised devices.

Runtime Rebel Intel
4 min read · Jul 3, 2026
China-Linked APT Targets Southeast Asia Critical Systems with New Backdoor
HIGH
Threat Intel

China-Linked APT Targets Southeast Asia Critical Systems with New Backdoor

A China-linked APT group has compromised ten organizations, including state-owned entities in Southeast Asia, deploying a new backdoor.

Runtime Rebel Intel
4 min read · Jul 1, 2026
Mustang Panda Exploits Zoho WorkDrive for C2 in Indian Govt Attacks
HIGH
Threat Intel

Mustang Panda Exploits Zoho WorkDrive for C2 in Indian Govt Attacks

Mustang Panda, a China-aligned APT, targets Indian government and hydropower entities, leveraging Zoho WorkDrive as a C2 channel and deploying new malware.

Runtime Rebel Intel
4 min read · Jun 29, 2026
HIGH
Threat Intel

UNC5792 & UNC4221 Target US Officials via Messaging Apps

Russian state-linked groups UNC5792 and UNC4221 are actively targeting US government, military, and allied personnel through evolving messaging app attacks.

Runtime Rebel Intel
4 min read · Jun 29, 2026
HIGH
Threat Intel

Turla APT Deploys StockStay Backdoor in Ukraine Espionage Campaign

Russian APT Turla targets Ukrainian government and military entities with the custom StockStay backdoor for persistent access and cyber espionage.

Runtime Rebel Intel
4 min read · Jun 26, 2026
Turla Deploys New STOCKSTAY Backdoor in Ukraine Espionage Operations
HIGH
Threat Intel

Turla Deploys New STOCKSTAY Backdoor in Ukraine Espionage Operations

Google identifies STOCKSTAY, a new .NET backdoor by Russian actor Turla targeting Ukrainian military and Italian foreign policy interests via Windows systems.

Runtime Rebel Intel
4 min read · Jun 26, 2026
HIGH
Threat Intel

UNC6508 Targets REDCap Servers: Espionage via INFINITERED Malware

PRC-nexus threat actor UNC6508 exploits REDCap servers in North America's medical and military research sectors, deploying INFINITERED malware for long-term espionage…

Runtime Rebel Intel
6 min read · Jun 15, 2026
China-Nexus Actor: Year-Long Espionage Against US Researchers
HIGH
Threat Intel

China-Nexus Actor: Year-Long Espionage Against US Researchers

A China-nexus actor spied on US researchers for a year, stealing RedCAP credentials and exfiltrating sensitive data from numerous institutions, discovered by Google.

Runtime Rebel Intel
4 min read · Jun 15, 2026
HIGH
Threat Intel

China-Linked Espionage Targets REDCap Servers, Stealing Medical Data

China-linked threat actors breached exposed REDCap servers, deploying InfiniteRed malware to steal sensitive medical research from a North American institution.

Runtime Rebel Intel
5 min read · Jun 15, 2026
HIGH
Threat Intel

Chinese Hackers Hijack Auth Flow for Decade-Long Espionage

Chinese state-sponsored hackers maintained long-term access to an isolated network by hijacking the authentication flow, enabling a decade of espionage.

Runtime Rebel Intel
5 min read · Jun 13, 2026
HIGH
Threat Intel

Chinese APT UNC5221 Deploys New Malware for M365 Persistence

Chinese APT UNC5221 leverages new malware, Plenet and AgentPSD, alongside Brickstorm backdoor to maintain persistent access in compromised Microsoft 365 environments for…

Runtime Rebel Intel
5 min read · Jun 5, 2026
OP-512: Analyzing the Custom Web Shell Framework Targeting Microsoft IIS
HIGH
Threat Intel

OP-512: Analyzing the Custom Web Shell Framework Targeting Microsoft IIS

Security researchers have identified OP-512, a China-nexus threat cluster targeting Microsoft IIS servers with a bespoke web shell framework for espionage.

Runtime Rebel Intel
4 min read · Jun 5, 2026
Handala Brand Evolution: Iran MOIS Shifts to Hybrid Physical Attacks
MEDIUM
Threat Intel

Handala Brand Evolution: Iran MOIS Shifts to Hybrid Physical Attacks

Iran’s MOIS expands the Handala brand into hybrid operations, combining cyber espionage with physical sabotage targeting U.S. and Israeli interests.

Runtime Rebel Intel
3 min read · Jun 2, 2026
MuddyWater 2026 Espionage: DLL Side-Loading Across 9 Countries
HIGH
Threat Intel

MuddyWater 2026 Espionage: DLL Side-Loading Across 9 Countries

Iranian group MuddyWater targets industrial manufacturing and financial sectors in a global 2026 espionage campaign using DLL side-loading techniques.

Runtime Rebel Intel
4 min read · May 26, 2026
FrostyNeighbor APT Targets Poland/Ukraine Gov with Spear-Phishing
HIGH
Threat Intel

FrostyNeighbor APT Targets Poland/Ukraine Gov with Spear-Phishing

Belarussian APT 'FrostyNeighbor' is deploying spear-phishing campaigns against Polish and Ukrainian government entities after unique victim fingerprinting, aiming for…

Runtime Rebel Intel
4 min read · May 14, 2026
HIGH
Threat Intel

YoroTrooper Campaign Hits 500+ Orgs: Espionage and Malware Tactics

Analysis of the multi-year YoroTrooper phishing campaign targeting critical infrastructure, aviation, and government sectors with custom malware stealers.

Runtime Rebel Intel
4 min read · May 11, 2026
SHADOW-EARTH-053: China-Linked APT Targets NATO and Asian Governments
HIGH
Threat Intel

SHADOW-EARTH-053: China-Linked APT Targets NATO and Asian Governments

Trend Micro uncovers SHADOW-EARTH-053, a China-aligned espionage group targeting defense sectors in Asia and a NATO member through advanced TTPs.

Runtime Rebel Intel
3 min read · May 1, 2026