Advertisement
SilkParasite Espionage Campaign Targets Central Asian Governments
SilkParasite espionage campaign targets Central Asian governments with seven remote access tools, including five newly documented RAT families.
Suspected Chinese-Speaking Hackers Deploy OctLurk, SilkLurk Backdoors
Ongoing cyberattacks by a suspected Chinese-speaking threat actor target Central Asian governments with OctLurk and SilkLurk backdoors for espionage and data theft.
US Humanoid Robot Ban: Mitigating Chinese Supply Chain Risks
The U.S. ban on foreign-made humanoid robots highlights growing concerns over data exfiltration and national security risks linked to Chinese manufacturing.
AI Agent Espionage Against Thai Ministry of Finance: Hermes YOLO Mode
Attackers leveraged the Hermes AI agent in 'YOLO mode' to perform an espionage operation targeting Thailand's Ministry of Finance. Learn TTPs and defense.
HollowGraph Malware Leverages Microsoft 365 Calendar for Stealthy C2
HollowGraph, a new espionage malware, hides C2 commands and exfiltrates data via legitimate Microsoft 365 calendar events, mimicking normal Graph API traffic.
Balochistan Police Portal Exploited in Multi-Group Espionage Campaign
Multiple threat actors weaponize Balochistan Police infrastructure, compromising criminal records and citizen data in a multi-year espionage operation.
Advertisement
Roundcube Flaw Exploited by China-Linked Group Against Academics
A China-linked threat cluster is actively exploiting a Roundcube webmail vulnerability to steal credentials and deploy backdoors at U.S./Canadian universities.
Google Disrupts NetNut Malicious Residential Proxy Network
Google, in coordination with the FBI and Lumen, has significantly disrupted the NetNut residential proxy network, impacting millions of compromised devices.
China-Linked APT Targets Southeast Asia Critical Systems with New Backdoor
A China-linked APT group has compromised ten organizations, including state-owned entities in Southeast Asia, deploying a new backdoor.
Mustang Panda Exploits Zoho WorkDrive for C2 in Indian Govt Attacks
Mustang Panda, a China-aligned APT, targets Indian government and hydropower entities, leveraging Zoho WorkDrive as a C2 channel and deploying new malware.
UNC5792 & UNC4221 Target US Officials via Messaging Apps
Russian state-linked groups UNC5792 and UNC4221 are actively targeting US government, military, and allied personnel through evolving messaging app attacks.
Turla APT Deploys StockStay Backdoor in Ukraine Espionage Campaign
Russian APT Turla targets Ukrainian government and military entities with the custom StockStay backdoor for persistent access and cyber espionage.
Turla Deploys New STOCKSTAY Backdoor in Ukraine Espionage Operations
Google identifies STOCKSTAY, a new .NET backdoor by Russian actor Turla targeting Ukrainian military and Italian foreign policy interests via Windows systems.
UNC6508 Targets REDCap Servers: Espionage via INFINITERED Malware
PRC-nexus threat actor UNC6508 exploits REDCap servers in North America's medical and military research sectors, deploying INFINITERED malware for long-term espionage…
China-Nexus Actor: Year-Long Espionage Against US Researchers
A China-nexus actor spied on US researchers for a year, stealing RedCAP credentials and exfiltrating sensitive data from numerous institutions, discovered by Google.
China-Linked Espionage Targets REDCap Servers, Stealing Medical Data
China-linked threat actors breached exposed REDCap servers, deploying InfiniteRed malware to steal sensitive medical research from a North American institution.
Chinese Hackers Hijack Auth Flow for Decade-Long Espionage
Chinese state-sponsored hackers maintained long-term access to an isolated network by hijacking the authentication flow, enabling a decade of espionage.
Chinese APT UNC5221 Deploys New Malware for M365 Persistence
Chinese APT UNC5221 leverages new malware, Plenet and AgentPSD, alongside Brickstorm backdoor to maintain persistent access in compromised Microsoft 365 environments for…
OP-512: Analyzing the Custom Web Shell Framework Targeting Microsoft IIS
Security researchers have identified OP-512, a China-nexus threat cluster targeting Microsoft IIS servers with a bespoke web shell framework for espionage.
Handala Brand Evolution: Iran MOIS Shifts to Hybrid Physical Attacks
Iran’s MOIS expands the Handala brand into hybrid operations, combining cyber espionage with physical sabotage targeting U.S. and Israeli interests.
MuddyWater 2026 Espionage: DLL Side-Loading Across 9 Countries
Iranian group MuddyWater targets industrial manufacturing and financial sectors in a global 2026 espionage campaign using DLL side-loading techniques.
FrostyNeighbor APT Targets Poland/Ukraine Gov with Spear-Phishing
Belarussian APT 'FrostyNeighbor' is deploying spear-phishing campaigns against Polish and Ukrainian government entities after unique victim fingerprinting, aiming for…
YoroTrooper Campaign Hits 500+ Orgs: Espionage and Malware Tactics
Analysis of the multi-year YoroTrooper phishing campaign targeting critical infrastructure, aviation, and government sectors with custom malware stealers.
SHADOW-EARTH-053: China-Linked APT Targets NATO and Asian Governments
Trend Micro uncovers SHADOW-EARTH-053, a China-aligned espionage group targeting defense sectors in Asia and a NATO member through advanced TTPs.