Skip to main content
← All Articles

Tag

#Espionage

45 articles

Advertisement

Tropic Trooper APT Targets Home Routers and Japanese Infrastructure
MEDIUM
Threat Intel

Tropic Trooper APT Targets Home Routers and Japanese Infrastructure

Tropic Trooper expands operations to target Japanese entities and home routers using specialized malware like Chinoiserie to obfuscate attack origins.

Runtime Rebel Intel
3 min read · Apr 24, 2026
Chinese APT Leverages PlugX & ShadowPad with Cloud C2 for Mongolian Espionage
HIGH
Threat Intel

Chinese APT Leverages PlugX & ShadowPad with Cloud C2 for Mongolian Espionage

A Chinese state-sponsored APT is exploiting Microsoft Outlook, Slack, Discord, and file.io for C2, deploying PlugX and ShadowPad in espionage operations targeting…

Runtime Rebel Intel
4 min read · Apr 23, 2026
Mustang Panda Targets Indian Banks with New LOTUSLITE Variant
HIGH
Threat Intel

Mustang Panda Targets Indian Banks with New LOTUSLITE Variant

Mustang Panda deploys a new LOTUSLITE malware variant against Indian financial institutions and South Korean policy entities for cyber espionage operations.

Runtime Rebel Intel
3 min read · Apr 22, 2026
HIGH
Threat Intel

Russian Hackers Exploit Routers to Steal Microsoft Office Tokens

Russian military intelligence-linked hackers exploited known router flaws to harvest Microsoft Office authentication tokens from over 18,000 networks, posing a…

Runtime Rebel Intel
5 min read · Apr 7, 2026
HIGH
Threat Intel

BRICKSTORM Malware: Hardening vSphere & VCSA Against Advanced Threats

Defend VMware vSphere and VCSA against BRICKSTORM malware. Learn hardening strategies, identity management, Zero Trust networking, and advanced logging to thwart…

Runtime Rebel Intel
9 min read · Apr 2, 2026
HIGH
Threat Intel

Iranian-Linked Handala Group Breaches Kash Patel's Personal Email

FBI confirms Iranian-linked Handala hackers breached Director nominee Kash Patel's personal email, leaking documents and highlighting spear-phishing risks.

Runtime Rebel Intel
3 min read · Mar 30, 2026

Advertisement

Red Menshen APT Deploys Upgraded BPFdoor Backdoor Against Telcos
HIGH
Threat Intel

Red Menshen APT Deploys Upgraded BPFdoor Backdoor Against Telcos

Chinese APT Red Menshen utilizes an upgraded BPFdoor backdoor to target global telecommunication companies, bypassing traditional defenses.

Runtime Rebel Intel
4 min read · Mar 27, 2026
Red Menshen BPFDoor Implants Target Telecom Networks for Espionage
HIGH
Threat Intel

Red Menshen BPFDoor Implants Target Telecom Networks for Espionage

Analysis of China-linked Red Menshen's long-term campaign using stealthy BPFDoor implants within telecom networks to conduct espionage against government entities.

Runtime Rebel Intel
4 min read · Mar 26, 2026
HIGH
Threat Intel

M-Trends 2026: Evolving Ransomware, Persistence, and SaaS Attack Vectors

M-Trends 2026 reveals critical shifts in adversary TTPs: destructive ransomware, zero-day exploitation for persistence, and voice phishing for SaaS access.

Runtime Rebel Intel
5 min read · Mar 23, 2026
DarkSword iPhone Exploit Kit: Zero-Day Attacks on iOS Users
HIGH
Threat Intel

DarkSword iPhone Exploit Kit: Zero-Day Attacks on iOS Users

DarkSword, an advanced iPhone exploit kit, leverages multiple zero-day vulnerabilities to target users in Saudi Arabia, Turkey, Malaysia, and Ukraine for espionage and…

Runtime Rebel Intel
4 min read · Mar 19, 2026
Chinese Nexus Actors Pivot to Qatar: Geopolitical Espionage
HIGH
Threat Intel

Chinese Nexus Actors Pivot to Qatar: Geopolitical Espionage

Analysis of Chinese Nexus actors' shift to targeting Qatari entities amid Iranian conflict. Understand their adaptable TTPs and fortify defenses.

Runtime Rebel Intel
5 min read · Mar 11, 2026
Chinese Cyber Threat: Persistent Espionage in Critical Asian Sectors
HIGH
Threat Intel

Chinese Cyber Threat: Persistent Espionage in Critical Asian Sectors

An undefined Chinese-speaking actor conducts long-term cyber espionage against critical Asian sectors using custom malware and living-off-the-land binaries.

Runtime Rebel Intel
4 min read · Mar 9, 2026
HIGH
Malware

Coruna iOS Exploit Kit: Spyware-Grade Threat Targets Crypto

The sophisticated Coruna iOS exploit kit, leveraging 23 undocumented vulnerabilities, is now deployed in targeted espionage and crypto theft attacks.

Runtime Rebel Intel
5 min read · Mar 4, 2026
HIGH
Threat Intel

Chinese Cyberspies Exploit SaaS APIs in Global Espionage Campaign

A suspected Chinese threat actor breached dozens of telecom firms and government agencies, using SaaS API calls to evade detection in a global espionage campaign.

Runtime Rebel Intel
5 min read · Feb 25, 2026
Google Disrupts UNC2814 GRIDTIDE Infrastructure After 53 Breaches
MEDIUM
Threat Intel

Google Disrupts UNC2814 GRIDTIDE Infrastructure After 53 Breaches

Google disrupts infrastructure of China-nexus threat actor UNC2814 (GRIDTIDE) after 53 breaches across 42 countries targeting government and telecom sectors.

Runtime Rebel Intel
3 min read · Feb 25, 2026
HIGH
Threat Intel

Ex-L3Harris Executive Sentenced for Selling Zero-Days to Russia

Former Trenchant CEO James Michael Robinson sentenced to 90 months for stealing zero-day exploits and selling them to a Russian state-linked broker.

Runtime Rebel Intel
4 min read · Feb 25, 2026
L3Harris Insider Sentenced for Selling Zero-Days to Russian Broker
HIGH
Threat Intel

L3Harris Insider Sentenced for Selling Zero-Days to Russian Broker

Former defense contractor Peter Williams sentenced to seven years for selling eight zero-day exploits to Russian broker Operation Zero for millions in profit.

Runtime Rebel Intel
4 min read · Feb 25, 2026
UAC-0050 Targets European Financial Institutions with RMS Malware
MEDIUM
Threat Intel

UAC-0050 Targets European Financial Institutions with RMS Malware

Russia-aligned actor UAC-0050 expands operations beyond Ukraine, targeting European financial entities with spoofed domains and RMS malware for espionage.

Runtime Rebel Intel
4 min read · Feb 25, 2026
UnsolicitedBooker Targets Central Asian Telecoms via LuciDoor Backdoor
HIGH
Threat Intel

UnsolicitedBooker Targets Central Asian Telecoms via LuciDoor Backdoor

The UnsolicitedBooker threat actor has pivoted to targeting telecommunications providers in Kyrgyzstan and Tajikistan using LuciDoor and MarsSnake backdoors.

Runtime Rebel Intel
4 min read · Feb 24, 2026
APT28 Operation MacroMaze: Webhook-Driven Macro Execution Targeting Western Europe
MEDIUM
Threat Intel

APT28 Operation MacroMaze: Webhook-Driven Macro Execution Targeting Western Europe

Analysis of a targeted campaign attributed to APT28, utilizing macro-enabled documents and legitimate webhook services for command-and-control obfuscation.

Runtime Rebel Intel
3 min read · Feb 24, 2026
Iranian APT MuddyWater Orchestrates Operation Olalampo Targeting MENA Infrastructure
HIGH
Threat Intel

Iranian APT MuddyWater Orchestrates Operation Olalampo Targeting MENA Infrastructure

Analysis of a new Iranian cyber-espionage campaign utilizing GhostFetch, CHAR, and HTTP_VIP malware families against organizations in the Middle East and North Africa.

Runtime Rebel Intel
2 min read · Feb 23, 2026