Advertisement
Tropic Trooper APT Targets Home Routers and Japanese Infrastructure
Tropic Trooper expands operations to target Japanese entities and home routers using specialized malware like Chinoiserie to obfuscate attack origins.
Chinese APT Leverages PlugX & ShadowPad with Cloud C2 for Mongolian Espionage
A Chinese state-sponsored APT is exploiting Microsoft Outlook, Slack, Discord, and file.io for C2, deploying PlugX and ShadowPad in espionage operations targeting…
Mustang Panda Targets Indian Banks with New LOTUSLITE Variant
Mustang Panda deploys a new LOTUSLITE malware variant against Indian financial institutions and South Korean policy entities for cyber espionage operations.
Russian Hackers Exploit Routers to Steal Microsoft Office Tokens
Russian military intelligence-linked hackers exploited known router flaws to harvest Microsoft Office authentication tokens from over 18,000 networks, posing a…
BRICKSTORM Malware: Hardening vSphere & VCSA Against Advanced Threats
Defend VMware vSphere and VCSA against BRICKSTORM malware. Learn hardening strategies, identity management, Zero Trust networking, and advanced logging to thwart…
Iranian-Linked Handala Group Breaches Kash Patel's Personal Email
FBI confirms Iranian-linked Handala hackers breached Director nominee Kash Patel's personal email, leaking documents and highlighting spear-phishing risks.
Advertisement
Red Menshen APT Deploys Upgraded BPFdoor Backdoor Against Telcos
Chinese APT Red Menshen utilizes an upgraded BPFdoor backdoor to target global telecommunication companies, bypassing traditional defenses.
Red Menshen BPFDoor Implants Target Telecom Networks for Espionage
Analysis of China-linked Red Menshen's long-term campaign using stealthy BPFDoor implants within telecom networks to conduct espionage against government entities.
M-Trends 2026: Evolving Ransomware, Persistence, and SaaS Attack Vectors
M-Trends 2026 reveals critical shifts in adversary TTPs: destructive ransomware, zero-day exploitation for persistence, and voice phishing for SaaS access.
DarkSword iPhone Exploit Kit: Zero-Day Attacks on iOS Users
DarkSword, an advanced iPhone exploit kit, leverages multiple zero-day vulnerabilities to target users in Saudi Arabia, Turkey, Malaysia, and Ukraine for espionage and…
Chinese Nexus Actors Pivot to Qatar: Geopolitical Espionage
Analysis of Chinese Nexus actors' shift to targeting Qatari entities amid Iranian conflict. Understand their adaptable TTPs and fortify defenses.
Chinese Cyber Threat: Persistent Espionage in Critical Asian Sectors
An undefined Chinese-speaking actor conducts long-term cyber espionage against critical Asian sectors using custom malware and living-off-the-land binaries.
Coruna iOS Exploit Kit: Spyware-Grade Threat Targets Crypto
The sophisticated Coruna iOS exploit kit, leveraging 23 undocumented vulnerabilities, is now deployed in targeted espionage and crypto theft attacks.
Chinese Cyberspies Exploit SaaS APIs in Global Espionage Campaign
A suspected Chinese threat actor breached dozens of telecom firms and government agencies, using SaaS API calls to evade detection in a global espionage campaign.
Google Disrupts UNC2814 GRIDTIDE Infrastructure After 53 Breaches
Google disrupts infrastructure of China-nexus threat actor UNC2814 (GRIDTIDE) after 53 breaches across 42 countries targeting government and telecom sectors.
Ex-L3Harris Executive Sentenced for Selling Zero-Days to Russia
Former Trenchant CEO James Michael Robinson sentenced to 90 months for stealing zero-day exploits and selling them to a Russian state-linked broker.
L3Harris Insider Sentenced for Selling Zero-Days to Russian Broker
Former defense contractor Peter Williams sentenced to seven years for selling eight zero-day exploits to Russian broker Operation Zero for millions in profit.
UAC-0050 Targets European Financial Institutions with RMS Malware
Russia-aligned actor UAC-0050 expands operations beyond Ukraine, targeting European financial entities with spoofed domains and RMS malware for espionage.
UnsolicitedBooker Targets Central Asian Telecoms via LuciDoor Backdoor
The UnsolicitedBooker threat actor has pivoted to targeting telecommunications providers in Kyrgyzstan and Tajikistan using LuciDoor and MarsSnake backdoors.
APT28 Operation MacroMaze: Webhook-Driven Macro Execution Targeting Western Europe
Analysis of a targeted campaign attributed to APT28, utilizing macro-enabled documents and legitimate webhook services for command-and-control obfuscation.
Iranian APT MuddyWater Orchestrates Operation Olalampo Targeting MENA Infrastructure
Analysis of a new Iranian cyber-espionage campaign utilizing GhostFetch, CHAR, and HTTP_VIP malware families against organizations in the Middle East and North Africa.