Tag: apt
-
North Korea’s APT Capabilities Are No Longer State-Exclusive
Tags: access, apt, cyber, finance, group, hacker, infrastructure, korea, lazarus, malware, military, north-korea, ransomware, skillsAhnLab Found Shared Malware, SSH Keys and Infrastructure Across Two Campaigns. Shared malware, infrastructure and access methods link Lazarus Group to Gunra ransomware activity, while former North Korean military hackers allegedly used state-trained skills to steal bank funds, exposing cyber capability diffusion and blowback inside the regime. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/north-koreas-apt-capabilities-are-no-longer-state-exclusive-a-32392
-
BlackTech APT Uses New BlueShell Linux Backdoor in Attacks on Japanese Organizations
BlackTech, a long-running China-aligned APT group, has adopted a new Linux backdoor built on the BlueShell open-source RAT to conduct post-intrusion operations against Japanese organizations, signaling ongoing toolchain evolution and focused targeting of enterprise Linux environments. Originally published on GitHub with Chinese-language documentation, BlueShell has seen limited but consistent abuse by China-based threat actors, including…
-
Insane Castle Hurricane: APT Codename Confusion Proliferates
Google Debuts Yet Another Way to Track State-Sponsored and Cybercrime Actors What do Castle, Ion, Neptune, Relic and Comet have in common? They’re among the codenames Google will begin assigning to threat groups, many of which already have a dozen different codenames assigned to them. In the words of one researcher: There is a massive…
-
Google’s solution to hacker name confusion? Yet another naming system
APT-number conventions are out, cryptonyms are in, and security teams now have one more naming system to keep straight. First seen on cyberscoop.com Jump to article: cyberscoop.com/google-threat-actor-naming-system/
-
Russian APT Laundry Bear perfects zero-click phishing attack
A newly identified Russian state threat actor is using a novel zero-click phishing technique, likely developed with the help of an AI, to target Western users of Zimbra software products First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366645968/Russian-APT-Laundry-Bear-perfects-zero-click-phishing-attack
-
US Agencies Warn of Laundry Bear Campaign Targeting Unpatched Zimbra Servers
Tags: advisory, apt, cybersecurity, email, exploit, flaw, government, group, infrastructure, international, russiaUS agencies warn Russian group Laundry Bear is exploiting a patched Zimbra flaw to steal email accounts from organizations running unpatched servers. The Cybersecurity and Infrastructure Security Agency (CISA), National Security Agency (NSA), Federal Bureau of Investigation (FBI) and other U.S. government and international partners published a joint advisory to warn that the Russia-linked APT…
-
CISA Urges Organizations to Remove Rockwell PLCs From Direct Internet Exposure
CISA and partner agencies are directing U.S. critical infrastructure operators to immediately remove Rockwell and other programmable logic controllers (PLCs) from direct internet exposure and to hunt for Iranian-affiliated APT activity in OT environments aggressively. In a joint advisory first issued on April 7, 2026 and updated on July 22, 2026, the FBI, CISA, NSA,…
-
GoldenEyeDog Subgroup Linked to DigiCert Breach and Code-Signing Certificate Theft
Cybersecurity researchers have attributed the April 2026 DigiCert security incident to a threat activity cluster dubbed CylindricalCanine.Expel, which shared technical details of the event, described the threat actor as a sub-group of GoldenEyeDog (aka APT-Q-27, Dragon Breath, and Miuuti Group), a Chinese cybercrime group known for its targeting of the gambling and gaming sectors using…
-
Spear-Phishing Campaign Uses Proton Drive Links and LNK Files to Deliver SpyGlace
The APT-C-60 threat actor has continued targeting Japanese organizations with a spear-phishing campaign that abuses Proton Drive, Windows shortcut files, trusted developer platforms, and native Windows utilities to deliver the SpyGlace malware. While the group retains several established tradecraft elements, including the abuse of legitimate services and the use of git.exe to execute malicious scripts,…
-
Armored Likho Hits Government, Energy Sectors With BusySnake Stealer
Kaspersky details how the newly named Armored Likho APT uses BusySnake Stealer, AI-generated loaders, and phishing to target government and energy organizations. First seen on hackread.com Jump to article: hackread.com/armored-likho-government-energy-busysnake-stealer/
-
China-Linked APT Expands Proxy Network With New Malware
Cisco Talos said China-linked APT UAT-7810 is growing its proxy relay network with new malware First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/uat-7810-china-apt-orb-proxy/
-
AI-Generated Malware Powers New Armored Likho APT Campaign
Armored Likho APT uses AI-generated malware, phishing, and BusySnake Stealer to target governments and power grids in Russia, Kazakhstan, and Brazil. Kaspersky’s threat research team has documented a previously unknown APT group they’re calling Armored Likho, also tracked under the name Eagle Werewolf. The group runs two parallel tracks: financially motivated attacks against private individuals…
-
Cavern Manticore: Exposing Iran-Linked Modular C2 Framework
ey Points Introduction Since early 2026, Check Point Research (CPR) has tracked a new modular command-and-control framework used by Cavern Manticore, an Iran-nexus APT group primarily targeting Israeli organizations, with a focus on IT providers, and government sectors. Cavern Manticore is an Iran MOIS (Ministry of Intelligence and Security)-linked actor, with links to the OilRig…
-
Armored Likho APT Deploys BusySnake Stealer Against Government and Power Sector Targets
A focused phishing campaign operated by a previously unreported APT we’ve named Armored Likho (also tracked under the provisional alias Eagle Werewolf). The group is targeting government agencies and the electric power sector across Russia, Brazil and Kazakhstan, and demonstrates an evolving toolkit that blends commodity and bespoke tooling to support both financially motivated operations…
-
Neues Spionage-Tool Umbrij kapert Gmail-Sitzungen
Die APT-Gruppe ToddyCat nutzt das neue Tool Umbrij, um über präparierte Browser-Sitzungen unbefugten Zugriff auf Gmail- und Google-Konten zu erlangen. First seen on it-daily.net Jump to article: www.it-daily.net/it-sicherheit/cybercrime/gmail-sitzungen-spionage-tool-umbrij
-
Chinese APT CL1062 targets Southeast Asia with new TinyRCT backdoor
First seen on scworld.com Jump to article: www.scworld.com/brief/chinese-apt-cl-sta-1062-targets-southeast-asia-with-new-tinyrct-backdoor
-
Chinese APT CL1062 Expands Attacks on Southeast Asian Critical Infrastructure With Custom Malware
Chinese-speaking APT CL-STA-1062 targeted Southeast Asian government and energy networks open-source tools, and a new TinyRCT backdoor. Palo Alto Networks Unit 42 researchers published a detailed report on a Chinese-speaking threat actor, tracked as CL-STA-1062, that has been running persistent operations across East Asia since at least March 2022 and shifted focus to Southeast Asian…
-
Chinese-Speaking APT Deploys New TinyRCT Backdoor in Southeast Asia Campaign
A Chinese-speaking advanced persistent threat (APT) actor has been linked to a new custom backdoor called TinyRCT as part of cyber attacks aimed at government entities and critical infrastructure in Southeast Asia.The activity, particularly aimed at state-owned enterprises in the energy and government sectors, has been attributed to a threat actor called CL-STA-1062, which Palo…
-
Russian APT ‘Gamaredon’ Upgrades Its Arsenal, Requiring New Defenses
The FSB state-sponsored operation has gotten a lot better at loading its malware and hiding its servers. First seen on darkreading.com Jump to article: www.darkreading.com/threat-intelligence/russia-apt-gamaredon-arsenal-defense
-
Chinese Cyber Operations Shift From APT Groups to Composite Responsibility Model
Chinese state-linked cyber activity has moved decisively away from the neat, single-actor narratives that dominated early attribution toward an ecosystem model in which responsibility is distributed across military units, intelligence services, private firms, and criminal-style intermediaries. Official advisories characterized some companies as providers of cyber-related products and services to Chinese intelligence; the UK’s NCSC said…
-
APT-Report: Russische Cyberangriffe auf Ukraine eskalieren weiter
Der Bericht ‘Nation-Aligned APTs in 2025″ von TrendAI, dem Cybersecurity-Bereich von Trend Micro, zeichnet ein deutlich verschärftes Bild der globalen Bedrohungslage. First seen on it-daily.net Jump to article: www.it-daily.net/it-sicherheit/cybercrime/apt-russische-cyberangriffe-ukraine
-
Sednit ist wieder da
Tags: aptWie eine der berüchtigtsten APT-Gruppen Russlands wieder auflebt First seen on welivesecurity.com Jump to article: www.welivesecurity.com/de/eset-research/sednit-ist-wieder-da/
-
Ghostwriter APT Uses Fake Gmail Login Panels to Steal Passwords and 2FA Codes
Ghostwriter (UNC1151) has escalated its long-standing phishing operations by deploying convincing fake Gmail login panels that harvest both passwords and two-factor authentication (2FA) codes, CERT Polska reports. The group historically focused on Polish email providers such as Onet, Wirtualna Polska and Interia shifted in March 2026 to high-volume Gmail-targeted campaigns. Attackers send professionally worded Polish-language…
-
OceanLotus: Von der Spionage im Ausland bis hin zu Angriffen im Inland
Tags: aptMit Vietnam verbündete APT-Gruppe verändert ihren modus operandi signifikant. First seen on welivesecurity.com Jump to article: www.welivesecurity.com/de/eset-research/oceanlotus-von-der-spionage-im-ausland-bis-hin-zu-angriffen-im-inland/
-
OceanLotus Targets Stock Investors in FireAnt MetaKit Supply-Chain Hack
OceanLotus APT has executed a precision supply”‘chain operation that implanted its SPECTRALVIPER backdoor into FireAnt MetaKit, a popular Vietnamese market”‘data component. Telemetry collected from mid”‘2024 through early 2026 shows OceanLotus (aka APT32) conducting two distinct campaigns: a long”‘running espionage intrusion against a Vietnamese infrastructure and transport construction company, and a targeted supply”‘chain compromise of FireAnt…
-
OceanLotus Targets Stock Investors in FireAnt MetaKit Supply-Chain Hack
OceanLotus APT has executed a precision supply”‘chain operation that implanted its SPECTRALVIPER backdoor into FireAnt MetaKit, a popular Vietnamese market”‘data component. Telemetry collected from mid”‘2024 through early 2026 shows OceanLotus (aka APT32) conducting two distinct campaigns: a long”‘running espionage intrusion against a Vietnamese infrastructure and transport construction company, and a targeted supply”‘chain compromise of FireAnt…
-
OceanLotus Targets Stock Investors in FireAnt MetaKit Supply-Chain Hack
OceanLotus APT has executed a precision supply”‘chain operation that implanted its SPECTRALVIPER backdoor into FireAnt MetaKit, a popular Vietnamese market”‘data component. Telemetry collected from mid”‘2024 through early 2026 shows OceanLotus (aka APT32) conducting two distinct campaigns: a long”‘running espionage intrusion against a Vietnamese infrastructure and transport construction company, and a targeted supply”‘chain compromise of FireAnt…
-
Chinese APTs have made identity part of the intrusion path
First seen on scworld.com Jump to article: www.scworld.com/perspective/chinese-apts-have-made-identity-part-of-the-intrusion-path
-
Chinese APT deploys new malware to keep access to hacked networks
A Chinese espionage group tracked as UNC5221 has been accessing Microsoft 365 environments using the Brickstorm backdoor and previously undocumented malware named Plenet and AgentPSD. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/chinese-apt-deploys-new-malware-to-keep-access-to-hacked-networks/

