Tag: apt
-
Chinese APT Clones Legitimate Websites to Deliver Chrome and Windows Zero-Day Exploits
A third Chinese threat actor has been linked to phishing campaigns that cloned trusted websites and chained Chrome and Windows zero-day exploits to deploy a previously undocumented backdoor. The activity occurred on September 3 and 4, 2026, while the targeted vulnerabilities remained unpatched in Google Chrome. It followed Volexity’s September 9 disclosure that UTA0560 and…
-
NightEagle Uses BlueKeep and DCSync to Move Toward Active Directory Domain Controllers
NightEagle, an espionage-focused threat group also tracked as APT-Q-95, has expanded its operations from Asian targets to Russian organizations, using a layered intrusion chain that culminates in attempts to compromise Active Directory domain controllers. The campaign illustrates a familiar but dangerous enterprise compromise pattern: attackers do not need a novel zero-day exploit when exposed remote…
-
China’s FamousSparrow APT Spies on US Politics in Latin America
Amid the US and China’s fight for eco-colonial influence in Latin America, a stealthy backdoor has taken flight. First seen on darkreading.com Jump to article: www.darkreading.com/cyberattacks-data-breaches/china-famoussparrow-spies-latin-america
-
NightEagle Hackers Abuse Microsoft Dev Tunnels and GhostContainer to Breach Russian Companies
The NightEagle advanced persistent threat group, tracked as APT-Q-95, has expanded its operations to target businesses in Russia, combining stolen VPN credentials, a stealthy Microsoft Exchange backdoor, and legitimate tunneling technologies to move through victim networks. Researchers from Kaspersky’s Global Emergency Response Team said the group has been active since at least 2023 and previously…
-
NightEagle Hackers Target Russian Companies Using GhostContainer Backdoor
The NightEagle advanced persistent threat group, tracked as APT-Q-95, has expanded its operations to target businesses in Russia, combining stolen VPN credentials, a stealthy Microsoft Exchange backdoor, and legitimate tunneling technologies to move through victim networks. Researchers from Kaspersky’s Global Emergency Response Team said the group has been active since at least 2023 and previously…
-
Three Threat Groups Target Russian Enterprises With Backdoors, Ransomware, and Wipers
Enterprises in Russia have emerged as the target of three threat activity clusters tracked as NightEagle, Hacking Cat, and Toy Ghouls, according to multiple reports from Kaspersky.The cybersecurity vendor said it has identified attacks mounted by NightEagle (aka APT-Q-95), a threat actor known to be active since at least 2023, that involve new techniques for…
-
Pentest bestanden und trotzdem gehackt: Wo Red Teaming und APT Simulationen mehr bieten
Die Firma hat den Pentest bestanden, wurde aber trotzdem gehackt? Erfahre, warum Red Teaming und APT-Simulationen die IT-Abwehr verbessern. First seen on tarnkappe.info Jump to article: tarnkappe.info/artikel/gast-artikel/pentest-bestanden-und-trotzdem-gehackt-wo-red-teaming-und-apt-simulationen-mehr-bieten-333471.html
-
Cisco FMC Flaws Give Ransomware and APTs a Path Into Internal Networks
Cisco Talos says attackers are exploiting FMC flaws to steal credentials, tunnel into internal networks, and deploy Qilin ransomware. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/news-cisco-fmc-vulnerabilities/
-
SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 114
Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Malware Newsletter REVSTEALER ramps up Breaking the Seal: Static Deobfuscation of JSCeal’s Compiled V8 Bytecode GuardBreaker: Derailing AI-assisted malware analysis with a code comment DPRK APTs: Ted backdoor and curlRAT target South Korean media and automotive…
-
Iran-linked APT Mirage Kitten Uses Fake Job Tests to Spread Malware
Mirage Kitten used fake LinkedIn coding tests to spread NodeRabbit and PollCat, even banning AI tools that could have spotted the malware. Iran-linked Mirage Kitten hackers just found a genuinely clever way to make their own malware harder to detect: telling job candidates not to use AI tools while reviewing the trojanized code they were…
-
Russian APT BlueDelta Uses HOOKEDGE to Target Defense and Diplomatic Organizations
BlueDelta (APT28) uses webhook.site and Microsoft Edge to hide HOOKEDGE espionage traffic targeting European governments. Recorded Future’s Insikt Group documented a campaign by BlueDelta, the Russian GRU-linked group that overlaps with the group APT28, running an entire espionage operation against European government targets using webhook.site, a service built for developers to test HTTP requests, as…
-
Nimbus Manticore Expands Toolset With TWOSTROKE-Like Backdoor and SSH Tunneler
Cybersecurity researchers have discovered additional infrastructure and previously undocumented malware associated with Nimbus Manticore, an Iranian state-sponsored hacking group affiliated with the Islamic Revolutionary Guard Corps (IRGC).Group-IB, in a new analysis published today, described the cyber espionage actor as among the most active Iranian APT groups in 2026. Nimbus Manticore (aka First seen on thehackernews.com…
-
Head Mare APT Exploits TrueConf Server RCE Flaws to Deliver PhantomCore Malware
Tags: access, apt, attack, conference, cyber, exploit, flaw, group, kaspersky, malware, rce, remote-code-execution, russia, supply-chainThe Head Mare APT group has been linked to a supply chain compromise involving unpatched TrueConf Server instances, which enabled the delivery of PhantomCore malware to video conference participants. Kaspersky researchers identified this activity while investigating attacks against Russian organizations. Attackers hosted legitimate-looking TrueConf client installers on compromised servers that silently deployed the remote-access malware…
-
Head Mare APT Exploits TrueConf Server RCE Flaws to Deliver PhantomCore Malware
Tags: access, apt, attack, conference, cyber, exploit, flaw, group, kaspersky, malware, rce, remote-code-execution, russia, supply-chainThe Head Mare APT group has been linked to a supply chain compromise involving unpatched TrueConf Server instances, which enabled the delivery of PhantomCore malware to video conference participants. Kaspersky researchers identified this activity while investigating attacks against Russian organizations. Attackers hosted legitimate-looking TrueConf client installers on compromised servers that silently deployed the remote-access malware…
-
SilkParasite: Tracking a China-Nexus APT Across Central Asia
<div cla TL;DR: SilkParasite is a cyberespionage operation, assessed at medium confidence as China-nexus, that targeted government bodies across Central Asia. Bitdefender Labs found seven remote access tool (RAT) families in use, five of which were previously undocumented; we identified and named them: DriveSilkRAT, CookiETagRAT, NomadRAT, GoginRAT, and NodeEdgeRAT. The toolset is small, modular, and…
-
China-Linked APT Uses AI to Optimize Hand-Built Malware
SilkParasite Deployed Against Central Asian Governments. Bitdefender said the China-linked SilkParasite espionage campaign deployed seven modular RATs against Central Asian governments, with coding artifacts indicating AI assisted expert developers rather than generating the stealth-focused malware itself. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/china-linked-apt-uses-ai-to-optimize-hand-built-malware-a-32597
-
North Korea’s APT Capabilities Are No Longer State-Exclusive
Tags: access, apt, cyber, finance, group, hacker, infrastructure, korea, lazarus, malware, military, north-korea, ransomware, skillsAhnLab Found Shared Malware, SSH Keys and Infrastructure Across Two Campaigns. Shared malware, infrastructure and access methods link Lazarus Group to Gunra ransomware activity, while former North Korean military hackers allegedly used state-trained skills to steal bank funds, exposing cyber capability diffusion and blowback inside the regime. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/north-koreas-apt-capabilities-are-no-longer-state-exclusive-a-32392
-
BlackTech APT Uses New BlueShell Linux Backdoor in Attacks on Japanese Organizations
BlackTech, a long-running China-aligned APT group, has adopted a new Linux backdoor built on the BlueShell open-source RAT to conduct post-intrusion operations against Japanese organizations, signaling ongoing toolchain evolution and focused targeting of enterprise Linux environments. Originally published on GitHub with Chinese-language documentation, BlueShell has seen limited but consistent abuse by China-based threat actors, including…
-
Insane Castle Hurricane: APT Codename Confusion Proliferates
Google Debuts Yet Another Way to Track State-Sponsored and Cybercrime Actors What do Castle, Ion, Neptune, Relic and Comet have in common? They’re among the codenames Google will begin assigning to threat groups, many of which already have a dozen different codenames assigned to them. In the words of one researcher: There is a massive…
-
Google’s solution to hacker name confusion? Yet another naming system
APT-number conventions are out, cryptonyms are in, and security teams now have one more naming system to keep straight. First seen on cyberscoop.com Jump to article: cyberscoop.com/google-threat-actor-naming-system/
-
Russian APT Laundry Bear perfects zero-click phishing attack
A newly identified Russian state threat actor is using a novel zero-click phishing technique, likely developed with the help of an AI, to target Western users of Zimbra software products First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366645968/Russian-APT-Laundry-Bear-perfects-zero-click-phishing-attack
-
US Agencies Warn of Laundry Bear Campaign Targeting Unpatched Zimbra Servers
Tags: advisory, apt, cybersecurity, email, exploit, flaw, government, group, infrastructure, international, russiaUS agencies warn Russian group Laundry Bear is exploiting a patched Zimbra flaw to steal email accounts from organizations running unpatched servers. The Cybersecurity and Infrastructure Security Agency (CISA), National Security Agency (NSA), Federal Bureau of Investigation (FBI) and other U.S. government and international partners published a joint advisory to warn that the Russia-linked APT…
-
CISA Urges Organizations to Remove Rockwell PLCs From Direct Internet Exposure
CISA and partner agencies are directing U.S. critical infrastructure operators to immediately remove Rockwell and other programmable logic controllers (PLCs) from direct internet exposure and to hunt for Iranian-affiliated APT activity in OT environments aggressively. In a joint advisory first issued on April 7, 2026 and updated on July 22, 2026, the FBI, CISA, NSA,…
-
GoldenEyeDog Subgroup Linked to DigiCert Breach and Code-Signing Certificate Theft
Cybersecurity researchers have attributed the April 2026 DigiCert security incident to a threat activity cluster dubbed CylindricalCanine.Expel, which shared technical details of the event, described the threat actor as a sub-group of GoldenEyeDog (aka APT-Q-27, Dragon Breath, and Miuuti Group), a Chinese cybercrime group known for its targeting of the gambling and gaming sectors using…
-
Spear-Phishing Campaign Uses Proton Drive Links and LNK Files to Deliver SpyGlace
The APT-C-60 threat actor has continued targeting Japanese organizations with a spear-phishing campaign that abuses Proton Drive, Windows shortcut files, trusted developer platforms, and native Windows utilities to deliver the SpyGlace malware. While the group retains several established tradecraft elements, including the abuse of legitimate services and the use of git.exe to execute malicious scripts,…
-
Armored Likho Hits Government, Energy Sectors With BusySnake Stealer
Kaspersky details how the newly named Armored Likho APT uses BusySnake Stealer, AI-generated loaders, and phishing to target government and energy organizations. First seen on hackread.com Jump to article: hackread.com/armored-likho-government-energy-busysnake-stealer/
-
China-Linked APT Expands Proxy Network With New Malware
Cisco Talos said China-linked APT UAT-7810 is growing its proxy relay network with new malware First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/uat-7810-china-apt-orb-proxy/
-
AI-Generated Malware Powers New Armored Likho APT Campaign
Armored Likho APT uses AI-generated malware, phishing, and BusySnake Stealer to target governments and power grids in Russia, Kazakhstan, and Brazil. Kaspersky’s threat research team has documented a previously unknown APT group they’re calling Armored Likho, also tracked under the name Eagle Werewolf. The group runs two parallel tracks: financially motivated attacks against private individuals…
-
Cavern Manticore: Exposing Iran-Linked Modular C2 Framework
ey Points Introduction Since early 2026, Check Point Research (CPR) has tracked a new modular command-and-control framework used by Cavern Manticore, an Iran-nexus APT group primarily targeting Israeli organizations, with a focus on IT providers, and government sectors. Cavern Manticore is an Iran MOIS (Ministry of Intelligence and Security)-linked actor, with links to the OilRig…

