Tag: cyberespionage
-
Chinese Hackers Use AI Agents in Multi-Country Cyber Campaign
Tags: ai, china, country, cyber, cyberattack, cyberespionage, government, hacker, intelligence, threatHunt.io uncovered a Chinese-speaking campaign using AI agents to automate cyberattacks against Asian government, education and industrial targets. Threat intelligence firm Hunt.io just documented a second, separate China-linked campaign wiring commercial AI models directly into live cyberespionage operations, this time hitting Taiwan’s Kuomintang Party archives, Indonesia’s Ministry of Foreign Affairs, government and education systems in…
-
Arctic Wolf Labs entdeckt neues Malware-Framework <>
Ein neues Malware-Framework in zwei unterschiedlich umfangreichen Ausführungen und ein Ausweichmechanismus über die Ethereum-Blockchain: Arctic Wolf Labs hat bei der Untersuchung eines gezielten Angriffs auf eine Organisation aus dem Kommunikationssektor in Venezuela die bislang nicht dokumentierte Malware <> entdeckt. Arctic Wolf ordnet den Angriff mit mittlerer Sicherheit der Cyberspionage-Gruppe Dark Caracal zu. Die wichtigsten Erkenntnisse…
-
Cyberspionage-Kampagne SilkParasite gegen Regierungen in Zentralasien
Tags: cyberespionageBitdefender hat mit SilkParasite eine rund ein Jahr laufende Cyberspionage-Kampagne aufgedeckt, die gezielt Regierungsstellen in Zentralasien angriff. First seen on it-daily.net Jump to article: www.it-daily.net/it-sicherheit/cybercrime/cyberspionage
-
SilkParasite Uses Google Drive as C2 to Hide RAT Traffic Inside Trusted Cloud Services
SilkParasite, a long-running cyberespionage operation targeting government bodies across Central Asia through a compact but highly mature arsenal of remote access trojans. Assessed with medium confidence as China-nexus activity, the campaign stands out for using Google Drive as a command-and-control channel, allowing malware traffic to blend into cloud activity that many enterprises inherently trust. The…
-
SilkParasite: Tracking a China-Nexus APT Across Central Asia
<div cla TL;DR: SilkParasite is a cyberespionage operation, assessed at medium confidence as China-nexus, that targeted government bodies across Central Asia. Bitdefender Labs found seven remote access tool (RAT) families in use, five of which were previously undocumented; we identified and named them: DriveSilkRAT, CookiETagRAT, NomadRAT, GoginRAT, and NodeEdgeRAT. The toolset is small, modular, and…
-
‘Living Off the Plant’ OT Attacks Pose Physical Safety Risk
Beware Abuse of Native OT Functionality, Says Orange Cyberdefense’s Ric Derbyshire. Attackers can employ living off the plant tactics to stealthily access and move laterally inside industrial networks, abusing native functionality to conduct cyberespionage or disruption campaigns. Orange Cyberdefense’s Ric Derbyshire details essential defenses against this threat. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/living-off-plant-ot-attacks-pose-physical-safety-risk-a-32591
-
OctLurk and SilkLurk Windows Backdoors Target Governments in 6 Countries
Kaspersky links OctLurk and SilkLurk to cyberespionage attacks stealing passwords, emails and files from government systems in six countries since January 2025. First seen on hackread.com Jump to article: hackread.com/octlurk-silklurk-backdoors-target-6-countries/
-
OctLurk and SilkLurk Backdoors Target Central Asian Governments in Cyberespionage Campaign
OctLurk and SilkLurk are highly customized, memory”‘resident backdoors used in an ongoing cyberespionage campaign against government and critical”‘sector networks across Central Asia and Syria, operated by a Chinese”‘speaking threat actor but not yet linked to a known APT. Active since January 2025, the operation leverages victim”‘specific loaders, multi”‘plugin frameworks, and shared infrastructure, along with Linux”‘focused…
-
Russian Espionage Hackers Hit Zimbra With Half-Click Attacks
Tags: attack, cyberespionage, cybersecurity, data, email, espionage, hacker, malicious, russia, update, vulnerabilityViewing Malicious Email in Vulnerable Webmail Client Triggers Data-Stealing Attack. Russian cyberespionage hackers are targeting a vulnerability in Zimbra Collaboration Suite – a patch is available – that enables them to execute a malicious, data- and email-stealing script simply if a user of a vulnerable client opens their email, warn Western cybersecurity agencies. First seen…
-
North Korean Hackers Use Fake Job Interviews to Deploy PylangGhost and GolangGhost RATs
North Korea’s Famous Chollima threat group, also tracked as Wagemole, is actively running a sophisticated cyberespionage campaign dubbed ClickFake Interview. The operation targets cryptocurrency and Web3 professionals, tricking candidates into executing terminal commands that infect their devices with platform-specific Remote Access Trojans (RATs): PylangGhost on Windows and GolangGhost on macOS. Detailed analysis by the SOCRadar…
-
EU and UK Sanction Russian Nation-State Hackers
Governments Cite Winter Hack of Polish Power Grid and Cyberespionage. A winter Russian intelligence hack of the Polish energy grid and a protracted campaign of cyberespionage are behind coordinated sanctions against Moscow’s intelligence apparatus announced Monday by the European Union and the United Kingdom. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/eu-uk-sanction-russian-nation-state-hackers-a-32213
-
EU Targets FSB-Linked Hackers in New Sanctions Over Cyber Sabotage
EU sanctions target nine people and four entities tied to Russia’s FSB over a 15-year cyberespionage and critical infrastructure sabotage campaign. The European Union imposed sanctions on Monday targeting nine individuals and four entities linked to a Russian cyberespionage and sabotage operation that Brussels says has been running since 2010. The targets include Russian military…
-
Chinese Cyberespionage Exploits University Roundcube Servers
Campaign Combines XSS and Deserialization to Steal Credentials and Deploy Malware. Proofpoint identified a likely China-aligned espionage group exploiting chained Roundcube vulnerabilities to steal credentials and deploy persistent malware against U.S. and Canadian university departments conducting sensitive physics, engineering and national security research. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/chinese-cyberespionage-exploits-university-roundcube-servers-a-32165
-
FBI Disrupts Widely Used NetNut Residential Proxy Service
2 Million Home Devices, Including Routers and Smart TVs, Tied to NetNut Botnet. The FBI and private-sector partners have disrupted NetNut, one of the world’s biggest and most popular residential proxy networks. Google researchers said it comprised 2 million secretly hijacked home devices and was often used to route and disguise cybercrime and cyberespionage activity.…
-
Neue Spionage-Gruppe OP-512 attackiert Microsoft-Server
Die Cyberspionage-Gruppe OP-512 greift gezielt Microsoft IIS-Webserver an und nutzt ein maßgeschneidertes Web-Shell-Framework zur Tarnung. First seen on it-daily.net Jump to article: www.it-daily.net/it-sicherheit/cybercrime/microsoft-server-spionage
-
China-linked actor spent two years inside medical research networks
Tags: china, credentials, cyberespionage, email, google, group, intelligence, military, network, threatChina’s UNC6508 hid in North American medical research networks for 2 years, stealing credentials and forwarding emails to Gmail Google’s Threat Intelligence Group published a report this week on UNC6508, a China-linked cyberespionage group that breached North American medical and military research organizations and stayed hidden for more than two years. The earliest confirmed intrusion…
-
PRC-Nexus Hackers Abuse REDCap Servers to Monitor US Medical Research Organizations
A sophisticated, long-running cyberespionage campaign attributed to UNC6508, a People’s Republic of China (PRC)-nexus threat actor, that systematically targets North American academic, medical, and military research institutions. The campaign, active since at least September 2023, remained undetected for over a year while the threat actor silently harvested credentials, exfiltrated sensitive communications, and maintained persistent access across victim…
-
Russian national charged in connection with Void Blizzard cyberespionage campaign
First seen on scworld.com Jump to article: www.scworld.com/brief/russian-national-charged-in-connection-with-void-blizzard-cyber-espionage-campaign
-
Hacker linked to Void Blizzard faces charges over cyberespionage campaign
Denis Obrezko, 36, made his initial appearance in federal court in Boston on Tuesday after being transferred to U.S. custody from Thailand, where he was arrested last November. First seen on therecord.media Jump to article: therecord.media/hacker-linked-to-void-blizzard-faces-charges
-
Hacker linked to Void Blizzard faces charges over cyberespionage campaign
Denis Obrezko, 36, made his initial appearance in federal court in Boston on Tuesday after being transferred to U.S. custody from Thailand, where he was arrested last November. First seen on therecord.media Jump to article: therecord.media/hacker-linked-to-void-blizzard-faces-charges
-
Russian Attackers Weaponize WinRAR Flaw Against Ukrainian Orgs
Two separate campaigns target CVE-2025-8088, fixed last July, to conduct data theft and cyberespionage against military and government targets in Ukraine. First seen on darkreading.com Jump to article: www.darkreading.com/vulnerabilities-threats/russian-groups-winrar-flaw-ukrainian-orgs
-
Breach Roundup: Microsoft Tries to Mend Researcher Bridges
Also: Gas Station Monitoring Systems Under Attack, Spanish Teen Doxer Arrested. This week, more happened than fits here: Microsoft tried to make nice with researchers, gas tank gauges under attack in the United States, fake FIFA websites are everywhere. Russia cried cyberespionage, Spanish police arrested a teenaged doxer, a Oracle Weblogic flaw was actively exploited.…
-
Breach Roundup: Microsoft Tried to Mend Researcher Bridges
Also: Gas Station Monitoring Systems Under Attack, Spanish Teen Doxer Arrested. This week, more happened than fits here: Microsoft tried to make nice with researchers, gas tank gauges under attack in the United States, fake FIFA websites are everywhere. Russia cried cyberespionage, Spanish police arrested a teenaged doxer, a Oracle Weblogic flaw was actively exploited.…
-
Afghan finance officials targeted by suspected Pakistani cyberespionage campaign
A suspected Pakistan-linked hacking group has targeted Afghanistan’s Ministry of Finance and provincial government officials in a new cyberespionage campaign, researchers have found. First seen on therecord.media Jump to article: therecord.media/afghan-officials-targeted-by-sidecopy
-
FrostyNeighbor: Neue Tricks und digitale Spielchen
Tags: cyberespionageESET-Forscher entdeckten neue Aktivitäten von FrostyNeighbor aufgedeckt. Die Belarus nahestehende Gruppe hat ihre Angriffskette erneut angepasst, um ihre laufenden Cyberespionage-Operationen fortzusetzen. First seen on welivesecurity.com Jump to article: www.welivesecurity.com/de/eset-research/frostyneighbor-neue-tricks-und-digitale-spielchen/
-
FrostyNeighbor: FrostyNeighbor: Neue Tricks und digitale Spielchen
Tags: cyberespionageESET-Forscher entdeckten neue Aktivitäten von FrostyNeighbor aufgedeckt. Die Belarus nahestehende Gruppe hat ihre Angriffskette erneut angepasst, um ihre laufenden Cyberespionage-Operationen fortzusetzen. First seen on welivesecurity.com Jump to article: www.welivesecurity.com/de/eset-research/frostyneighbor-frostyneighbor-neue-tricks-und-digitale-spielchen/
-
Mustang Panda Linked to New Modular FDMTP Backdoor
Researchers Say Nation-State Actors Are Evolving Persistence Techniques. An apparent Chinese nation-state hacking group gussied up its tooling with new modular functionality, say security researchers who observed a cyberespionage campaign affecting Asia-Pacific governments. The activity resembles attack patterns of the threat actor tracked as Mustang Panda First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/mustang-panda-linked-to-new-modular-fdmtp-backdoor-a-31696
-
Python Infostealer Hides in GitHub Releases to Bypass Detection
A stealthy Python-based infostealer campaign that abuses GitHub Releases to host payloads and maintain long-term, low”‘visibility access to victim systems. The operation, dubbed “Operation HumanitarianBait” in some reporting, appears designed for cyberespionage against Russian”‘speaking targets using humanitarian”‘themed lures and a PE”‘less Python architecture. The campaign starts with phishing emails that deliver a RAR archive containing…
-
Omani Government Targeted in Blatant Iranian-Nexus Cyberespionage
The post Omani Government Targeted in Blatant Iranian-Nexus Cyberespionage appeared first on Daily CyberSecurity. First seen on securityonline.info Jump to article: securityonline.info/oman-government-cyberattack-hunt-intelligence-apt34-muddywater/
-
Hackers Abuse DAEMON Tools Distribution Channel to Deliver Malicious Payloads
A sophisticated supply-chain attack has compromised the official distribution channel for DAEMON Tools, delivering multi-stage malware to users worldwide. Since April 8, 2026, threat actors have distributed trojanized installers signed with legitimate digital certificates to conduct highly targeted cyberespionage operations. Attackers successfully breached the development pipeline of AVB Disc Soft, the creators of the widely…

