Tag: espionage
-
Russian hackers hijack hotel Wi-Fi networks to spy on travelers, Microsoft says
Russian state-sponsored hackers have been compromising hotel Wi-Fi networks around the world to steal travelers’ login credentials and infect devices with espionage malware, Microsoft said. First seen on therecord.media Jump to article: therecord.media/russian-wifi-hackers-hotels
-
Russian Hackers Exploit Hotel Wi-Fi in New CaptiveCrunch Espionage Campaign
Microsoft Threat Intelligence has uncovered CaptiveCrunch, a cyber espionage campaign linked to Storm-2945, a subgroup of Midnight Blizzard, the Russian state-linked threat actor associated with Russia’s Foreign Intelligence Service (SVR). First seen on thecyberexpress.com Jump to article: thecyberexpress.com/captivecrunch-midnight-blizzard/
-
AI Agent Drives Espionage Attack on Thai Ministry of Finance
Attackers used Hermes, an autonomous open source tool, in unrestricted YOLO mode to conduct espionage against Thailand’s Ministry of Finance. First seen on darkreading.com Jump to article: www.darkreading.com/cyberattacks-data-breaches/ai-agent-espionage-attack-thai-ministry-finance
-
Hackers used autonomous AI agent to spy on Thailand’s finance ministry
Hackers used an autonomous artificial intelligence agent to carry out a cyber-espionage campaign against Thailand’s Ministry of Finance, researchers discovered. First seen on therecord.media Jump to article: therecord.media/thailand-hackers-ai-finance-ministry
-
Russian Espionage Hackers Hit Zimbra With Half-Click Attacks
Tags: attack, cyberespionage, cybersecurity, data, email, espionage, hacker, malicious, russia, update, vulnerabilityViewing Malicious Email in Vulnerable Webmail Client Triggers Data-Stealing Attack. Russian cyberespionage hackers are targeting a vulnerability in Zimbra Collaboration Suite – a patch is available – that enables them to execute a malicious, data- and email-stealing script simply if a user of a vulnerable client opens their email, warn Western cybersecurity agencies. First seen…
-
GoSerpent Backdoor Drives a Patient Cyber Espionage Campaign Against Southeast Asian Governments
At a glance Malware family GoSerpent backdoor, plus McMx, Stowaway, ThumbcacheService, and TmcLoader/TmcPayload Threat actor Unconfirmed. Kaspersky notes First seen on securityonline.info Jump to article: securityonline.info/goserpent-backdoor/
-
Thailand’s Ministry of Finance Targeted With Hermes AI Agent Running Unattended, Hades Implant Staged
Hunt.io uncovered a cyber-espionage attack on Thailand’s Finance Ministry using Hermes AI agent and Hades malware for reconnaissance and persistence. Researchers at Hunt.io have uncovered an intrusion targeting Thailand’s Ministry of Finance that offers a rare look inside a live cyber-espionage operation. Instead of recovering malware after the fact, the team found exposed staging servers…
-
Hotel Wi-Fi Routers Compromised to Steal Corporate Login Credentials From Visitors
Researchers at ReliaQuest warned of widespread DNS poisoning attacks targeting the hospitality sector as part of a cyber espionage campaign First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/hotel-wifi-dns-poisoning/
-
Russian LAUNDRY BEAR Hackers Exploit Zimbra Zero-Day to Steal 90 Days of Emails
Tags: advisory, cyber, cybersecurity, defense, email, espionage, exploit, government, group, hacker, russia, technology, threat, vulnerability, zero-dayRussian state-supported threat actors, known as LAUNDRY BEAR, have exploited a zero-day vulnerability in the Zimbra Collaboration Suite to steal up to 909,090 days’ worth of emails from targeted organizations across Western countries. A joint cybersecurity advisory, AA26-204A, issued on July 23, 2026, warns that this espionage-focused group has targeted government, defense, energy, technology, education,…
-
Russian Espionage Group Exploited Zimbra Zero-Day to Steal Mail and 2FA Codes
A Russian state-supported espionage group spent months reading Western mailboxes through a then-unknown flaw in Zimbra’s webmail client.The payload goes after the last 90 days of email, the organization’s entire email directory, the password saved in the browser and the codes kept for two-factor recovery. Opening the message was enough to start it.The NSA, CISA…
-
Russian espionage group using novel Zimbra exploit to steal sensitive data from Western countries
Laundry Bear exploited a zero-day vulnerability for five months before it was patched in July 2025, and the group is still actively exploiting vulnerable environments. First seen on cyberscoop.com Jump to article: cyberscoop.com/russian-laundry-bear-zimbra-exploit/
-
New TriBack Loader Evades EDR Using Signed Binaries and Win32 Callback APIs
A new shellcode loader, dubbed “TriBack Loader,” to a China-nexus intrusion cluster tracked as JadeProx, with the malware explicitly engineered to evade modern EDR by abusing signed binaries and uncommon Win32 callback APIs. Across at least four observed variants, the loader underpins simultaneous espionage campaigns in South-East Asia and Latin America, including targeting of a…
-
HOLLOWGRAPH malware turns Microsoft 365 calendars into an espionage channel
Microsoft 365 calendars have become a hiding place for espionage malware, with commands and stolen files stashed inside appointments dated to the year 2050, researchers from … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/20/hollowgraph-malware-microsoft-365-calendar/
-
HollowGraph Malware Hides C2 and Stolen Files in Microsoft 365 Events Dated 2050
A newly discovered espionage implant has been using a hijacked Microsoft 365 calendar as its command channel, planting operator instructions and smuggling out stolen files as attachments on calendar events dated to the year 2050.Group-IB, which named the malware HollowGraph, says the approach moves tasking and stolen data through legitimate Microsoft Graph API traffic, so…
-
Dutch Intelligence Warns Russia Uses Hacked IP Cameras for Military Espionage
Dutch intelligence says Russia hacks IP cameras to monitor NATO military logistics and weapons shipments to Ukraine. The Netherlands’ AIVD and MIVD, the civilian and military intelligence services, published a joint advisory on July 10 confirming that at least one Russian intelligence service is systematically compromising internet-connected IP cameras across the Netherlands, other EU and…
-
New GoSerpent Malware Targets Southeast Asian Governments and Diplomats for Espionage
Cybersecurity researchers have discovered a previously undocumented malware called GoSerpent that has been put to use in cyber attacks targeting entities in Southeast Asia since late 2025 with a focus on long-term access and intelligence gathering.Russian cybersecurity company Kaspersky, which uncovered the activity in February 2026, said it was aimed at government and diplomatic entities…
-
GoSerpent Silently Steals Government Files for Weeks Before Sending Them to Hackers
A sophisticated cyber espionage campaign targeting government and diplomatic organizations across Southeast Asia has used a Go-based remote access Trojan, dubbed GoSerpent, to collect sensitive documents for weeks before exfiltrating them via network shares. Researchers first identified the activity in February 2026, although evidence indicates the operation began in late 2025. The attackers deployed GoSerpent…
-
Claude Code and DeepSeek Powered Chinese Cyber Espionage Campaign
Chinese actors used Claude Code and DeepSeek to automate attacks that breached government systems and targeted financial firms. Hunt.io researchers stumbled onto an active intrusion campaign in June 2026 while pivoting on known TencShell command-and-control infrastructure. A single HTTP header fingerprint on port 1111 led them to 13 Hong Kong-based servers and, on one of…
-
Europe strikes out against Russia’s Turla over espionage, ‘destructive attacks’
The EU, its members and the U.K. took action against Russian government officials and others while attributing the winter cyberattacks against Poland’s energy grid to the FSB. First seen on cyberscoop.com Jump to article: cyberscoop.com/eu-uk-russian-cyberespionage-sanctions/
-
Pakistani Police Systems Hit by Chinese and Indian Espionage
Chinese and Indian spies converged on the same Balochistan police force, SentinelLabs found First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/chinese-indian-espionage-pakistani/
-
Russian FSB-Linked Turla Hackers Target French Ministries, Embassies, and Defense Entities
France has publicly attributed a long-running cyber-espionage campaign targeting government, diplomatic and defence-linked organisations to Turla, an intrusion set associated with the 16th Center of Russia’s Federal Security Service (FSB), also known as military unit 71330. French authorities said the operation has affected entities across the French state since the 2010s, including ministries, diplomatic organizations,…
-
BusySnake Stealer Uses Reverse SSH Tunnels and AI-Generated Loaders to Evade Detection
Armored Likho, a previously undocumented threat group also tracked as Eagle Werewolf based on circumstantial evidence, is targeting government institutions and electric-power organizations across Russia, Brazil, and Kazakhstan with a new Python-based infostealer named BusySnake. The group’s activity reflects an unusual overlap between cyber-espionage and financially motivated operations. Armored Likho targets organizations for intelligence collection…
-
Taiwan charges two businessmen over alleged role in Chinese espionage campaign
A company based in Taiwan was leasing out accounts on the popular LINE messaging app to Chinese spies, according to prosecutors, who charged two men in the alleged scheme. First seen on therecord.media Jump to article: therecord.media/taiwan-charges-businessmen-china-cyber-espionage-campaign
-
Iran-linked MuddyWater espionage campaign targets organisations across four continents
A new threat intelligence report from WatchGuard is warning organisations worldwide to strengthen behavioural detection capabilities after uncovering an espionage campaign by the Iran-linked threat group MuddyWater that successfully targeted high-value organisations across four continents. The report details how the group, also known as Seedworm, targeted organisations across manufacturing, aviation, financial services, education, professional services…
-
Chinese Cyberespionage Exploits University Roundcube Servers
Campaign Combines XSS and Deserialization to Steal Credentials and Deploy Malware. Proofpoint identified a likely China-aligned espionage group exploiting chained Roundcube vulnerabilities to steal credentials and deploy persistent malware against U.S. and Canadian university departments conducting sensitive physics, engineering and national security research. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/chinese-cyberespionage-exploits-university-roundcube-servers-a-32165
-
Suspected Chinese espionage group used a Roundcube exploit chain to burrow into universities
Proofpoint researchers said attackers targeted physics and engineering departments, and warn that the campaign is likely ongoing. First seen on cyberscoop.com Jump to article: cyberscoop.com/china-espionage-attacks-us-canada-universities-proofpoint/
-
Armored Likho Targets Government Agencies, Power Sector with BusySnake Stealer
A previously undocumented threat actor known as Armored Likho has been attributed to cyber attacks targeting government agencies and the electric power sector across Russia, Brazil, and Kazakhstan.”Armored Likho blends financially motivated campaigns targeting private individuals with targeted cyber espionage aimed at organizations,” Kaspersky said in a technical analysis published today. “ First seen on…
-
ToddyCat Uses Shadow Token via Remote Debug to Compromise Gmail Accounts
ToddyCat, an advanced persistent threat group long associated with targeted espionage against corporate environments, has evolved its toolkit to exploit OAuth-based authorization flows and compromise Gmail accounts without directly stealing credentials. Umbrij is deployed on Windows hosts using DLL sideloading: attackers place a malicious DLL alongside legitimately signed executables known to insecurely load libraries (examples…

