Tag: espionage
-
NightEagle Uses BlueKeep and DCSync to Move Toward Active Directory Domain Controllers
NightEagle, an espionage-focused threat group also tracked as APT-Q-95, has expanded its operations from Asian targets to Russian organizations, using a layered intrusion chain that culminates in attempts to compromise Active Directory domain controllers. The campaign illustrates a familiar but dangerous enterprise compromise pattern: attackers do not need a novel zero-day exploit when exposed remote…
-
China Hackers Hit Latin American Governments With Backdoor
ESET Says FamousSparrow Shifted Nearly All Targeting to Latin America. A Chinese espionage group has deployed a previously undocumented backdoor against government entities in eight Latin American countries and territories, including Puerto Rico, in a campaign researchers say tracks with U.S. pressure on Chinese investments across the region. First seen on govinfosecurity.com Jump to article:…
-
SilkParasite Hackers Use SpiceRAT Infrastructure to Target Central Asian Governments and Energy Firms
A wider cluster of SpiceRAT command-and-control infrastructure has been linked to the SilkParasite cyber-espionage activity targeting government, telecommunications, and energy-related entities across Central Asia. The infrastructure findings extend the operational footprint around servers previously associated with the suspected China-nexus cluster, but do not establish that any impersonated organization was compromised. Detection logic derived from Cisco…
-
APT36 Targets Indian Government and Defense Organizations With New Rust Malware Arsenal
Pakistan-nexus threat actor APT36 has launched a renewed espionage campaign targeting government and defense organizations in India and Afghanistan. Deploying a new Rust-based malware suite designed for covert command-and-control, data theft, and propagation into isolated networks. Tracked by Zscaler ThreatLabz as Operation RapidRust, the activity was observed in August 2026 and reflects a significant evolution…
-
Chinese hackers use SparroWocky malware in govt espionage attacks
The China-linked espionage group FamousSparrow has been using a new backdoor named SparroWocky in attacks on government organizations in Latin America. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/chinese-hackers-use-sparrowocky-malware-in-govt-espionage-attacks/
-
Cyber Op Targets South Korean Media & Automotive Sectors
A likely North Korean advanced persistent threat (APT) group used a previously undocumented Linux espionage toolkit to compromise load balancers, gain access to communications, and further exploit networks. First seen on darkreading.com Jump to article: www.darkreading.com/cyberattacks-data-breaches/cyber-south-korean-media-automotive
-
One Exploit Chain, Two Espionage Campaigns: Chrome and Windows Under Fire
Two China-linked groups ran identical Chrome/Windows zero-day exploits against NGOs, before Chrome’s patch shipped, deploying different backdoors each. Two China-linked threat actors used the same Chrome/Windows zero-day against NGOs starting September 1, 2026, Volexity’s new report lays out the whole chain in detail. On September 1, Volexity detected a spear-phishing campaign by UTA0560 targeting several…
-
âš¡ Weekly Recap: Rogue AI Agents, WeChat Worm, PaperCut Attacks, AI Espionage, and Rootkits
AI keeps showing up in the wrong places. Attackers are using it to speed up exploits, test defenses, and automate more of the job. Some models are also crossing lines on their own. That is not a great combination.The rest of the week is more familiar: old bugs still working, fresh exploit chains, exposed systems,…
-
Hackers exploit Tencent app flaw to deploy GrayRabbit malware
Threat actors linked to a China-aligned espionage group are exploiting a critical vulnerability (CVE-2026-51990) in Tencent’s Sogou Input Method for Windows to deploy the GrayRabbit backdoor. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/hackers-exploit-tencent-app-flaw-to-deploy-grayrabbit-malware/
-
Threat Actors Use Claude AI Agents to Automate Cyberattacks and Steal Sensitive Data
Threat actors are increasingly using Claude-based AI workflows to automate cyberattacks, accelerate data theft, and reduce the technical expertise needed to run complex intrusions. Anthropic’s report details cyber espionage, financially motivated extortion, supply-chain compromise, and hacktivist activity disrupted between December 2025 and August 2026. Rather than using an AI chatbot only for occasional coding assistance,…
-
China-Linked Hackers Chain Chrome Zero-Day With Windows Kernel Flaw in Attacks
China-linked threat actors UTA0560 and JungleBamboo chained a Google Chrome zero-day with a Windows kernel privilege-escalation flaw in phishing campaigns targeting NGOs and other victims. Volexity documented the operations, detected on September 1, 2026, as using identical browser-to-kernel exploit components but ultimately installing separate espionage payloads: the GRIMWEDGE JScript backdoor and the LONGTALE credential-stealing Chrome…
-
Your AI Keys Are The Loot Now
Anthropic published its September 2026 threat intelligence report this week. It runs 154 pages and documents activity disrupted between December 2025 and August 2026 across seven harm areas, from state espionage to weapons development to a network of fake dating… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/your-ai-keys-are-the-loot-now/
-
Hackers abused Claude to extract secrets from 1.8M Android apps
Anthropic says multiple threat groups, including the financially motivated and state-sponsored espionage groups linked to Russia and China, tried to abuse its Claude AI model for malicious purposes. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/hackers-abused-claude-to-extract-secrets-from-18m-android-apps/
-
Russian State-Sponsored Hackers Use Claude to Rebuild Malware After Detection
Anthropic on Thursday revealed it disrupted a campaign mounted by a Russian state-sponsored threat actor that abused Claude for developing an AI-assisted workflow to get ahead of the detection curve.The operation has been attributed to a cyber espionage group it calls GTG-20006 (where “GTG” stands for Generative Threat Group), which aligns with broader reporting linking…
-
Anthropic caught Russia-linked spies using Claude in hacking operations
Anthropic detected and disrupted a Russia-linked cyber-espionage group that used its AI tool Claude in a hacking campaign targeting more than 20 government, intelligence, diplomatic and defense organizations. First seen on therecord.media Jump to article: therecord.media/anthropic-russia-hackers-claude
-
AI lets small actors run state-level hacking campaigns, Anthropic report finds
The report details a Russian-aligned espionage campaign against more than 20 organizations, an exploit foundry run by Chinese undergraduates and ShinyHunters-affiliated breaches, among other disrupted operations. First seen on cyberscoop.com Jump to article: cyberscoop.com/anthropic-report-ai-enabled-cyber-attacks/
-
New ‘BlueMoon’ kit exploited Windows and Chrome zero-day flaws
Multiple cyber-espionage groups deployed an exploit kit dubbed “BlueMoon” that leveraged zero-day vulnerabilities in Microsoft Windows and Google Chrome. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/new-bluemoon-kit-exploited-windows-and-chrome-zero-day-flaws/
-
New ‘BlueMoon’ kit exploited Windows and Chrome zero-day flaws
Multiple cyber-espionage groups deployed an exploit kit dubbed “BlueMoon” that leveraged zero-day vulnerabilities in Microsoft Windows and Google Chrome. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/new-bluemoon-kit-exploited-windows-and-chrome-zero-day-flaws/
-
New ‘BlueMoon’ kit exploited Windows and Chrome zero-day flaws
Multiple cyber-espionage groups deployed an exploit kit dubbed “BlueMoon” that leveraged zero-day vulnerabilities in Microsoft Windows and Google Chrome. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/new-bluemoon-kit-exploited-windows-and-chrome-zero-day-flaws/
-
New ‘BlueMoon’ kit exploited Windows and Chrome zero-day flaws
Multiple cyber-espionage groups deployed an exploit kit dubbed “BlueMoon” that leveraged zero-day vulnerabilities in Microsoft Windows and Google Chrome. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/new-bluemoon-kit-exploited-windows-and-chrome-zero-day-flaws/
-
Four Nation-State Actors Used the Same Chrome Zero-Day Exploit Kit Within 12 Days
Four espionage groups used the BlueMoon Chrome+Windows exploit kit within 12 days. Researchers suspect AI development. Proofpoint published a detailed analysis of a Chrome-and-Windows exploit kit it tracks as BlueMoon that four nation-state actors adopted within roughly two weeks of the first observed use. Google’s Threat Intelligence Group, Microsoft’s MSTIC, and Volexity all contributed to…
-
China-Linked Hackers Exploit Chrome and Windows Zero-Days in BlueMoon Attacks
Researcher has discovered a rapidly spreading exploit kit called BlueMoon, which combines vulnerabilities in the Chrome browser with a Windows kernel privilege-escalation flaw to compromise targets in espionage campaigns. This activity was first observed on August 28, 2026, and at least four threat clusters have adopted it, most of which are suspected to have ties…
-
Chinese espionage groups swarm to exploit triple-link chain of zero-days
Multiple China-aligned threat groups exploited the defects quickly to target various organizations. Proofpoint said the activity is ongoing and expects it to widen. First seen on cyberscoop.com Jump to article: cyberscoop.com/china-espionage-groups-exploit-chain-zero-days/
-
Chinese espionage groups swarm to exploit triple-link chain of zero-days
Multiple China-aligned threat groups exploited the defects quickly to target various organizations. Proofpoint said the activity is ongoing and expects it to widen. First seen on cyberscoop.com Jump to article: cyberscoop.com/china-espionage-groups-exploit-chain-zero-days/
-
Chinese espionage groups swarm to exploit triple-link chain of zero-days
Multiple China-aligned threat groups exploited the defects quickly to target various organizations. Proofpoint said the activity is ongoing and expects it to widen. First seen on cyberscoop.com Jump to article: cyberscoop.com/china-espionage-groups-exploit-chain-zero-days/
-
Four Spy Groups Used the Same Chrome and Windows Exploit Kit Within a Week
Multiple espionage-motivated threat activity clusters have been found deploying a previously undocumented exploit kit called BlueMoon that chains together multiple vulnerabilities in Microsoft Windows and Google Chrome.The first in-the-wild use of BlueMoon has been attributed to the China-aligned state-sponsored group tracked as APT31 (aka Bronze Vinewood, Judgement Panda, JungleBamboo, First seen on thehackernews.com Jump to…
-
Multiple Chinese hacking groups seen using identical Chrome zero-day exploit
A Google Chrome bug identified in August was exploited by at least four China-linked cyber-espionage groups, according to researchers. First seen on therecord.media Jump to article: therecord.media/china-hackers-chrome-browser-zero-day-multiple-groups
-
North Korea’s Lazarus Operates Through Six Distinct Cyber Clusters
Sekoia and Kudelski Security have observed that North Korea’s Lazarus umbrella is split into six distinct clusters, focused on espionage, financial theft and sanctions evasion First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/north-korea-lazarus-six-cyber/
-
DPRK-Linked Hackers Backdoor HAProxy Servers to Spy on South Korean Organizations
A previously undocumented Linux espionage toolkit linked with medium confidence to DPRK-aligned threat actors has been used to compromise South Korean organizations in the automotive and media sectors. The campaign is notable because it does not exploit a flaw in HAProxy itself. Instead, the operators appear to have obtained code execution on targeted edge servers…
-
Russian Hackers Deploy New HOOKEDGE Backdoor in Espionage Attacks Across Europe
Russian state-sponsored threat actor BlueDelta, also tracked as APT28, Fancy Bear, and Forest Blizzard, has deployed a lightweight Windows backdoor named HOOKEDGE in espionage operations targeting government, diplomatic, and defense-manufacturing organizations across Europe. The activity, documented by PolySwarm, targeted entities in Romania, Spain, and Turkey between late September 2025 and early April 2026. New variants…

