Tag: espionage
-
Hackers used autonomous AI agent to spy on Thailand’s finance ministry
Hackers used an autonomous artificial intelligence agent to carry out a cyber-espionage campaign against Thailand’s Ministry of Finance, researchers discovered. First seen on therecord.media Jump to article: therecord.media/thailand-hackers-ai-finance-ministry
-
Russian Espionage Hackers Hit Zimbra With Half-Click Attacks
Tags: attack, cyberespionage, cybersecurity, data, email, espionage, hacker, malicious, russia, update, vulnerabilityViewing Malicious Email in Vulnerable Webmail Client Triggers Data-Stealing Attack. Russian cyberespionage hackers are targeting a vulnerability in Zimbra Collaboration Suite – a patch is available – that enables them to execute a malicious, data- and email-stealing script simply if a user of a vulnerable client opens their email, warn Western cybersecurity agencies. First seen…
-
Hotel Wi-Fi Routers Compromised to Steal Corporate Login Credentials From Visitors
Researchers at ReliaQuest warned of widespread DNS poisoning attacks targeting the hospitality sector as part of a cyber espionage campaign First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/hotel-wifi-dns-poisoning/
-
GoSerpent Backdoor Drives a Patient Cyber Espionage Campaign Against Southeast Asian Governments
At a glance Malware family GoSerpent backdoor, plus McMx, Stowaway, ThumbcacheService, and TmcLoader/TmcPayload Threat actor Unconfirmed. Kaspersky notes First seen on securityonline.info Jump to article: securityonline.info/goserpent-backdoor/
-
Thailand’s Ministry of Finance Targeted With Hermes AI Agent Running Unattended, Hades Implant Staged
Hunt.io uncovered a cyber-espionage attack on Thailand’s Finance Ministry using Hermes AI agent and Hades malware for reconnaissance and persistence. Researchers at Hunt.io have uncovered an intrusion targeting Thailand’s Ministry of Finance that offers a rare look inside a live cyber-espionage operation. Instead of recovering malware after the fact, the team found exposed staging servers…
-
Russian LAUNDRY BEAR Hackers Exploit Zimbra Zero-Day to Steal 90 Days of Emails
Tags: advisory, cyber, cybersecurity, defense, email, espionage, exploit, government, group, hacker, russia, technology, threat, vulnerability, zero-dayRussian state-supported threat actors, known as LAUNDRY BEAR, have exploited a zero-day vulnerability in the Zimbra Collaboration Suite to steal up to 909,090 days’ worth of emails from targeted organizations across Western countries. A joint cybersecurity advisory, AA26-204A, issued on July 23, 2026, warns that this espionage-focused group has targeted government, defense, energy, technology, education,…
-
Russian Espionage Group Exploited Zimbra Zero-Day to Steal Mail and 2FA Codes
A Russian state-supported espionage group spent months reading Western mailboxes through a then-unknown flaw in Zimbra’s webmail client.The payload goes after the last 90 days of email, the organization’s entire email directory, the password saved in the browser and the codes kept for two-factor recovery. Opening the message was enough to start it.The NSA, CISA…
-
Russian espionage group using novel Zimbra exploit to steal sensitive data from Western countries
Laundry Bear exploited a zero-day vulnerability for five months before it was patched in July 2025, and the group is still actively exploiting vulnerable environments. First seen on cyberscoop.com Jump to article: cyberscoop.com/russian-laundry-bear-zimbra-exploit/
-
New TriBack Loader Evades EDR Using Signed Binaries and Win32 Callback APIs
A new shellcode loader, dubbed “TriBack Loader,” to a China-nexus intrusion cluster tracked as JadeProx, with the malware explicitly engineered to evade modern EDR by abusing signed binaries and uncommon Win32 callback APIs. Across at least four observed variants, the loader underpins simultaneous espionage campaigns in South-East Asia and Latin America, including targeting of a…
-
HOLLOWGRAPH malware turns Microsoft 365 calendars into an espionage channel
Microsoft 365 calendars have become a hiding place for espionage malware, with commands and stolen files stashed inside appointments dated to the year 2050, researchers from … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/20/hollowgraph-malware-microsoft-365-calendar/
-
HollowGraph Malware Hides C2 and Stolen Files in Microsoft 365 Events Dated 2050
A newly discovered espionage implant has been using a hijacked Microsoft 365 calendar as its command channel, planting operator instructions and smuggling out stolen files as attachments on calendar events dated to the year 2050.Group-IB, which named the malware HollowGraph, says the approach moves tasking and stolen data through legitimate Microsoft Graph API traffic, so…
-
Dutch Intelligence Warns Russia Uses Hacked IP Cameras for Military Espionage
Dutch intelligence says Russia hacks IP cameras to monitor NATO military logistics and weapons shipments to Ukraine. The Netherlands’ AIVD and MIVD, the civilian and military intelligence services, published a joint advisory on July 10 confirming that at least one Russian intelligence service is systematically compromising internet-connected IP cameras across the Netherlands, other EU and…
-
New GoSerpent Malware Targets Southeast Asian Governments and Diplomats for Espionage
Cybersecurity researchers have discovered a previously undocumented malware called GoSerpent that has been put to use in cyber attacks targeting entities in Southeast Asia since late 2025 with a focus on long-term access and intelligence gathering.Russian cybersecurity company Kaspersky, which uncovered the activity in February 2026, said it was aimed at government and diplomatic entities…
-
GoSerpent Silently Steals Government Files for Weeks Before Sending Them to Hackers
A sophisticated cyber espionage campaign targeting government and diplomatic organizations across Southeast Asia has used a Go-based remote access Trojan, dubbed GoSerpent, to collect sensitive documents for weeks before exfiltrating them via network shares. Researchers first identified the activity in February 2026, although evidence indicates the operation began in late 2025. The attackers deployed GoSerpent…
-
Claude Code and DeepSeek Powered Chinese Cyber Espionage Campaign
Chinese actors used Claude Code and DeepSeek to automate attacks that breached government systems and targeted financial firms. Hunt.io researchers stumbled onto an active intrusion campaign in June 2026 while pivoting on known TencShell command-and-control infrastructure. A single HTTP header fingerprint on port 1111 led them to 13 Hong Kong-based servers and, on one of…
-
Europe strikes out against Russia’s Turla over espionage, ‘destructive attacks’
The EU, its members and the U.K. took action against Russian government officials and others while attributing the winter cyberattacks against Poland’s energy grid to the FSB. First seen on cyberscoop.com Jump to article: cyberscoop.com/eu-uk-russian-cyberespionage-sanctions/
-
Pakistani Police Systems Hit by Chinese and Indian Espionage
Chinese and Indian spies converged on the same Balochistan police force, SentinelLabs found First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/chinese-indian-espionage-pakistani/
-
Russian FSB-Linked Turla Hackers Target French Ministries, Embassies, and Defense Entities
France has publicly attributed a long-running cyber-espionage campaign targeting government, diplomatic and defence-linked organisations to Turla, an intrusion set associated with the 16th Center of Russia’s Federal Security Service (FSB), also known as military unit 71330. French authorities said the operation has affected entities across the French state since the 2010s, including ministries, diplomatic organizations,…
-
BusySnake Stealer Uses Reverse SSH Tunnels and AI-Generated Loaders to Evade Detection
Armored Likho, a previously undocumented threat group also tracked as Eagle Werewolf based on circumstantial evidence, is targeting government institutions and electric-power organizations across Russia, Brazil, and Kazakhstan with a new Python-based infostealer named BusySnake. The group’s activity reflects an unusual overlap between cyber-espionage and financially motivated operations. Armored Likho targets organizations for intelligence collection…
-
Taiwan charges two businessmen over alleged role in Chinese espionage campaign
A company based in Taiwan was leasing out accounts on the popular LINE messaging app to Chinese spies, according to prosecutors, who charged two men in the alleged scheme. First seen on therecord.media Jump to article: therecord.media/taiwan-charges-businessmen-china-cyber-espionage-campaign
-
Iran-linked MuddyWater espionage campaign targets organisations across four continents
A new threat intelligence report from WatchGuard is warning organisations worldwide to strengthen behavioural detection capabilities after uncovering an espionage campaign by the Iran-linked threat group MuddyWater that successfully targeted high-value organisations across four continents. The report details how the group, also known as Seedworm, targeted organisations across manufacturing, aviation, financial services, education, professional services…
-
Chinese Cyberespionage Exploits University Roundcube Servers
Campaign Combines XSS and Deserialization to Steal Credentials and Deploy Malware. Proofpoint identified a likely China-aligned espionage group exploiting chained Roundcube vulnerabilities to steal credentials and deploy persistent malware against U.S. and Canadian university departments conducting sensitive physics, engineering and national security research. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/chinese-cyberespionage-exploits-university-roundcube-servers-a-32165
-
Suspected Chinese espionage group used a Roundcube exploit chain to burrow into universities
Proofpoint researchers said attackers targeted physics and engineering departments, and warn that the campaign is likely ongoing. First seen on cyberscoop.com Jump to article: cyberscoop.com/china-espionage-attacks-us-canada-universities-proofpoint/
-
Armored Likho Targets Government Agencies, Power Sector with BusySnake Stealer
A previously undocumented threat actor known as Armored Likho has been attributed to cyber attacks targeting government agencies and the electric power sector across Russia, Brazil, and Kazakhstan.”Armored Likho blends financially motivated campaigns targeting private individuals with targeted cyber espionage aimed at organizations,” Kaspersky said in a technical analysis published today. “ First seen on…
-
ToddyCat Uses Shadow Token via Remote Debug to Compromise Gmail Accounts
ToddyCat, an advanced persistent threat group long associated with targeted espionage against corporate environments, has evolved its toolkit to exploit OAuth-based authorization flows and compromise Gmail accounts without directly stealing credentials. Umbrij is deployed on Windows hosts using DLL sideloading: attackers place a malicious DLL alongside legitimately signed executables known to insecurely load libraries (examples…
-
FCC Bans Chinese-Produced Network Equipment Linked to Cyber and Espionage Risks
The U.S. Federal Communications Commission (FCC) has implemented comprehensive new restrictions banning the import and marketing of Chinese-produced telecommunications and surveillance equipment identified as posing significant cybersecurity and espionage risks. Announced on June 26, 2026, this updated regulation addresses a longstanding loophole that previously allowed companies on the FCC’s “Covered List” to continue selling older,…
-
Mustang Panda Targets India’s Government and Energy Sectors With ZOHOMURK and MINIRECON
Two concurrent espionage campaigns by Mustang Panda targeting Indian government and energy-sector organisations, deploying a novel malware suite that includes SHARDLOADER, MINIRECON and ZOHOMURK. The intrusions, observed in June 2026, focused on hydropower entities and government offices engaged in MOUs with Taiwanese institutions, using geopolitically themed lures and weaponised archives that sideload malicious DLLs via…
-
Mustang Panda Uses Zoho WorkDrive as Command Channel in Indian Government Attacks
The China-aligned espionage group Mustang Panda is running two campaigns against the Indian government and hydropower targets, deploying new malware and turning a legitimate cloud service into its command channel.Acronis Threat Research Unit found active compromises inside Indian government networks, including machines used by senior administrative staff, and worked with First seen on thehackernews.com Jump…
-
STOCKSTAY Malware Uses WebSocket C2, RSA Encryption, and Environmental Keying for Stealth
Analysis of a .NET backdoor tracked as STOCKSTAY exposes a mature, modular espionage implant actively developed and deployed by the Russia-linked Turla cluster since at least December 2022. STOCKSTAY demonstrates several operational techniques designed to maximize stealth and survivability: secure WebSocket-based C2, asymmetric encryption using a 4096-bit RSA keypair, inter-component IPC, and environment-based keying of…

