Tag: russia
-
Russian-Speaking Hackers Used Cursor AI in Attacks on Seven Companies, Report Says
Russian-speaking hackers used Cursor AI during attacks on corporate networks, reportedly speeding reconnaissance, VPN access and exploitation attempts. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/news-cursor-ai-hackers-aur0ra-ransomware/
-
Russian APT BlueDelta Uses HOOKEDGE to Target Defense and Diplomatic Organizations
BlueDelta (APT28) uses webhook.site and Microsoft Edge to hide HOOKEDGE espionage traffic targeting European governments. Recorded Future’s Insikt Group documented a campaign by BlueDelta, the Russian GRU-linked group that overlaps with the group APT28, running an entire espionage operation against European government targets using webhook.site, a service built for developers to test HTTP requests, as…
-
BlueDelta Targets Defense and Diplomatic Organizations With HOOKEDGE Malware
Russian state-linked threat actor BlueDelta has launched a renewed espionage campaign against defense manufacturing, government, and diplomatic organizations in Romania, Spain, and Türkiye using a lightweight Windows backdoor dubbed HOOKEDGE. The activity, tracked from late September 2025 through early April 2026, relied on macro-enabled Microsoft Word documents and legitimate webhook infrastructure to establish access, execute…
-
Google Tracks Russian Cyber Espionage Clusters
Google tracks suspected Russian cyber espionage clusters abusing logins. Learn how these Russian cyber espionage clusters target global officials. First seen on securityonline.info Jump to article: securityonline.info/russian-cyber-espionage-clusters/
-
Leaked University Files Reveal How Russia Trains Hackers for Military Cyber Operations
A cache of leaked internal records has exposed what appears to be a structured Russian military cyber-operator pipeline embedded inside Bauman Moscow State Technical University. The documents indicate that the university’s concealed Department No. 4 trained students for intelligence collection, offensive cyber operations, information warfare, and technical defense before moving selected graduates into GRU-linked units.…
-
Breach Roundup: A Call for Cyber Defense Collective Action
e=4>This week: a call for cyber defense, OpenAI banned Russian ChatGPT accounts, critical Gitea flaw, U.K. airport passenger data theft, North Korean remote workers, Barcelona police data, Norway services hit by DDoS, Taiwan charged 9 over AI server exports and Nigeria advanced a sovereign cloud push. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/breach-roundup-call-for-cyber-defense-collective-action-a-32673
-
Pro-Russian Hackers Claim Norway’s Biggest-Ever Government Cyberattack
Norway’s Digdir faced its largest recorded DDoS attack as a pro-Russian group claimed responsibility and linked the campaign to support for Ukraine. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/news-norway-digdir-ddos-pro-russian-hackers-emea/
-
OpenAI Bans Russian ChatGPT Accounts Used in Covert Influence Campaign
OpenAI banned Russian ChatGPT accounts tied to a covert influence campaign involving copied research, fake attribution and coordinated social posts. The post OpenAI Bans Russian ChatGPT Accounts Used in Covert Influence Campaign appeared first on TechRepublic. First seen on techrepublic.com Jump to article: www.techrepublic.com/article/news-openai-russian-chatgpt-influence-campaign-emea/
-
Chinese and Russian spies stepping up cyberattacks, German companies report
Foreign intelligence services, particularly those from China and Russia, are increasingly behind cyberattacks on German companies, according to a new survey of the country’s private sector. First seen on therecord.media Jump to article: therecord.media/germany-cyberattacks-china-russia
-
Russian Hackers Phish EU Officials Over Messaging Apps
EU governments are trying to move away from popular messaging apps as nation-state threat groups shift their focus from email to Signal and WhatsApp. First seen on darkreading.com Jump to article: www.darkreading.com/cyberattacks-data-breaches/russian-hackers-phish-eu-officials-messaging-apps
-
Ransomware Hacker Uses AI to Plan Attacks and Compromises More Than 20 Organizations
A Russian-speaking affiliate of the Aurora ransomware operation compromised more than 20 organizations across nine countries between April and July 2026, using the AI coding assistant Cursor to plan intrusion activity and Active Directory escalation. The exposed server offered an unusually complete view of a ransomware affiliate’s operational workflow. It contained victim-specific directories, shell history,…
-
Russian Cyber Espionage Infrastructure Uses Evilginx and OAuth Phishing to Steal Accounts
Tags: access, authentication, credentials, cyber, espionage, exploit, flaw, infrastructure, phishing, russia, softwareRussian-linked cyber espionage operators are expanding account-compromise operations by combining OAuth abuse, device-code phishing, credential-harvesting infrastructure, and suspected Evilginx reverse-proxy setups. GTIG assesses with moderate confidence that UNC6293 is an initial-access subcluster of ICE RELIC, formerly tracked as APT29, Cozy Bear, and Midnight Blizzard. Rather than exploiting a software flaw, the operators abuse legitimate authentication…
-
OpenAI banned Russian ChatGPT accounts backing covert influence operation
OpenAI banned Russian ChatGPT accounts backing a fake think tank, IBI, that used AI posts and a fake “sovereignty” index to push pro”‘Russia narratives. OpenAI says it has banned a cluster of ChatGPT accounts that likely originated in Russia and were used to support a covert influence operation. The campaign promoted an organisation called the…
-
Russian hackers use ‘zero-click’ email attacks against organizations
First seen on scworld.com Jump to article: www.scworld.com/brief/russian-hackers-use-zero-click-email-attacks-against-organizations
-
Russia-Linked Operators Used ChatGPT to Run a Secretive Online Influence Campaign
OpenAI has disrupted a covert influence operation that used ChatGPT to promote a purported Israeli think tank, spread Russia-favorable narratives, and manufacture the appearance of academic legitimacy across major social platforms. The company banned a cluster of accounts it assessed as very likely originating in Russia after tracing AI-generated posts to a broader network built…
-
OpenAI Bans Russian ChatGPT Accounts Used to Run Influence Operation
OpenAI on Tuesday said it banned a cluster of Russian ChatGPT accounts that used VPNs to bypass access restrictions and run an influence operation, which relied on its artificial intelligence (AI) tool to generate social media posts and comments that were shared on Substack, Telegram, X, Facebook and LinkedIn.The accounts “were being used to promote…
-
Core Werewolf Hackers Deploy New CoreRAT Malware Against Russian Government and Defense Organizations
The Core Werewolf espionage cluster has introduced a previously undocumented remote access trojan dubbed CoreRAT in targeted attacks on Russian public-sector bodies and defense-industry organizations. The shift is notable because Core Werewolf, previously associated with the abuse of legitimate UltraVNC remote-access software and smaller custom backdoors, now operates a full-featured C++ RAT of its own.…
-
Ukraine to give Britain access to battlefield data to train AI
Ukraine will give Britain access to a vast trove of battlefield data collected during the war with Russia, allowing U.K. companies and researchers to use it to train and test artificial intelligence systems. First seen on therecord.media Jump to article: therecord.media/ukraine-uk-ai-drone-data
-
OpenAI Disrupts Russian Influence Campaign Promoting Fake Think Tank
OpenAI disrupted a covert Russian influence campaign promoting a fake think tank. Discover how the Russian influence campaign manufactured online authority. First seen on securityonline.info Jump to article: securityonline.info/russian-influence-campaign-openai/
-
Russian Backdoor Found in Slovak Traffic Cameras
SMS Messages Could Enable Remote Access to Live Traffic Feeds. Slovakian cyber authorities have suspended the rollout of high-speed traffic cameras after a security investigation uncovered backdoors and multiple software weaknesses. The devices were reportedly rebranded versions of Russian-made cameras sold through a Cyprus-based company. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/russian-backdoor-found-in-slovak-traffic-cameras-a-32645
-
iAuthFlow v2: The $10,000 Phishing Toolkit That Survives Your Password Reset
iAuthFlow v2 phishing toolkit uses a phished Google session to enroll an attacker-controlled passkey that survives password resets. Abnormal Security researchers have published an analysis of iAuthFlow v2, a phishing toolkit sold on a Russian-language cybercrime forum for $10,000 base price. The author also offers for sale additional capability modules separately. The headline feature is…
-
Your Expired Visa Card Could Be ‘Zombified’ to Make Contactless Payments
Plus: Apple sends out an “unprecedented” number of spyware warnings, Ukraine hits a Russian ecommerce giant with cyber and drone attacks, and more. First seen on wired.com Jump to article: www.wired.com/story/security-news-this-week-your-expired-visa-card-could-be-zombiefied-to-make-contactless-payments/
-
That Legitimate OAuth Login Might Be a Russian Hack
Attackers Use Real Google and Microsoft Authentication Before Redirecting Victims. Google says three Russia-linked espionage clusters are abusing legitimate Google and Microsoft authentication flows to steal tokens and account access from defense, government, academic and think tank targets, exposing a visibility gap around personal accounts. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/that-legitimate-oauth-login-might-be-russian-hack-a-32634
-
Russian network monitoring firm confirms cyberattack claimed by pro-Ukraine hackers
The statement came a day after a hacking group calling itself Black Spark claimed it had spent more than a month inside Microolap’s network and gained access to its internal systems, including EtherSensor, the company’s network traffic analysis platform. First seen on therecord.media Jump to article: therecord.media/russian-network-monitoring-firm-confirms-cyberattack-claimed-by-pro-ukraine-group
-
Fake Conferences, OAuth and WhatsApp: Inside Russia’s New Espionage Tactics
Tags: access, authentication, conference, cyber, defense, espionage, google, group, intelligence, phishing, russia, tactics, threat, toolGoogle tracks three Russia-linked espionage clusters using phishing and legitimate authentication tools to target researchers, diplomats and defense staff. Google’s Threat Intelligence Group tracked three separate suspected Russia-linked cyber espionage clusters. All three focus on the same thing: abusing authentication features that are supposed to protect accounts to access them instead. Threat actors target researchers,…
-
Head Mare APT Exploits TrueConf Server RCE Flaws to Deliver PhantomCore Malware
Tags: access, apt, attack, conference, cyber, exploit, flaw, group, kaspersky, malware, rce, remote-code-execution, russia, supply-chainThe Head Mare APT group has been linked to a supply chain compromise involving unpatched TrueConf Server instances, which enabled the delivery of PhantomCore malware to video conference participants. Kaspersky researchers identified this activity while investigating attacks against Russian organizations. Attackers hosted legitimate-looking TrueConf client installers on compromised servers that silently deployed the remote-access malware…
-
Head Mare APT Exploits TrueConf Server RCE Flaws to Deliver PhantomCore Malware
Tags: access, apt, attack, conference, cyber, exploit, flaw, group, kaspersky, malware, rce, remote-code-execution, russia, supply-chainThe Head Mare APT group has been linked to a supply chain compromise involving unpatched TrueConf Server instances, which enabled the delivery of PhantomCore malware to video conference participants. Kaspersky researchers identified this activity while investigating attacks against Russian organizations. Attackers hosted legitimate-looking TrueConf client installers on compromised servers that silently deployed the remote-access malware…
-
Russia-Linked Hackers Exploit Legitimate Login Flows to Bypass 2FA and Steal Account Access
Tags: 2fa, access, authentication, credentials, cyber, defense, espionage, exploit, government, hacker, login, password, russiaThree suspected Russian cyber espionage clusters abusing legitimate authentication mechanisms to hijack accounts belonging to academics, diplomats, defense personnel, government staff, and think-tank researchers across Europe and the United States. Rather than relying solely on credential-harvesting pages, the operators manipulate users into completing genuine app-password, OAuth, device-code, and device-linking workflows that can hand attackers authenticated…
-
Suspected Russian Hackers Abuse Google OAuth and WhatsApp Linking to Hijack Accounts
Three distinct suspected Russian cyber espionage threat clusters have been observed leveraging legitimate authentication flows to single out individuals working in academia, aerospace and defense, governments, and think tanks across Europe, as well as academia and think tanks within the U.S.These clusters include UNC6293, UNC7005, and UNC5976.”These clusters engage in persistent, adaptive First seen on…
-
Manic Android Malware Exfiltrates Data From Offline Phones via Nearby Infected Devices
A new Android threat codenamed Manic has been observed actively targeting Ukrainian banks, government and identity services, and messaging applications, as well as Russian and European financial institutions, global fintech and cryptocurrency services, and military-focused communications.”Manic sits at the intersection of Android banking malware and mobile spyware, combining financial-fraud First seen on thehackernews.com Jump to…

