Tag: apt
87 articles

Chinese Hackers Exploit Cisco Routers for Covert Surveillance
Chinese hackers have cleverly exploited Cisco routers, transforming them from mere transit devices to covert surveillance platforms, as discovered by incident responders at Sygnia. This sinister manipulation allows hackers to secretly collect data, with one of the first clues being an unexplained GRE tunnel interface on a Cisco IOS XR router.

Fire Ant Exploits Cisco Routers to Harvest Credentials and Evade Detection
When hackers take control of routers like Cisco's IOS XR, they don't just gain access - they gain a bird's-eye view of the entire network, allowing them to harvest sensitive credentials and fly under the radar. The notorious Fire Ant group recently exploited these routers to turn them into intelligence collection platforms, putting countless networks at risk.

FBI Warns of Chinese Hacker Group QTFY's Infrastructure Attacks
Meet QTFY, a notorious Chinese hacker group that's been wreaking havoc on US government and critical infrastructure networks with its custom-built QScan platform, capable of conducting over 2 million scanning and penetration testing tasks in just one day. This sophisticated tool has helped QTFY identify and exploit targets with alarming speed and accuracy.

Iranian Hacker Group Expands Arsenal with Advanced Backdoor, SSH Tunneler
Meet the Iranian Hacker Group that's expanding its cyber espionage arsenal with advanced tools, potentially setting its sights on a broader target list that includes Middle Eastern and European countries. Their latest moves suggest a more aggressive and sophisticated approach to digital spying.

Tortoiseshell Malware Toolkit Expands with New Backdoor, SSH Tunneling
Meet Tortoiseshell, a stealthy malware toolkit that's been lurking in the shadows since 2018, and just got a nasty upgrade with a new backdoor and SSH tunneling capabilities. This cyber-espionage group's toolkit expansion could spell trouble for defense, aerospace, and military organizations worldwide.

ToxicPanda Malware Exploits VPN Permissions to Evade Google Play Security Checks
Meet ToxicPanda, a sneaky malware that's evolved to outsmart Google Play's security checks by exploiting VPN permissions and controlling device traffic. This cunning threat can now target nearly 350 apps and execute over 160 remote commands, putting your mobile security at risk.

Google Tracks Russian Cyber Spies Abusing OAuth in Targeted Phishing Campaigns
Google is sounding the alarm on Russian cyber spies who are using OAuth to carry out highly targeted phishing campaigns against top industries, and is sharing details of the attacks to help people recognize malicious outreach. The tech giant has identified three distinct groups behind the ongoing operations, which have been targeting individuals in Europe and the US since last year.

China-linked SilkParasite campaign targets Central Asia with custom RATs
Meet SilkParasite, a sneaky espionage operation linked to China that's been targeting government bodies in Central Asia with a custom arsenal of Remote Access Tools. This sophisticated campaign boasts seven unique RAT families, five of which have never been seen before, and hints at AI-assisted development.

US Recharges Indictment Against Iranian Hackers Tied to Mabna Institute
The US has ramped up its pursuit of justice against Iranian hackers, expanding an indictment to charge 17 individuals affiliated with the notorious Mabna Institute, which allegedly compromised over 100,000 professors' email accounts worldwide. This move marks a significant escalation in the case, with eight new defendants added to the original 2018 indictment.

Mustang Panda Upgrades CoolClient Backdoor with Signed Windows Rootkit
Meet the upgraded CoolClient backdoor, now armed with a signed Windows rootkit that lets it hide in plain sight, and a closer look reveals it's linked to the notorious HoneyMyte threat group, aka Mustang Panda. This sneaky malware has been targeting victims in Myanmar, Mongolia, Pakistan, and more.

China-nexus APT Exploits VMware Flaw to Deploy Ransomware
A China-linked APT group has been exploiting a recently patched VMware vCenter vulnerability to deploy ransomware in a widespread campaign that hit 361 victims across 47 countries. The attackers used the flaw to gain root access and, in some cases, installed a Babuk-derived ransomware that locks files with a ".babyk" extension.

HoneyMyte APT Group Upgrades CoolClient Backdoor with Kernel-Level Rootkit
Meet the upgraded CoolClient Backdoor, now packing a kernel-level rootkit courtesy of the sneaky HoneyMyte APT Group - and it's hiding in plain sight with a legit digital signature. This clever malware uses a Windows service and a kernel-mode driver to evade detection.

Lazarus Exploits Windows Zero-Day in Targeted Defense Sector Attacks
The notorious Lazarus threat group has been exploiting a newly patched Windows zero-day vulnerability, CVE-2026-68820, to gain SYSTEM privileges and escalate their attacks on high-value targets in the defense sector. This alarming exploit has been active since early July, making it crucial for organizations to stay vigilant.

Lazarus Exploits Windows Zero-Day with Post-Quantum Key Exchange Tactics
Lazarus hackers have taken a cutting-edge approach, using a post-quantum key exchange to secure their command channel before exploiting a Windows zero-day vulnerability in a targeted campaign against defense and aerospace companies. They leveraged Kyber/ML-KEM, a key encapsulation scheme designed to withstand quantum computer attacks, to generate fresh key material and evade detection.

Lazarus Group Exploits Microsoft Zero-Day in Global Defense Sector Attacks
North Korea's notorious Lazarus Group has been exploiting a Microsoft zero-day vulnerability, CVE-2026-68820, since early June, targeting the global defense sector with alarming precision. This high-severity flaw, patched in August, allowed attackers to execute code with SYSTEM-level privileges, putting countless systems at risk.

Microsoft Patches Zero-Day Windows Driver Flaw Under Active Attack
Microsoft just patched a high-severity Windows driver flaw, known as CVE-2026-68820, that was already being exploited by hackers in the wild. This zero-day vulnerability, with a CVSS score of 7.0, could be triggered by a race condition, allowing attackers to gain a foothold in targeted systems.

Head Mare APT Exploits Unpatched TrueConf Servers to Deliver PhantomCore Malware
In a sneaky move, the Head Mare group exploited unpatched TrueConf servers to spread PhantomCore malware, using a chain of vulnerabilities to swap out legitimate client installers with infected ones. This allowed them to secretly deliver a backdoor to unsuspecting meeting participants.

Kimsuky Bolsters Phishing Arsenal with Offline AI Infrastructure
North Korean hackers Kimsuky are taking phishing to the next level by leveraging offline AI infrastructure, a deliberate move to supercharge their espionage capabilities. Genians, a South Korean security firm, uncovered evidence of language-model tools like Ollama and GPT4All being installed and run on Kimsuky's servers.

TeamPCP Linked to Years-Old Cryptojacking Operation
New research reveals that TeamPCP, a notorious cryptojacking group, has been secretly operating for years, with evidence tracing back to 2020 and a recent connection to a massive supply-chain compromise in March 2026. Their operation, linked to the TA-NATALSTATUS activity, involved a sophisticated deployment framework and shared infrastructure.

Oracle Exploited: Attackers Turn SQL Injection into Windows SYSTEM Access
Attackers have successfully exploited a SQL injection vulnerability to gain unprecedented access to Oracle databases, converting it into a Windows SYSTEM-level access with alarming ease. This rare and sophisticated technique has allowed hackers to deploy a custom toolkit, dubbed khunt, that turns database-stored Java into a powerful post-exploitation tool.

China-Linked Hackers Exploit Vulnerabilities in Record Time
China-linked hackers, specifically Vault Panda and Genesis Panda, are exploiting vulnerabilities at lightning-fast speeds, rapidly validating and weaponizing newly disclosed flaws into active intrusions. This swift response highlights their sophisticated approach to staying ahead of the constantly changing attack surface.

Microsoft Exposes Russian Spies' Wi-Fi Malware Ploy
Microsoft uncovered a sneaky malware plot by Russian spies, who turned Wi-Fi networks at hotels and conference centers into a backdoor to steal valuable credentials and gain access to victims' cloud environments. The clever attack, attributed to the notorious SVR's Midnight Blizzard group, went undetected for months.

Chinese Hackers Target Central Asian Governments with OctLurk and SilkLurk Malware
Chinese hackers have launched a stealthy cyberattack on government organizations across six Central Asian countries, infiltrating ministries, hospitals, and schools with sophisticated malware. The targeted countries include Afghanistan, Kyrgyzstan, Tajikistan, Uzbekistan, Kazakhstan, and the Syrian Arab Republic.

Mirage Kitten Unveils New Malware Arsenal for Middle East Espionage
Mirage Kitten hackers have unleashed a potent new malware arsenal targeting the Middle East, threatening aerospace, aviation, defense, and telecom organizations with stealthy backdoors and tunnelers that enable covert surveillance and data relay. Their latest Windows backdoor, NightLedger, masquerades as a legitimate system file to infiltrate and gather intel.