Skip to main content

Tag: espionage

223 articles

A somber government building interior with a torn or broken security badge on a table.

DIA Insider Pleads Guilty to Leaking Secrets to Foreign Spies

A DIA insider has pleaded guilty to leaking classified information to foreign spies, admitting to betraying his oath and putting national security at risk. The shocking case began with a single email in March 2025, sparking a months-long undercover operation that ultimately led to his arrest.

Analyst 207
Server room with rack-mounted equipment and a single empty rack with a severed Ethernet cable.

Signed Drivers Exposed to Abuse Microsoft Defender Driver Repurposed $10 Million Reward Offered AI Model Exploits Vulnerabilities RCE Flaws Discovered in Gogs, n8n

In a stunning example of old-school ingenuity, a team of investigators finally thwarted a sophisticated espionage campaign by doing something remarkably low-tech: cutting a cable to a compromised router in a Chicago data center. This bold move brought an end to months of digital detective work that had been stymied by the elusive threat actors.

Analyst 207
Government office in Central Asia with a laptop and papers on a desk, hinting at technology integration.

China-linked SilkParasite campaign targets Central Asia with custom RATs

Meet SilkParasite, a sneaky espionage operation linked to China that's been targeting government bodies in Central Asia with a custom arsenal of Remote Access Tools. This sophisticated campaign boasts seven unique RAT families, five of which have never been seen before, and hints at AI-assisted development.

Analyst 207
Empty server room with rows of equipment racks and monitoring stations.

Jewelbug APT Exploits Dual Agenda with Espionage and Crypto Fraud

Meet Jewelbug, a notorious APT group that's been pulling off a double heist - stealing sensitive info and swindling victims out of crypto - all from the same interconnected operation. Their massive haul includes over 1 million implant check-ins and 580,000 stolen cookies, with targets spanning government systems and service providers across the Middle East, Southeast Asia, and South Asia.

Analyst 207
Government building exterior with subtle hint of computer infrastructure.

Jewelbug Hacker Group Exposes Dual Threat of Espionage and Crypto Fraud

Meet Jewelbug, a China-based hacker group that's been wreaking havoc with a dual threat of espionage and crypto fraud, leaving a trail of over a million compromised implant check-ins and thousands of stolen credentials in its wake. By cleverly injecting a single malicious script into a shared webmail template, Jewelbug gained write access to sensitive government webmail accounts, making off with valuable data.

Analyst 207
A laptop sits alone on a table in front of a blurred background of computer workstations and servers.

CAV3RN Espionage Framework Evolves With Google Apps Script C2 Relay

Meet the sneaky CAV3RN Espionage Framework, which just got a clever upgrade - it can now use Google Apps Script as a relay to secretly communicate with its controllers, all while hiding in plain sight within DNS traffic. This clever tactic lets the malware decide on a per-transaction basis whether to connect directly to its masters or take a detour through Google's services.

Analyst 207
A cluttered server room with rows of computer servers and networking equipment, highlighting a single organized server.

Kimsuky Bolsters Phishing Arsenal with Offline AI Infrastructure

North Korean hackers Kimsuky are taking phishing to the next level by leveraging offline AI infrastructure, a deliberate move to supercharge their espionage capabilities. Genians, a South Korean security firm, uncovered evidence of language-model tools like Ollama and GPT4All being installed and run on Kimsuky's servers.

Analyst 207
Government ministry office with laptop, papers, and cityscape view through large window.

Chinese Cyber-Attacks Expose Central Asian Governments to Espionage.

Since January 2025, a sneaky cyber-attack campaign has been targeting government organizations across Central Asia, with victims in six countries, including Afghanistan, Kazakhstan, and Uzbekistan. The attacks, involving customized malware, have hit a wide range of sectors, from healthcare and research to law enforcement and education.

Analyst 207
Server room with computer equipment, cables, and rack in a government or corporate office setting.

Russia-Aligned TA488 Exploits Outlook Web Access With Persistent Implant

A Russia-aligned espionage group, known as TA488, has launched a sophisticated attack using a half-click backdoor, exploiting a flaw in Outlook Web Access to deploy a persistent implant. This new implant, dubbed OWAReaper, allows the group to maintain server-side access, marking a significant escalation in their cyber operations.

Analyst 207
Dimly lit server room with rows of computer servers and equipment, hinting at covert cyber operations.

Iranian Hackers Deploy NightLedger Backdoor in Global Espionage Campaign

Meet NightLedger, a sneaky new Windows backdoor that's part of a sophisticated espionage toolkit used by Iranian hackers to secretly infiltrate and gather intel from targets worldwide. This powerful tool enables hackers to execute commands, capture screenshots, and operate undetected, putting organizations in the Middle East, Africa, and South Asia on high alert.

Analyst 207
Laptop on office desk shows Microsoft 365 calendar with blurred cityscape in background.

Malware Hides in Microsoft 365 Calendars via HOLLOWGRAPH Campaign

Meet HOLLOWGRAPH, a sneaky malware that's hiding in plain sight - using Microsoft 365 calendars to pull off a highly targeted espionage threat. This compact implant is reading and writing secret messages, all while masquerading as a harmless calendar event.

Analyst 207
Military logistics area under surveillance by IP cameras in Ukraine.

Russian Hackers Exploit IP Cameras to Spy on NATO, Ukraine Military Logistics

Russian hackers are exploiting internet-connected security cameras to spy on NATO and Ukraine's military logistics, with over 87,000 cameras across the EU and Ukraine vulnerable to a known exploit. This alarming operation, revealed by Dutch intelligence, has left sensitive sites exposed to Russian surveillance.

Analyst 207
Formal office setting with laptop, papers, and pen on a desk near a window overlooking a cityscape.

GoSerpent Malware Targets Southeast Asian Governments for Espionage

A stealthy cyber threat, known as GoSerpent, has been secretly targeting Southeast Asian governments and diplomats since late 2025, with the goal of gathering sensitive intelligence. This sophisticated malware has been evolving, with a new set of malicious tools deployed as recently as May 2026.

Analyst 207
Cluttered workspace with laptop and technical instruments in a modern research facility.

Microsoft Exposes GigaWiper Malware's Dual Espionage, Destructive Capabilities

Microsoft researchers have uncovered a highly sophisticated malware, GigaWiper, that masterfully combines espionage and destructive capabilities, allowing threat actors to operate efficiently and wreak havoc on infected systems. This multi-purpose backdoor enables attackers to quietly gather intel while packing a punch with its suite of destructive options.

Analyst 207
Living room with smart TV and streaming box, cityscape visible through window.

Google Disrupts Massive NetNut Residential Proxy Network

Google's Threat Intelligence Group has made a significant dent in the massive NetNut residential proxy network, estimated to comprise at least 2 million home devices worldwide, by partnering with the FBI, Lumen, and other allies to reduce its pool of usable devices by millions. This disruption targeted a network used by both cybercriminal and espionage groups.

Analyst 207
Government building stands under bright sunlight with a hint of unease.

Google Uncovers China Espionage Group UNC6508 Lurking Undetected Since 2023

Google's Threat Intelligence Group has uncovered a stealthy Chinese espionage group, UNC6508, that had been secretly lurking in networks since 2023, targeting key sectors in the US and Canada. The full extent of the damage is still unknown, leaving experts concerned about potential long-term security breaches.

Analyst 207
Brightly-lit hospital corridor with medical equipment, computers, and researchers in the distance.

Chinese hackers breach medical research servers with custom malware

Malicious hackers linked to China breached a North American medical research institution, hiding undetected for over a year and gaining access to sensitive research areas. The attackers used custom malware, known as Infinitered, with broad capabilities to siphon off valuable intel from September 2023 to November 2025.

Analyst 207
Hospital corridor with laptop in foreground, natural light through large windows.

Chinese Spies Exploit Medical, Military Networks for Over a Year

Google's Threat Intelligence Group uncovered a sneaky espionage campaign by Chinese spies that infiltrated medical and military networks in North America for over a year, making off with a treasure trove of sensitive data. The group, tracked as UNC6508, targeted top medical providers, academic centers, and military organizations, leaving no stone unturned in their quest for classified information.

Analyst 207
Person browsing on a laptop in a busy coffee shop with blurred background.

China Exploits Job Sites for Spying on Five Eyes Targets

Be cautious on job sites - Chinese spies are posing as recruiters on LinkedIn, Indeed, and Upwork to trick Five Eyes targets into divulging sensitive information. They're using clever social engineering tactics to make their scams seem all too believable.

Analyst 207
Researchers in lab coats work in a modern laboratory with a mix of old and new architecture.

US Research Security Landscape Evolves Amid Foreign Exploitation Fears

Join a live webinar on June 24, 2026, to explore how the Pentagon's new emphasis on research security is transforming the way universities, government agencies, and institutions protect against foreign exploitation. Earn 1 CPE credit while learning how to bolster defenses for basic and applied research in a rapidly evolving security landscape.

Analyst 207
Compromised web server in a data center with a focus on the targeted server on a rack.

China-Linked OP-512 Targets IIS Servers with Custom Web Shells

Meet OP-512, a China-linked threat cluster with a taste for espionage, recently caught targeting IIS servers with custom web shells in a stealthy bid for sensitive intel. This sneaky operation aligns with China's intelligence priorities, putting certain sectors and geographies firmly in its crosshairs.

Analyst 207
Person sitting at desk with laptop and smartphone, looking concerned amidst papers and notes.

China Exploits Job Platforms to Recruit State Secret Leakers

MI5 warns that China's military intelligence is using popular job platforms like LinkedIn, Indeed, and Upwork to recruit individuals with access to classified information, targeting those in foreign policy, defence, and other sensitive fields. The goal is to gather privileged military, political, and economic intelligence.

Analyst 207
Cramped network closet with equipment and cables, and a single laptop in the foreground.

Chinese hackers infiltrate telcos with Showboat, JFMBackdoor malware

Chinese-aligned hackers have been secretly infiltrating telecommunications providers across Asia Pacific and the Middle East since mid-2022, using sneaky malware like Showboat and JFMBackdoor to stay under the radar. They even used a clever "hide" command to conceal their digital footprints on infected machines.

Analyst 207
Office building lobby with blurred security camera and people walking, hint of network connection on screen.

Mustang Panda Deploys Updated FDMTP Backdoor in Asia-Pacific Espionage

A sophisticated espionage campaign has been targeting organizations across Asia-Pacific and Japan for months, with researchers linking the activity to the notorious China-aligned group Mustang Panda with moderate confidence. The group's tactics may evolve, but their execution model remains eerily consistent.

Analyst 207