Tag: espionage
223 articles

DIA Insider Pleads Guilty to Leaking Secrets to Foreign Spies
A DIA insider has pleaded guilty to leaking classified information to foreign spies, admitting to betraying his oath and putting national security at risk. The shocking case began with a single email in March 2025, sparking a months-long undercover operation that ultimately led to his arrest.

Signed Drivers Exposed to Abuse Microsoft Defender Driver Repurposed $10 Million Reward Offered AI Model Exploits Vulnerabilities RCE Flaws Discovered in Gogs, n8n
In a stunning example of old-school ingenuity, a team of investigators finally thwarted a sophisticated espionage campaign by doing something remarkably low-tech: cutting a cable to a compromised router in a Chicago data center. This bold move brought an end to months of digital detective work that had been stymied by the elusive threat actors.

China-linked SilkParasite campaign targets Central Asia with custom RATs
Meet SilkParasite, a sneaky espionage operation linked to China that's been targeting government bodies in Central Asia with a custom arsenal of Remote Access Tools. This sophisticated campaign boasts seven unique RAT families, five of which have never been seen before, and hints at AI-assisted development.

Jewelbug APT Exploits Dual Agenda with Espionage and Crypto Fraud
Meet Jewelbug, a notorious APT group that's been pulling off a double heist - stealing sensitive info and swindling victims out of crypto - all from the same interconnected operation. Their massive haul includes over 1 million implant check-ins and 580,000 stolen cookies, with targets spanning government systems and service providers across the Middle East, Southeast Asia, and South Asia.

Jewelbug Hacker Group Exposes Dual Threat of Espionage and Crypto Fraud
Meet Jewelbug, a China-based hacker group that's been wreaking havoc with a dual threat of espionage and crypto fraud, leaving a trail of over a million compromised implant check-ins and thousands of stolen credentials in its wake. By cleverly injecting a single malicious script into a shared webmail template, Jewelbug gained write access to sensitive government webmail accounts, making off with valuable data.

CAV3RN Espionage Framework Evolves With Google Apps Script C2 Relay
Meet the sneaky CAV3RN Espionage Framework, which just got a clever upgrade - it can now use Google Apps Script as a relay to secretly communicate with its controllers, all while hiding in plain sight within DNS traffic. This clever tactic lets the malware decide on a per-transaction basis whether to connect directly to its masters or take a detour through Google's services.

Kimsuky Bolsters Phishing Arsenal with Offline AI Infrastructure
North Korean hackers Kimsuky are taking phishing to the next level by leveraging offline AI infrastructure, a deliberate move to supercharge their espionage capabilities. Genians, a South Korean security firm, uncovered evidence of language-model tools like Ollama and GPT4All being installed and run on Kimsuky's servers.

Chinese Cyber-Attacks Expose Central Asian Governments to Espionage.
Since January 2025, a sneaky cyber-attack campaign has been targeting government organizations across Central Asia, with victims in six countries, including Afghanistan, Kazakhstan, and Uzbekistan. The attacks, involving customized malware, have hit a wide range of sectors, from healthcare and research to law enforcement and education.

Russia-Aligned TA488 Exploits Outlook Web Access With Persistent Implant
A Russia-aligned espionage group, known as TA488, has launched a sophisticated attack using a half-click backdoor, exploiting a flaw in Outlook Web Access to deploy a persistent implant. This new implant, dubbed OWAReaper, allows the group to maintain server-side access, marking a significant escalation in their cyber operations.

Iranian Hackers Deploy NightLedger Backdoor in Global Espionage Campaign
Meet NightLedger, a sneaky new Windows backdoor that's part of a sophisticated espionage toolkit used by Iranian hackers to secretly infiltrate and gather intel from targets worldwide. This powerful tool enables hackers to execute commands, capture screenshots, and operate undetected, putting organizations in the Middle East, Africa, and South Asia on high alert.

Malware Hides in Microsoft 365 Calendars via HOLLOWGRAPH Campaign
Meet HOLLOWGRAPH, a sneaky malware that's hiding in plain sight - using Microsoft 365 calendars to pull off a highly targeted espionage threat. This compact implant is reading and writing secret messages, all while masquerading as a harmless calendar event.

Russian Hackers Exploit IP Cameras to Spy on NATO, Ukraine Military Logistics
Russian hackers are exploiting internet-connected security cameras to spy on NATO and Ukraine's military logistics, with over 87,000 cameras across the EU and Ukraine vulnerable to a known exploit. This alarming operation, revealed by Dutch intelligence, has left sensitive sites exposed to Russian surveillance.

GoSerpent Malware Targets Southeast Asian Governments for Espionage
A stealthy cyber threat, known as GoSerpent, has been secretly targeting Southeast Asian governments and diplomats since late 2025, with the goal of gathering sensitive intelligence. This sophisticated malware has been evolving, with a new set of malicious tools deployed as recently as May 2026.

Microsoft Exposes GigaWiper Malware's Dual Espionage, Destructive Capabilities
Microsoft researchers have uncovered a highly sophisticated malware, GigaWiper, that masterfully combines espionage and destructive capabilities, allowing threat actors to operate efficiently and wreak havoc on infected systems. This multi-purpose backdoor enables attackers to quietly gather intel while packing a punch with its suite of destructive options.

Google Disrupts Massive NetNut Residential Proxy Network
Google's Threat Intelligence Group has made a significant dent in the massive NetNut residential proxy network, estimated to comprise at least 2 million home devices worldwide, by partnering with the FBI, Lumen, and other allies to reduce its pool of usable devices by millions. This disruption targeted a network used by both cybercriminal and espionage groups.

Google Uncovers China Espionage Group UNC6508 Lurking Undetected Since 2023
Google's Threat Intelligence Group has uncovered a stealthy Chinese espionage group, UNC6508, that had been secretly lurking in networks since 2023, targeting key sectors in the US and Canada. The full extent of the damage is still unknown, leaving experts concerned about potential long-term security breaches.

Chinese hackers breach medical research servers with custom malware
Malicious hackers linked to China breached a North American medical research institution, hiding undetected for over a year and gaining access to sensitive research areas. The attackers used custom malware, known as Infinitered, with broad capabilities to siphon off valuable intel from September 2023 to November 2025.

Chinese Spies Exploit Medical, Military Networks for Over a Year
Google's Threat Intelligence Group uncovered a sneaky espionage campaign by Chinese spies that infiltrated medical and military networks in North America for over a year, making off with a treasure trove of sensitive data. The group, tracked as UNC6508, targeted top medical providers, academic centers, and military organizations, leaving no stone unturned in their quest for classified information.

China Exploits Job Sites for Spying on Five Eyes Targets
Be cautious on job sites - Chinese spies are posing as recruiters on LinkedIn, Indeed, and Upwork to trick Five Eyes targets into divulging sensitive information. They're using clever social engineering tactics to make their scams seem all too believable.

US Research Security Landscape Evolves Amid Foreign Exploitation Fears
Join a live webinar on June 24, 2026, to explore how the Pentagon's new emphasis on research security is transforming the way universities, government agencies, and institutions protect against foreign exploitation. Earn 1 CPE credit while learning how to bolster defenses for basic and applied research in a rapidly evolving security landscape.

China-Linked OP-512 Targets IIS Servers with Custom Web Shells
Meet OP-512, a China-linked threat cluster with a taste for espionage, recently caught targeting IIS servers with custom web shells in a stealthy bid for sensitive intel. This sneaky operation aligns with China's intelligence priorities, putting certain sectors and geographies firmly in its crosshairs.

China Exploits Job Platforms to Recruit State Secret Leakers
MI5 warns that China's military intelligence is using popular job platforms like LinkedIn, Indeed, and Upwork to recruit individuals with access to classified information, targeting those in foreign policy, defence, and other sensitive fields. The goal is to gather privileged military, political, and economic intelligence.

Chinese hackers infiltrate telcos with Showboat, JFMBackdoor malware
Chinese-aligned hackers have been secretly infiltrating telecommunications providers across Asia Pacific and the Middle East since mid-2022, using sneaky malware like Showboat and JFMBackdoor to stay under the radar. They even used a clever "hide" command to conceal their digital footprints on infected machines.

Mustang Panda Deploys Updated FDMTP Backdoor in Asia-Pacific Espionage
A sophisticated espionage campaign has been targeting organizations across Asia-Pacific and Japan for months, with researchers linking the activity to the notorious China-aligned group Mustang Panda with moderate confidence. The group's tactics may evolve, but their execution model remains eerily consistent.