Nation-state hacking, APT groups, intelligence operations, and geopolitical cyber activity.
Iranian Hackers Use Telegram-Controlled Malware to Spy on Dissidents and Journalists
US, UK, and Dutch cybersecurity agencies have exposed a Windows malware deployed by Iran's intelligence service to conduct surveillance on dissidents,…
Cyber Op Targets South Korean Media & Automotive Sectors
# North Korean APT Deploys Novel Linux Espionage Toolkit Against South Korean Infrastructure A North Korean-linked advanced persistent threat group d…
Russian State-Sponsored Hackers Use Claude to Rebuild Malware After Detection
Anthropic disclosed that Russian state-sponsored hackers exploited Claude, its AI assistant, to automate malware development and evasion. The threat a…
U.S. Disrupts Xinbi Guarantee Scam Marketplace, Freezes $52.8 Million in Crypto
The U.S. Department of Justice dismantled Xinbi Guarantee, a sophisticated online scam operation that facilitated fraud schemes across multiple contin…
US Government Accuses Chinese AI Firms of Distilling Frontier Models
US government officials have accused Chinese artificial intelligence companies of systematically extracting billions of tokens from leading Western AI…
U.S. Agencies Accuse China AI Firms of Distilling Claude, GPT, Gemini, and Grok
U.S. intelligence and cybersecurity agencies have formally accused Chinese artificial intelligence companies of systematically extracting proprietary …
Slim Spider Steals Crypto Custody Secrets From Brazilian Financial Institution
CrowdStrike researchers have identified a new financially motivated threat actor designated Slim Spider conducting targeted attacks against Brazilian …
Pegasus Zero-Click Spyware Exploit Infects Serbian Student Movement Member's iPhone
NSO Group's Pegasus spyware infected the iPhone of a Serbian student activist through a zero-click iMessage exploit, according to forensic analysis by…
North Korean Job Fraud Expands Beyond IT Into Healthcare and Sales
North Korean operatives are diversifying their employment fraud campaigns far beyond technology roles, now targeting healthcare, sales, and marketing …
DoJ Corrects China Hacking Claim, Says U.S. Agencies Were Targets, Not Victims
The U.S. Department of Justice withdrew a misleading statement about Chinese cyber operations targeting American government agencies, clarifying that …
China-Linked Fire Ant Hijacks Cisco Routers to Steal Credentials and Blind Security Logs
# China-Linked Fire Ant Campaign Targets Cisco Router Infrastructure for Credential Theft Fire Ant, a Chinese state-aligned cyber espionage group, ha…
APT28-Linked HOOKEDGE Backdoor Targets European Government and Diplomatic Organizations
Russian military intelligence unit GRU's cyber operations division tracked as APT28 has deployed a previously unknown backdoor called HOOKEDGE against…
Russian Hackers Phish EU Officials Over Messaging Apps
Russian nation-state threat actors have shifted their phishing operations away from traditional email channels toward encrypted messaging platforms, t…
FBI Disrupts China-Linked QTFY Infrastructure Used to Steal Data From U.S. Organizations
The FBI and Department of Justice disrupted two hacking platforms, QScan and QTRouter, that Chinese state-sponsored threat actors used to breach U.S. …
Nimbus Manticore Expands Toolset With TWOSTROKE-Like Backdoor and SSH Tunneler
Nimbus Manticore, an Iranian state-sponsored hacking group with ties to the Islamic Revolutionary Guard Corps (IRGC), has expanded its malware arsenal…
OpenAI Bans Russian ChatGPT Accounts Used to Run Influence Operation
OpenAI terminated Russian accounts operating under false pretenses to conduct a coordinated influence campaign across multiple social media platforms.…
INTERPOL Operation Jackal IV Arrests 58, Identifies 263 in Global Cyber Fraud Crackdown
INTERPOL coordinated a multinational operation that resulted in 58 arrests and identified 263 additional suspects involved in cyber fraud schemes link…
Red Flags That Expose Fake North Korean IT Workers
# How to Spot Fake North Korean IT Workers Before They Infiltrate Your Network North Korean-sponsored threat actors continue to infiltrate Western te…
Interpol's Jackal IV Disrupts West African Crime Infrastructure
Interpol launched Operation Jackal IV, a coordinated international enforcement action targeting West African cybercriminal networks operating as crime…
U.S. Sanctions Iran-Linked Hackers Behind Critical Infrastructure Breaches
The U.S. Treasury Department imposed new sanctions on Iranian cyber actors linked to breaches of American critical infrastructure targets. The action …
Operation QUICSILVER Targets Myanmar Government and IT with QUICAgent Backdoor
Seqrite Labs researchers have uncovered a targeted cyber espionage campaign against Myanmar's government and IT sectors that exploits social engineeri…
SilkParasite Threatens Central Asian Orgs With Flurry of RATs
# China-Linked SilkParasite Group Deploys Multiple RATs Against Central Asian Organizations A coordinated spear-phishing campaign attributed to SilkP…
Pakistan's Transparent Tribe Refreshes Toolset for Afghan Cyberattacks
Pakistan-linked nation-state hackers operating under the moniker Transparent Tribe continue refining their attack capabilities, with fresh evidence sh…
SilkParasite Espionage Campaign Targets Central Asian Governments with Five New RATs
Researchers identified a previously unknown espionage campaign targeting Central Asian government entities. The operation, tracked as SilkParasite, de…
'Jewelbug' APT Balances State Espionage & Cryptocurrency Theft
# 'Jewelbug' APT Operates Dual-Purpose Cyber Operation Spanning State Espionage and Cryptocurrency Theft Security researchers have uncovered evidence…
Lazarus Exploits Windows Zero-Day to Gain SYSTEM Access and Deploy Backdoor
North Korea's Lazarus Group exploited an unpatched Windows zero-day vulnerability to establish persistence on systems belonging to defense and aerospa…
Sandworm-Linked UAC-0145 Uses Fake Job Interviews to Push VPN That Can Run Commands
CERT-UA has exposed a targeted social engineering campaign by UAC-0145, a Sandworm subgroup linked to Russian state actors, targeting Ukrainian IT wor…