#APT
15 stories taggedAPT.

Meet Jewelbug: The Chinese Hacker-for-Hire Group Stealing Crypto and Spying on Governments at the Same Time
A single criminal outfit is running a massive cryptocurrency scam network with one hand and breaking into Middle Eastern government email systems with the other. Researchers say the group almost certainly works for China.

Chinese-Speaking Hackers Hit Central Asian Governments With Two New Malware Families
Researchers link a spying campaign against Afghanistan, Kyrgyzstan and neighbours to a Chinese-speaking crew using tools tracked as OctLurk and SilkLurk.

Black Hat 2025: Five things worth your time, and the traps to avoid
The Las Vegas conference still produces genuinely useful research. Getting to it means ignoring a lot of expensive noise.

Russian Hackers Are Reading Your Email Just by Sending You One: Zimbra Zero-Day Explained
A Kremlin-linked crew tracked as LAUNDRY BEAR is exploiting CVE-2025-66376 in Zimbra webmail to steal 90 days of email the moment a victim opens a booby-trapped message.

Hackers hijack Russian security tool ViPNet to spy on government agencies
A campaign called HelloNet has been slipping malicious files into ViPNet updates since May, hitting Russian ministries, energy firms and transport operators.

GoSerpent: A New Espionage Tool Quietly Targeting Southeast Asian Governments
Kaspersky says the previously unseen malware has been hitting government and diplomatic offices across the region since late 2025, with signs pointing to long-term spying rather than smash-and-grab theft.

Suspected Chinese and Indian Spies Both Targeted Pakistani Police, Researchers Say
A two-year campaign hit Balochistan Police and other law enforcement bodies, with servers holding criminal records among the compromised assets.

ToddyCat's New Umbrij Malware Pulls Gmail Straight From Google's API
Kaspersky ties the China-nexus crew to a Gmail-siphoning tool that skips the browser and talks to Google directly.

SharkLoader Drops Cobalt Strike on Asian Government Targets in 'StrikeShark' Campaign
A previously undocumented loader is being used against a diplomatic office in Indonesia and government bodies in Taiwan, with operators staging Cobalt Strike Beacon as the final payload.

Turla's STOCKSTAY: A Fresh .NET Backdoor Aimed at Kyiv and Rome
Google's threat hunters tie the Russian FSB-linked crew to a previously undocumented Windows implant hitting Ukrainian military targets and Italy-focused diplomatic entities.

Briefing: Apple Fixes Beats Bug, GCP Config Connector Flaw Enables Account Takeover, Velvet Ant's Decade in the Shadows
A Bluetooth eavesdropping patch, a quietly dangerous GCP misconfiguration vulnerability, and a threat actor that spent ten years undetected — here's what you may have missed.

Velvet Ant Lived Inside PAM and OpenSSH for Nearly Ten Years
A China-nexus crew skipped the endpoints defenders actually watch and backdoored the Linux login stack itself, where IR runbooks rarely reach.

FBI Dismantles 13 Sites Tied to Chinese Influence Operation Targeting Cleared US Personnel
The seized domains posed as consulting firms advertising jobs — a tradecraft pattern consistent with state-directed recruitment campaigns against intelligence community insiders.

Five Eyes Warns: Chinese Intelligence Officers Posing as Recruiters to Harvest Government Secrets
A joint advisory flags a persistent social engineering campaign targeting personnel with access to classified material — fake job offers, real espionage.

Lithuania Probes Foreign Hand in Leak of 600,000-Plus National Register Records
Lithuanian authorities suspect state-linked actors after a data breach exposed more than 600,000 entries from government population and registration databases.