Tag

#APT

15 stories taggedAPT.

Full-frame photoreal editorial image of a dimly lit government office at night in Southeast Asia, empty desk with a glowing monitor showing abstract green code
Threat Intelligence

Meet Jewelbug: The Chinese Hacker-for-Hire Group Stealing Crypto and Spying on Governments at the Same Time

A single criminal outfit is running a massive cryptocurrency scam network with one hand and breaking into Middle Eastern government email systems with the other. Researchers say the group almost certainly works for China.

3 min read
Full-frame photoreal editorial image of a dimly lit government office at night in Southeast Asia, empty desk with a glowing monitor showing abstract green code
Threat Intelligence

Chinese-Speaking Hackers Hit Central Asian Governments With Two New Malware Families

Researchers link a spying campaign against Afghanistan, Kyrgyzstan and neighbours to a Chinese-speaking crew using tools tracked as OctLurk and SilkLurk.

3 min read
Photoreal editorial shot of a dimly lit server room corridor with a single illuminated rack door slightly ajar, soft blue and amber LEDs reflecting off polished
AI Security

Black Hat 2025: Five things worth your time, and the traps to avoid

The Las Vegas conference still produces genuinely useful research. Getting to it means ignoring a lot of expensive noise.

3 min read
Photoreal editorial shot of a laptop screen glowing in a dim office, showing a generic webmail inbox interface with one email highlighted, faint reflection of c
Vulnerabilities

Russian Hackers Are Reading Your Email Just by Sending You One: Zimbra Zero-Day Explained

A Kremlin-linked crew tracked as LAUNDRY BEAR is exploiting CVE-2025-66376 in Zimbra webmail to steal 90 days of email the moment a victim opens a booby-trapped message.

4 min read
Photoreal editorial shot of a dimly lit server room in a Russian government building, rows of network equipment with faint green status lights, a single monitor
Threat Intelligence

Hackers hijack Russian security tool ViPNet to spy on government agencies

A campaign called HelloNet has been slipping malicious files into ViPNet updates since May, hitting Russian ministries, energy firms and transport operators.

3 min read
Full-frame photoreal editorial image of a dimly lit government office at night in Southeast Asia, empty desk with a glowing monitor showing abstract green code
Threat Intelligence

GoSerpent: A New Espionage Tool Quietly Targeting Southeast Asian Governments

Kaspersky says the previously unseen malware has been hitting government and diplomatic offices across the region since late 2025, with signs pointing to long-term spying rather than smash-and-grab theft.

3 min read
A dimly lit government office at night, rows of empty desks with old CRT and flat-screen monitors glowing faintly with generic login prompts, a single overhead
Threat Intelligence

Suspected Chinese and Indian Spies Both Targeted Pakistani Police, Researchers Say

A two-year campaign hit Balochistan Police and other law enforcement bodies, with servers holding criminal records among the compromised assets.

3 min read
Full-frame edge-to-edge photoreal editorial image of a darkened data center corridor with a single amber warning light reflecting off polished server racks, an
Threat Intelligence

ToddyCat's New Umbrij Malware Pulls Gmail Straight From Google's API

Kaspersky ties the China-nexus crew to a Gmail-siphoning tool that skips the browser and talks to Google directly.

3 min read
Threat Intelligence

SharkLoader Drops Cobalt Strike on Asian Government Targets in 'StrikeShark' Campaign

A previously undocumented loader is being used against a diplomatic office in Indonesia and government bodies in Taiwan, with operators staging Cobalt Strike Beacon as the final payload.

2 min read
Threat Intelligence

Turla's STOCKSTAY: A Fresh .NET Backdoor Aimed at Kyiv and Rome

Google's threat hunters tie the Russian FSB-linked crew to a previously undocumented Windows implant hitting Ukrainian military targets and Italy-focused diplomatic entities.

2 min read
Vulnerabilities

Briefing: Apple Fixes Beats Bug, GCP Config Connector Flaw Enables Account Takeover, Velvet Ant's Decade in the Shadows

A Bluetooth eavesdropping patch, a quietly dangerous GCP misconfiguration vulnerability, and a threat actor that spent ten years undetected — here's what you may have missed.

2 min read
Threat Intelligence

Velvet Ant Lived Inside PAM and OpenSSH for Nearly Ten Years

A China-nexus crew skipped the endpoints defenders actually watch and backdoored the Linux login stack itself, where IR runbooks rarely reach.

3 min read
Threat Intelligence

FBI Dismantles 13 Sites Tied to Chinese Influence Operation Targeting Cleared US Personnel

The seized domains posed as consulting firms advertising jobs — a tradecraft pattern consistent with state-directed recruitment campaigns against intelligence community insiders.

2 min read
Threat Intelligence

Five Eyes Warns: Chinese Intelligence Officers Posing as Recruiters to Harvest Government Secrets

A joint advisory flags a persistent social engineering campaign targeting personnel with access to classified material — fake job offers, real espionage.

2 min read
Breaches

Lithuania Probes Foreign Hand in Leak of 600,000-Plus National Register Records

Lithuanian authorities suspect state-linked actors after a data breach exposed more than 600,000 entries from government population and registration databases.

2 min read
© 2026 Threat Vectr