Tag

#APT

14 stories taggedAPT.

A computer server room with glowing neural network visualizations on displays, an open access panel revealing circuitry, and a shadowy figure's hand reaching to
Threat Intelligence

Spies and Criminals Are Stealing AI Systems, Not Just Data

Google's threat research team says nation-state hackers and extortion gangs are now going after the AI models, cloud accounts, and secret access keys that companies use to run artificial intelligence, turning those stolen assets into weapons for their own attacks.

4 min read
An FBI field office with law enforcement and cyber agents gathered around seized server equipment, network diagrams showing connections to targeted government a
Threat Intelligence

The US just seized the servers behind China's hacking-for-hire empire

A private Chinese company quietly ran shared attack tools for state hackers targeting NASA, the Federal Reserve, and US hospitals. The FBI just pulled the plug.

5 min read
A computer terminal displaying encrypted command-line output and network packet traces, with shadowy server rack infrastructure visible in the background sugges
Threat Intelligence

Iran's Nimbus Manticore Adds New Backdoor and SSH Tunneler to Spy Kit

Group-IB says the IRGC-linked hackers have quietly built out fresh infrastructure and custom malware for espionage campaigns in 2026.

3 min read
Split-screen digital representation showing cryptocurrency exchange data on one side and government email infrastructure on the other, both displaying intrusion
Threat Intelligence

Meet Jewelbug: The Chinese Hacker-for-Hire Group Stealing Crypto and Spying on Governments at the Same Time

A single criminal outfit runs a massive cryptocurrency scam network with one hand and breaks into Middle Eastern government email systems with the other. Researchers say the group almost certainly works for China.

4 min read
A nighttime cityscape of Central Asian architecture with surveillance camera feeds displayed as overlaid windows, digital map markers indicating targeted locati
Threat Intelligence

Chinese-Speaking Hackers Hit Central Asian Governments With Two New Malware Families

Researchers link a spying campaign against Afghanistan, Kyrgyzstan and four neighbouring states to a Chinese-speaking crew using tools tracked as OctLurk and SilkLurk.

4 min read
The Las Vegas Strip at night with conference center marquees and security researchers walking through lobbies with credential badges visible, neon reflections o
AI Security

Black Hat 2025: Five things worth your time, and the traps to avoid

The Las Vegas conference still produces genuinely useful research. Getting to it means ignoring a lot of expensive noise.

3 min read
A computer screen displaying an opened email in a webmail interface, with malicious code invisibly executing in the background, represented by subtle system pro
Vulnerabilities

Russian Hackers Are Reading Your Email Just by Sending You One: Zimbra Zero-Day Explained

A Kremlin-linked crew tracked as LAUNDRY BEAR is exploiting CVE-2025-66376 in Zimbra webmail to steal 90 days of email the moment a victim opens a booby-trapped message.

4 min read
Illustration: a dimly lit server room in a Russian government building
Threat Intelligence

Hackers hijack Russian security tool ViPNet to spy on government agencies

A campaign called HelloNet has been slipping malicious files into ViPNet updates since May, hitting Russian ministries, energy firms and transport operators.

3 min read
Illustration: a dimly lit government office at night in Southeast Asia
Threat Intelligence

GoSerpent: A New Espionage Tool Quietly Targeting Southeast Asian Governments

Kaspersky says the previously unseen malware has been hitting government and diplomatic offices across the region since late 2025, with signs pointing to long-term spying rather than smash-and-grab theft.

3 min read
A dimly lit government office at night, rows of empty desks with old CRT and flat-screen monitors glowing faintly with generic login prompts, a single overhead
Threat Intelligence

Suspected Chinese and Indian Spies Both Targeted Pakistani Police, Researchers Say

A two-year campaign hit Balochistan Police and other law enforcement bodies, with servers holding criminal records among the compromised assets.

3 min read
Illustration: a darkened data center corridor with a single amber warning light reflecting off polished server racks
Threat Intelligence

ToddyCat's New Umbrij Malware Pulls Gmail Straight From Google's API

Kaspersky ties the China-nexus crew to a Gmail-siphoning tool that skips the browser and talks to Google directly.

3 min read
Illustration: a dim government-
Threat Intelligence

SharkLoader Drops Cobalt Strike on Asian Government Targets in 'StrikeShark' Campaign

A previously undocumented loader is being used against a diplomatic office in Indonesia and government bodies in Taiwan, with operators staging Cobalt Strike Beacon as the final payload.

3 min read
Illustration: a dimly lit server rack room with cool blue and amber LED indicators reflecting off polished dark floor tiles
Threat Intelligence

Turla's STOCKSTAY: A Fresh .NET Backdoor Aimed at Kyiv and Rome

Google's threat hunters tie the Russian FSB-linked crew to a previously undocumented Windows implant hitting Ukrainian military targets and Italy-focused diplomatic entities.

3 min read
Illustration: tangled ethernet cables and server rack indicator lights glowing amber and green in a darkened data center
Vulnerabilities

Briefing: Apple Fixes Beats Bug, GCP Config Connector Flaw Enables Account Takeover, Velvet Ant's Decade in the Shadows

A Bluetooth eavesdropping patch, a quietly dangerous GCP authorization flaw, and a threat actor that spent ten years undetected, here is what you may have missed.

3 min read
© 2026 Threat Vectr