Tag

#espionage

31 stories taggedespionage · page 2 of 3.

Photoreal editorial shot of a laptop screen glowing in a dim office, showing a generic webmail inbox interface with one email highlighted, faint reflection of c
Vulnerabilities

Zimbra Patches Critical Webmail Flaw That Lets Booby-Trapped Emails Run Code

A stored cross-site scripting bug in Zimbra's Classic Web Client can hijack a user's session the moment a rigged email is opened.

3 min read
Photoreal news-editorial image, 16:9, full frame edge to edge
Threat Intelligence

China-linked hackers hit university email servers to spy on physics and defence researchers

A group tracked as UNK_MassTraction is exploiting two Roundcube flaws at U.S. and Canadian universities to steal logins and plant backdoors, Proofpoint says.

4 min read
A close-up, editorial-style photograph of a small black wireless router sitting on a plain wooden desk in a modest office, indicator lights glowing faintly gree
Threat Intelligence

Chinese Hacking Group Adds Three New Backdoors to Its Router Attack Kit

The group behind a long-running campaign targeting small office routers has quietly expanded its toolbox, giving it more ways to hide inside a victim's network.

3 min read
Photoreal news-editorial style, 16:9 framing, full-frame edge-to-edge composition
Threat Intelligence

Iran-Linked Hackers Hit Israeli IT Firms to Reach High-Value Targets

A group tied to Iran used a flexible, plug-in-style hacking toolkit to break into IT service providers in Israel, then moved through those companies to attack their clients.

2 min read
Full-frame photoreal editorial image of a dimly lit server room in an Israeli office building, blue and amber indicator lights reflecting on polished floor, a f
Threat Intelligence

Iranian Spies Target Israeli IT Firms With a New Custom Toolkit Called Cavern

A hacking crew tied to Iran's intelligence ministry is running a previously unseen command-and-control framework against Israeli government bodies and their IT suppliers.

3 min read
Threat Intelligence

Mustang Panda Turns Zoho WorkDrive Into C2 in Twin Campaigns Against Indian Government

The China-aligned crew is running parallel operations against New Delhi ministries and hydropower operators, abusing a legitimate cloud collaboration service to move commands past network defenses.

3 min read
Threat Intelligence

China-Nexus Crew Burrowed Into REDCap, Turned Google Workspace Rules Into an Exfil Pipe

A 13-plus-month intrusion across medical, academic, and defense research networks abused victim-side mail forwarding instead of dropping noisy C2.

2 min read
Threat Intelligence

Threat Actor 'Misere' Claims Breach of French Government Messaging Platform Tchap

Around 73,000 sovereign-platform accounts may be compromised. Attribution remains unclear, and the actor is not yet tied to a known cluster.

2 min read
Threat Intelligence

OP-512 Cluster Hits IIS Servers With Custom Web Shell Kit, Researchers Link Activity to China

A previously unreported intrusion set is dropping a bespoke web shell framework on Microsoft IIS servers, with espionage indicators pointing toward Beijing.

2 min read
Threat Intelligence

Five Eyes Warns: Chinese Intelligence Officers Posing as Recruiters to Harvest Government Secrets

A joint advisory flags a persistent social engineering campaign targeting personnel with access to classified material — fake job offers, real espionage.

2 min read
Threat Intelligence

Five-Month Outlook Intrusion at Global Stock Exchange Exfiltrated via Dropbox, OneDrive

Threat hunters say the executive's mailbox was siphoned in small batches over consumer cloud channels — a pattern consistent with state-aligned espionage rather than financially motivated crime.

3 min read
Threat Intelligence

Operation Dragon Weave Drops AdaptixC2 on Czech, Taiwanese Targets

Spear-phishing campaign hits government, academia, and finance with ZIP-borne lures and an open-source C2 framework.

2 min read
Threat Intelligence

Russia's Tech Embargo Run-Around: Shell Companies, Middlemen, and Embedded Spies

Western sanctions were supposed to starve Moscow's military-industrial base of critical components. Instead, Russian intelligence built a procurement machine to go get them anyway.

2 min read
Threat Intelligence

MuddyWater Targets Global Organizations with DLL Side-Loading

Iranian group MuddyWater exploits DLL side-loading in espionage affecting nine nations.

2 min read
Threat Intelligence

Showboat: A Modular Linux Backdoor Quietly Camped in a Middle East Telco Since 2022

Lumen's Black Lotus Labs ties the SOCKS5-capable implant to a years-long intrusion at a regional carrier, with an in-memory loader and ELF payloads that sidestep most host telemetry.

2 min read
© 2026 Threat Vectr