Thursday, October 8, 2026

APT

Chinese APT Clones Legitimate Websites to Deliver Chrome and Windows Zero-Day Exploits

A third Chinese threat actor has been linked to phishing campaigns that cloned trusted websites and chained Chrome and Windows zero-day exploits to deploy a previously undocumented backdoor. The...

BlackTech APT Uses New BlueShell Linux Backdoor in Attacks on Japanese Organizations

BlackTech, a long-running China-aligned APT group, has adopted a new Linux backdoor built on the BlueShell open-source RAT to conduct post-intrusion operations against Japanese...

Armored Likho APT Deploys BusySnake Stealer Against Government and Power Sector Targets

A focused phishing campaign operated by a previously unreported APT we’ve named Armored Likho (also tracked under the provisional alias Eagle Werewolf). The group...

Chinese Cyber Operations Shift From APT Groups to Composite Responsibility Model

Chinese state-linked cyber activity has moved decisively away from the neat, single-actor narratives that dominated early attribution toward an ecosystem model in which responsibility...

Ghostwriter APT Uses Fake Gmail Login Panels to Steal Passwords and 2FA Codes

Ghostwriter (UNC1151) has escalated its long-standing phishing operations by deploying convincing fake Gmail login panels that harvest both passwords and two-factor authentication (2FA) codes,...

GRU-Linked APT28 Uses MooBot Botnet and Compromised EdgeRouters for Cyber Operations

A notable operational pivot by the GRU-linked intrusion set APT28 (aka Fancy Bear, Sofacy, Forest Blizzard, Pawn Storm) that combines the MooBot botnet and...

Chinese APT VerdantBamboo Targets Appliances with BRICKSTORM Malware

BRICKSTORM is a modular remote access trojan (RAT) originally seen in Golang and later in Rust. It uses a wssoft library with pluggable “tasks”...

Nimbus Manticore APT Uses Fake Jobs to Deliver Custom Malware

A newly observed cyber campaign linked to the Iran-aligned threat group Nimbus Manticore (also tracked as UNC1549 and Smoke Sandstorm) is targeting aerospace and...

APT Group Patches termsrv.dll to Enable Multiple RDP Sessions

A sustained cyber espionage campaign attributed to the Cloud Atlas advanced persistent threat (APT) group has introduced a stealthy technique that modifies the Windows...

Iranian APT Uses SEO Poisoning to Spread Fake SQL Developer Malware

A newly observed cyber campaign linked to the Iranian IRGC-affiliated threat group Nimbus Manticore (also tracked as UNC1549) highlights an evolution in both delivery...

Paper Werewolf APT Spreads EchoGather RAT via Fake Adobe Installer

A sophisticated Russian-language threat cluster known as Paper Werewolf (also tracked as GOFFEE) has launched a fresh wave of targeted cyberattacks against Russian industrial, financial, and...