Secure Bulletin Navigating the cyber sea with knowledge
Home > Tag > APT
#APT

Decade-Old Noodle RAT Resurfaces, Now Hunting Both Windows and Linux Systems Across Asia

17 September 2026  |  dark6  |  Malware

Check Point researchers have tracked renewed activity from Noodle RAT, a cross-platform backdoor linked to Chinese-speaking threat actors and shared across multiple APT and cybercrime groups. Victims span...

>> read more

North Korean Hackers Hide ‘Ted’ Backdoor Inside Trojanized HAProxy to Spy on South Korean Firms

8 September 2026  |  dark6  |  Malware

Rapid7 researchers have uncovered a DPRK-linked Linux intrusion toolkit — built around a modified HAProxy binary dubbed Ted and a companion remote access tool called CurlRAT — that...

>> read more

FBI Dismantles Chinese State-Sponsored Botnet That Powered a Global Hacking Platform

28 August 2026  |  dark6  |  Cybercrime

The FBI and Department of Justice have seized the domains behind QScan and QTRouter, a pair of linked platforms that a Chinese state-sponsored group allegedly used to hijack...

>> read more

Chinese Threat Group Automates Web Server Attacks at Scale Using AI Agents, Cisco Talos Warns

22 August 2026  |  dark6  |  Cybercrime

Cisco Talos has tracked a Chinese-speaking group known as UAT-10147 using AI-generated scripts and playbooks to automate reconnaissance and exploitation across roughly 170,000 URLs. The campaign hit government,...

>> read more

New Espionage Campaign ‘SilkParasite’ Hits Central Asian Governments With Five Undocumented Malware Tools

22 August 2026  |  dark6  |  Malware

Researchers have uncovered SilkParasite, a cyberespionage operation using spear-phishing and five previously unseen malware families to target government bodies across Central Asia. The campaign favors cloud-based command channels...

>> read more

Chinese APT Group Deploys Signed Kernel Rootkit to Hide ‘CoolClient’ Backdoor on Government Networks

18 August 2026  |  dark6  |  Malware

Researchers have exposed a HoneyMyte campaign that pairs the PlugX loader with a new backdoor called CoolClient, concealed by a digitally signed kernel rootkit driver. The malware has...

>> read more

Lazarus Group Weaponizes Windows Kernel Zero-Day to Deploy Next-Generation FudModule Rootkit

14 August 2026  |  dark6  |  Malware

Check Point Research has caught North Korea's Lazarus group exploiting a previously unknown Windows kernel flaw, CVE-2026-68820, to plant an upgraded FudModule rootkit on defense and aerospace targets....

>> read more

Patchwork Espionage Group Uses Fake PDFs and Romance-Themed Chat Apps to Spy on PCs and Phones

9 August 2026  |  dark6  |  Spyware

The long-running Patchwork espionage group, also tracked as Dropping Elephant, is running parallel campaigns against Windows machines and Android phones — one built around a PDF-disguised shortcut file,...

>> read more