Secure Bulletin Navigating the cyber sea with knowledge
Home > Tag > APT
#APT

Patchwork Espionage Group Uses Fake PDFs and Romance-Themed Chat Apps to Spy on PCs and Phones

9 August 2026  |  dark6  |  Spyware

The long-running Patchwork espionage group, also tracked as Dropping Elephant, is running parallel campaigns against Windows machines and Android phones — one built around a PDF-disguised shortcut file,...

>> read more

Dark Web Persona ‘ModernStealer’ Ties Together Alleged Military and Nuclear Regulator Data Leaks

4 August 2026  |  dark6  |  Cybercrime

Threat intelligence firm StealthMole has traced a web of dark forum and Telegram listings advertising alleged military, nuclear, and aerospace data back to a recurring set of contact...

>> read more

BlackTech’s Linux Backdoor Blends In by Routing Through Your Own Proxy Server

1 August 2026  |  dark6  |  Malware

China-linked espionage group BlackTech has been spotted deploying a stealthy Linux variant of the BlueShell backdoor against Japanese organizations, tunneling command-and-control traffic through the victim's own proxy infrastructure....

>> read more

Sloppy Server Configuration Unmasks JadeProx Espionage Campaign and Its TriBack Malware Loader

24 July 2026  |  dark6  |  Malware

Researchers at Group-IB stumbled onto an active espionage operation, now tracked as JadeProx, after its operators left a staging server's directory listing wide open. The exposed files revealed...

>> read more

Iran’s Cyber Playbook Shifts From Loud Attacks to Patient, Long-Term Access

23 July 2026  |  dark6  |  Cybercrime

A new SentinelOne assessment finds Iran-linked hacking groups increasingly favor quiet, persistent access over destructive attacks, planting footholds in cloud accounts, IT suppliers, and industrial systems that could...

>> read more

Cavern Manticore: Iranian-Linked APT Abuses SysAid RMM and DLL Sideloading to Deploy Modular C2 Framework

7 July 2026  |  dark6  |  Malware

A newly identified Iranian-linked group, Cavern Manticore, is abusing the SysAid RMM platform and DLL sideloading via WinDirStat to deploy a modular C2 framework against Israeli organizations. Check...

>> read more

Russia’s Turla APT Deploys STOCKSTAY Backdoor Against Ukrainian Government and Military Targets

30 June 2026  |  dark6  |  Cybercrime

Russia-linked Turla (FSB Center 16) has been running a long-running espionage campaign deploying a new .NET backdoor called STOCKSTAY against Ukrainian government and military organizations since December 2022....

>> read more

HazyBeacon APT Campaign Weaponizes AWS Lambda to Hide Command-and-Control Traffic

22 June 2026  |  dark6  |  Cybercrime

Qualys researchers have exposed HazyBeacon, a stealthy APT campaign targeting Southeast Asian governments that uses AWS Lambda Function URLs as covert command-and-control relays. By routing malicious traffic through...

>> read more