Patchwork Espionage Group Uses Fake PDFs and Romance-Themed Chat Apps to Spy on PCs and Phones
The long-running Patchwork espionage group, also tracked as Dropping Elephant, is running parallel campaigns against Windows machines and Android phones — one built around a PDF-disguised shortcut file,...
Dark Web Persona ‘ModernStealer’ Ties Together Alleged Military and Nuclear Regulator Data Leaks
Threat intelligence firm StealthMole has traced a web of dark forum and Telegram listings advertising alleged military, nuclear, and aerospace data back to a recurring set of contact...
BlackTech’s Linux Backdoor Blends In by Routing Through Your Own Proxy Server
China-linked espionage group BlackTech has been spotted deploying a stealthy Linux variant of the BlueShell backdoor against Japanese organizations, tunneling command-and-control traffic through the victim's own proxy infrastructure....
Sloppy Server Configuration Unmasks JadeProx Espionage Campaign and Its TriBack Malware Loader
Researchers at Group-IB stumbled onto an active espionage operation, now tracked as JadeProx, after its operators left a staging server's directory listing wide open. The exposed files revealed...
Iran’s Cyber Playbook Shifts From Loud Attacks to Patient, Long-Term Access
A new SentinelOne assessment finds Iran-linked hacking groups increasingly favor quiet, persistent access over destructive attacks, planting footholds in cloud accounts, IT suppliers, and industrial systems that could...
Cavern Manticore: Iranian-Linked APT Abuses SysAid RMM and DLL Sideloading to Deploy Modular C2 Framework
A newly identified Iranian-linked group, Cavern Manticore, is abusing the SysAid RMM platform and DLL sideloading via WinDirStat to deploy a modular C2 framework against Israeli organizations. Check...
Russia’s Turla APT Deploys STOCKSTAY Backdoor Against Ukrainian Government and Military Targets
Russia-linked Turla (FSB Center 16) has been running a long-running espionage campaign deploying a new .NET backdoor called STOCKSTAY against Ukrainian government and military organizations since December 2022....
HazyBeacon APT Campaign Weaponizes AWS Lambda to Hide Command-and-Control Traffic
Qualys researchers have exposed HazyBeacon, a stealthy APT campaign targeting Southeast Asian governments that uses AWS Lambda Function URLs as covert command-and-control relays. By routing malicious traffic through...