Sloppy Server Configuration Unmasks JadeProx Espionage Campaign and Its TriBack Malware Loader
Researchers at Group-IB stumbled onto an active espionage operation, now tracked as JadeProx, after its operators left a staging server's directory listing wide open. The exposed files revealed...
HazyBeacon APT Campaign Weaponizes AWS Lambda to Hide Command-and-Control Traffic
Qualys researchers have exposed HazyBeacon, a stealthy APT campaign targeting Southeast Asian governments that uses AWS Lambda Function URLs as covert command-and-control relays. By routing malicious traffic through...
Chinese Hackers (UNC6508) Spent Over a Year Spying on US Medical Research Institutions via REDCap
Google GTIG has attributed a 2+ year Chinese cyber-espionage campaign to UNC6508, which exploited REDCap medical research servers across North America. The group deployed a novel modular malware...
China-Linked OP-512 Uses Cryptographically Unique Web Shells in Patient IIS Server Espionage Campaign
ReliaQuest has uncovered OP-512, a new China-linked threat cluster targeting IIS servers with a custom web shell framework that generates cryptographically unique signatures per deployment, evading traditional detection....
Seedworm (MuddyWater) APT Abuses Signed Security Binaries in Global Espionage Campaign Across 9 Countries
Iran-linked Seedworm (MuddyWater) APT has been caught running a broad espionage campaign against at least 9 organizations across 9 countries in early 2026. The group hijacked legitimate, digitally...
Cloud Atlas APT Patches termsrv.dll to Enable Silent Dual RDP Sessions — Targets Government and Diplomatic Organizations
The Cloud Atlas APT group has adopted a stealthy new technique: modifying Windows termsrv.dll to enable multiple simultaneous RDP sessions, allowing attackers to maintain covert access while legitimate...
China-Aligned SHADOW-EARTH Deploys ShadowPad, IOX Proxy, and WMIC in Multi-Stage Espionage Campaign Across Asia
A China-aligned threat group has conducted a prolonged espionage campaign against government agencies and critical infrastructure across eight Asian countries. The attackers used ShadowPad delivered via DLL sideloading,...
State-Sponsored UAT-4356 Deploys FIRESTARTER Backdoor on Cisco Firepower Devices via Chained N-Day Vulnerabilities
Cisco Talos has uncovered an active espionage campaign by state-sponsored group UAT-4356, which chains two Cisco Firepower FXOS vulnerabilities (CVE-2025-20333 and CVE-2025-20362) to deploy the FIRESTARTER backdoor —...