Articles tagged "APT"

Found 77 articles

A Chinese hacking group known as FamousSparrow is reportedly spying on U.S. political activities in Latin America. This group is part of a broader trend where state-sponsored actors are increasingly targeting regions of geopolitical interest. Researchers have identified that FamousSparrow uses a stealthy backdoor to gain access to sensitive information, making it difficult for victims to detect their presence. The implications of this espionage are significant, especially as it relates to U.S. interests in Latin America, where competition with China is intensifying. Organizations involved in politics or policy-making in the region should be particularly vigilant against these types of cyber intrusions.

Read Original

Three distinct threat groups, identified as NightEagle, Hacking Cat, and Toy Ghouls, are targeting Russian enterprises with various cyberattack methods, including backdoors, ransomware, and wipers. NightEagle, also known as APT-Q-95, has been active since at least 2023 and is employing innovative techniques for maintaining access and moving laterally within networks. The attacks pose significant risks to the affected organizations, as they could lead to data breaches, operational disruptions, and potential ransom demands. Kaspersky's reports indicate that these groups are becoming increasingly sophisticated, which raises concerns for the security of businesses operating in Russia. Companies in this region should enhance their security measures to defend against these evolving threats and protect sensitive information.

Read Original
Actively Exploited

Kaspersky's GERT team has identified a new campaign from the NightEagle APT group, which is targeting Russian companies. This campaign utilizes the GhostContainer backdoor and exploits vulnerabilities in Active Directory and Remote Desktop Protocol (RDP). The tools used in these attacks are hosted on GitHub, raising concerns about the accessibility of malicious resources for attackers. Companies in Russia should be particularly vigilant as these vulnerabilities can lead to unauthorized access and potential data breaches. Understanding the methods employed by NightEagle is crucial for organizations to strengthen their defenses against such targeted campaigns.

Read Original

A North Korean advanced persistent threat (APT) group has targeted South Korea's media and automotive sectors using a new Linux espionage toolkit. This toolkit allowed the attackers to compromise load balancers, which are critical for managing network traffic, and gain unauthorized access to communications within these organizations. The incident raises significant concerns about the security of sensitive data and communication networks in South Korea, particularly given the geopolitical tensions in the region. The use of an undocumented toolkit indicates that the attackers have advanced capabilities, which could lead to further exploitation of vulnerable systems. Organizations in the affected sectors need to bolster their cybersecurity measures to defend against such sophisticated attacks.

Read Original
Actively Exploited

The latest issue of the Security Affairs Malware newsletter covers significant developments in malware research. One notable focus is on REVSTEALER, which is ramping up its activities, posing a risk to users through information theft. Researchers also discuss techniques for deobfuscating JSCeal’s compiled V8 bytecode, which could help security professionals better understand and combat this malware. Additionally, the DPRK APT group has been linked to the Ted backdoor and curlRAT, which are targeting South Korean media and automotive sectors. These findings emphasize the ongoing challenges that organizations face in defending against sophisticated malware attacks.

Read Original

Researchers have identified vulnerabilities in TrueConf, a video conferencing software, which are being exploited by the Head Mare APT hacktivist group. These flaws allow for the distribution of PhantomCore malware, posing a significant risk to meeting participants. Organizations using TrueConf should be aware of the potential for these attacks, which could compromise sensitive information during virtual meetings. The discovery of these vulnerabilities emphasizes the need for users to keep their software updated and to implement robust security measures to protect against such threats. As this situation unfolds, it’s crucial for affected users to remain vigilant.

Read Original

A spear-phishing campaign linked to a China-based group known as FamousSparrow is targeting organizations in Central Asia with various remote access trojans (RATs). These attacks are part of a broader strategy that reflects the geopolitical tensions in the region and the ongoing activities of advanced persistent threat (APT) groups. The campaign uses deceptive emails to trick recipients into installing malware, which can give attackers control over compromised systems. This poses significant risks for the affected organizations, as it could lead to data breaches, espionage, and further exploitation of sensitive information. Security experts are urging organizations in Central Asia to strengthen their defenses against such targeted attacks, especially as the threat landscape continues to evolve with geopolitical developments.

Read Original

Cybersecurity researchers have identified a new security threat linked to a suspected China-nexus advanced persistent threat group. The group is exploiting a serious vulnerability in Broadcom's VMware vCenter, known as CVE-2026-59310, which has a CVSS score of 9.8, indicating its severity. This directory-traversal flaw allows attackers to execute arbitrary code on affected systems. Recent reports show that the attackers are deploying Babuk-derived ransomware during these exploits, raising concerns for organizations using VMware vCenter. Companies that rely on this software need to act quickly to secure their environments and protect sensitive data from potential ransomware attacks.

Read Original

Researchers from Broadcom have linked a Chinese APT group, known as 'Jewelbug', to a hack-for-hire scheme that is reportedly involved in a significant cryptocurrency fraud operation. This group has been known for its cyber espionage activities but is now suspected of engaging in illegal financial schemes, potentially affecting individuals and organizations involved in cryptocurrency transactions. The connection to hack-for-hire operations raises concerns about the growing trend of state-sponsored groups diversifying into criminal activities for profit. This development highlights the need for enhanced vigilance among crypto users and businesses to protect against potential scams and fraud. The implications are serious, as these types of operations can undermine trust in the cryptocurrency market and lead to financial losses for victims.

Read Original

Researchers have identified a group of hackers known as 'Jewelbug' who are operating a dual-purpose cyber operation. This group is engaging in both state-sponsored espionage and cryptocurrency theft, using a single web panel to manage their activities. The findings suggest that these attackers are not only targeting sensitive information on behalf of nation-states but are also financially motivated, seeking to steal funds from cryptocurrency exchanges and users. This dual approach raises concerns about the increasing overlap between state-sponsored hacking and financial crime, making it harder for organizations and individuals to protect themselves. The implications of this could be significant, as it blurs the lines between traditional cybersecurity threats and those driven by financial gain.

Read Original
Actively Exploited

A new vulnerability in VMware vCenter has been identified and is currently being exploited by an unspecified advanced persistent threat (APT) group. This group has targeted 361 unique IP addresses across 47 countries, indicating a widespread impact. The flaw poses significant risks to organizations using VMware vCenter, as it could allow attackers to gain unauthorized access and control over critical systems. Given the number of affected systems, companies using VMware products need to assess their exposure and take immediate action to secure their environments. The urgency of addressing this vulnerability cannot be overstated, as ongoing attacks are already in progress.

Read Original

Researchers at Kaspersky have identified a cybersecurity threat involving the Head Mare APT group, which is exploiting vulnerabilities in unpatched TrueConf servers. This group is using malicious software installers to deliver two backdoors, PhantomCore and PhantomGraph, to users participating in video conferences. The attack specifically targets systems that have not updated their TrueConf software, making them susceptible to these exploits. This situation raises significant concerns for organizations that rely on video conferencing tools for communication, as attackers could gain unauthorized access to sensitive information. Users and companies should prioritize patching their TrueConf installations to mitigate this risk.

Read Original

U.S. agencies, including CISA, NSA, and FBI, have issued a warning about the Russian group Laundry Bear exploiting a known vulnerability in Zimbra servers. This flaw allows attackers to access and steal email accounts from organizations that have not applied the necessary patches. The advisory stresses that any organizations running unpatched versions of Zimbra could be at risk, as the attackers are actively targeting these systems. It is crucial for affected organizations to update their servers promptly to protect sensitive information and prevent unauthorized access. This incident emphasizes the ongoing threat posed by advanced persistent threat groups and the importance of maintaining up-to-date software.

Read Original

In April 2026, cybersecurity researchers identified a breach involving DigiCert, a prominent certificate authority, linked to a threat group known as CylindricalCanine, which is a subgroup of the Chinese cybercrime organization GoldenEyeDog. This group is particularly notorious for attacking the gambling and gaming industries. The breach resulted in the theft of code-signing certificates, which can be used to sign malicious software, making it harder for users to detect the threats. The incident raises serious concerns for companies relying on DigiCert for security, as compromised certificates could lead to widespread malware distribution. Organizations need to assess their certificate management practices and ensure they have robust monitoring in place to detect any misuse of their digital signatures.

Read Original

The Armored Likho APT group is reportedly using a sophisticated toolkit that includes AI-generated malware alongside existing threats like the BusySnake Stealer, a Python-based tool designed to siphon off sensitive information. This group is known for its modular approach, which allows them to adapt their methods and tools quickly, making it difficult for organizations to defend against their attacks. The use of obfuscated remote access trojans (RATs) and network tunneling tools like Go2Tunnel adds another layer of complexity to their operations. As a result, businesses and individuals need to be vigilant about their cybersecurity measures to protect against these evolving threats. Given the capabilities of this APT group, the potential for data breaches and unauthorized access remains high, raising concerns for organizations that store sensitive information.

Read Original
Page 1 of 6Next