Articles tagged "APT"

Found 72 articles

Researchers have identified vulnerabilities in TrueConf, a video conferencing software, which are being exploited by the Head Mare APT hacktivist group. These flaws allow for the distribution of PhantomCore malware, posing a significant risk to meeting participants. Organizations using TrueConf should be aware of the potential for these attacks, which could compromise sensitive information during virtual meetings. The discovery of these vulnerabilities emphasizes the need for users to keep their software updated and to implement robust security measures to protect against such threats. As this situation unfolds, it’s crucial for affected users to remain vigilant.

Read Original

A spear-phishing campaign linked to a China-based group known as FamousSparrow is targeting organizations in Central Asia with various remote access trojans (RATs). These attacks are part of a broader strategy that reflects the geopolitical tensions in the region and the ongoing activities of advanced persistent threat (APT) groups. The campaign uses deceptive emails to trick recipients into installing malware, which can give attackers control over compromised systems. This poses significant risks for the affected organizations, as it could lead to data breaches, espionage, and further exploitation of sensitive information. Security experts are urging organizations in Central Asia to strengthen their defenses against such targeted attacks, especially as the threat landscape continues to evolve with geopolitical developments.

Read Original

Cybersecurity researchers have identified a new security threat linked to a suspected China-nexus advanced persistent threat group. The group is exploiting a serious vulnerability in Broadcom's VMware vCenter, known as CVE-2026-59310, which has a CVSS score of 9.8, indicating its severity. This directory-traversal flaw allows attackers to execute arbitrary code on affected systems. Recent reports show that the attackers are deploying Babuk-derived ransomware during these exploits, raising concerns for organizations using VMware vCenter. Companies that rely on this software need to act quickly to secure their environments and protect sensitive data from potential ransomware attacks.

Read Original

Researchers from Broadcom have linked a Chinese APT group, known as 'Jewelbug', to a hack-for-hire scheme that is reportedly involved in a significant cryptocurrency fraud operation. This group has been known for its cyber espionage activities but is now suspected of engaging in illegal financial schemes, potentially affecting individuals and organizations involved in cryptocurrency transactions. The connection to hack-for-hire operations raises concerns about the growing trend of state-sponsored groups diversifying into criminal activities for profit. This development highlights the need for enhanced vigilance among crypto users and businesses to protect against potential scams and fraud. The implications are serious, as these types of operations can undermine trust in the cryptocurrency market and lead to financial losses for victims.

Read Original

Researchers have identified a group of hackers known as 'Jewelbug' who are operating a dual-purpose cyber operation. This group is engaging in both state-sponsored espionage and cryptocurrency theft, using a single web panel to manage their activities. The findings suggest that these attackers are not only targeting sensitive information on behalf of nation-states but are also financially motivated, seeking to steal funds from cryptocurrency exchanges and users. This dual approach raises concerns about the increasing overlap between state-sponsored hacking and financial crime, making it harder for organizations and individuals to protect themselves. The implications of this could be significant, as it blurs the lines between traditional cybersecurity threats and those driven by financial gain.

Read Original
Actively Exploited

A new vulnerability in VMware vCenter has been identified and is currently being exploited by an unspecified advanced persistent threat (APT) group. This group has targeted 361 unique IP addresses across 47 countries, indicating a widespread impact. The flaw poses significant risks to organizations using VMware vCenter, as it could allow attackers to gain unauthorized access and control over critical systems. Given the number of affected systems, companies using VMware products need to assess their exposure and take immediate action to secure their environments. The urgency of addressing this vulnerability cannot be overstated, as ongoing attacks are already in progress.

Read Original

Researchers at Kaspersky have identified a cybersecurity threat involving the Head Mare APT group, which is exploiting vulnerabilities in unpatched TrueConf servers. This group is using malicious software installers to deliver two backdoors, PhantomCore and PhantomGraph, to users participating in video conferences. The attack specifically targets systems that have not updated their TrueConf software, making them susceptible to these exploits. This situation raises significant concerns for organizations that rely on video conferencing tools for communication, as attackers could gain unauthorized access to sensitive information. Users and companies should prioritize patching their TrueConf installations to mitigate this risk.

Read Original

U.S. agencies, including CISA, NSA, and FBI, have issued a warning about the Russian group Laundry Bear exploiting a known vulnerability in Zimbra servers. This flaw allows attackers to access and steal email accounts from organizations that have not applied the necessary patches. The advisory stresses that any organizations running unpatched versions of Zimbra could be at risk, as the attackers are actively targeting these systems. It is crucial for affected organizations to update their servers promptly to protect sensitive information and prevent unauthorized access. This incident emphasizes the ongoing threat posed by advanced persistent threat groups and the importance of maintaining up-to-date software.

Read Original

In April 2026, cybersecurity researchers identified a breach involving DigiCert, a prominent certificate authority, linked to a threat group known as CylindricalCanine, which is a subgroup of the Chinese cybercrime organization GoldenEyeDog. This group is particularly notorious for attacking the gambling and gaming industries. The breach resulted in the theft of code-signing certificates, which can be used to sign malicious software, making it harder for users to detect the threats. The incident raises serious concerns for companies relying on DigiCert for security, as compromised certificates could lead to widespread malware distribution. Organizations need to assess their certificate management practices and ensure they have robust monitoring in place to detect any misuse of their digital signatures.

Read Original

The Armored Likho APT group is reportedly using a sophisticated toolkit that includes AI-generated malware alongside existing threats like the BusySnake Stealer, a Python-based tool designed to siphon off sensitive information. This group is known for its modular approach, which allows them to adapt their methods and tools quickly, making it difficult for organizations to defend against their attacks. The use of obfuscated remote access trojans (RATs) and network tunneling tools like Go2Tunnel adds another layer of complexity to their operations. As a result, businesses and individuals need to be vigilant about their cybersecurity measures to protect against these evolving threats. Given the capabilities of this APT group, the potential for data breaches and unauthorized access remains high, raising concerns for organizations that store sensitive information.

Read Original
Actively Exploited

Cisco Talos has reported that a Chinese cyber espionage group, identified as APT UAT-7810, is expanding its proxy relay network by deploying new malware. This development raises concerns about the group's capabilities to conduct more extensive surveillance and data exfiltration activities. The increased use of proxies can help attackers mask their origin while facilitating access to targeted networks. Organizations should be vigilant, as this activity suggests that the group is actively seeking new methods to bypass security measures. The implications of this malware expansion could impact various sectors, especially those involving sensitive information or critical infrastructure.

Read Original
Critical
Armored Likho Hits Government, Energy Sectors With BusySnake Stealer

Hackread – Cybersecurity News, Data Breaches, AI and More

Actively Exploited

Kaspersky has reported that the Armored Likho group, a previously identified advanced persistent threat (APT), is actively targeting government and energy sectors using a combination of techniques. They employ BusySnake Stealer, a type of malware designed to extract sensitive information, alongside AI-generated loaders and phishing methods to infiltrate systems. This campaign poses significant risks to organizations in these critical sectors, as the stolen data could lead to further exploitation or security breaches. The use of sophisticated tools and tactics highlights the evolving nature of cyber threats and the need for enhanced security measures within these industries. Organizations should remain vigilant and strengthen their defenses against such targeted attacks.

Read Original

A new cyber espionage group known as Armored Likho is reportedly targeting government and electric power sectors. This advanced persistent threat (APT) uses modular remote access tools (RATs) and information stealers to conduct its operations, which appear to be financially motivated as well as aimed at gathering intelligence. The implications of these attacks are significant, as they could compromise sensitive government data and disrupt critical infrastructure, potentially leading to broader security risks. Organizations in these sectors should remain vigilant and improve their cyber defenses to protect against such targeted campaigns.

Read Original

A Chinese cyber espionage group known as CL-STA-1062 is targeting organizations in Southeast Asia using a new backdoor called TinyRCT. This group employs a mix of open-source tools, including SoftEther VPN and Mimikatz, alongside their custom malware. The use of such a hybrid toolkit suggests a sophisticated approach to infiltrating networks and exfiltrating sensitive information. Organizations in Southeast Asia should be especially vigilant, as this attack could compromise critical data and disrupt operations. The ongoing activity of this threat actor raises concerns about the security posture of companies in the region.

Read Original

Researchers from Palo Alto Networks Unit 42 have reported that a Chinese-speaking advanced persistent threat group, tracked as CL-STA-1062, has been targeting government and energy networks in Southeast Asia. This group has been active since at least March 2022 and has recently intensified its operations in the region, employing custom malware known as TinyRCT to exploit vulnerabilities in critical infrastructure. The focus on Southeast Asia raises concerns about the security of essential services and the potential for significant disruptions. As these attacks target vital sectors, governments and organizations in the region need to bolster their cybersecurity defenses to mitigate risks posed by such sophisticated threats.

Read Original
Page 1 of 5Next