Skip to content
Threat Feed

Tag

Espionage

24 briefs RSS
high advisory

Iranian State-Sponsored Surveillance Malware: Chosen Brick

Iranian state-sponsored actors are leveraging the 'Chosen Brick' Windows malware to conduct surveillance on global activists and journalists via social engineering and Telegram-based command-and-control.

surveillance nation-state windows espionage
1r 4t
high threat

Nimbus Manticore Targets Developers with Node.js-based Cross-Platform RATs

The Iranian threat actor Nimbus Manticore is distributing NodeRabbit and PollCat cross-platform RATs via trojanized coding challenges on LinkedIn to compromise developer systems.

VS Code +1 Nimbus Manticore espionage rat phishing recruitment cross-platform
1r 3t 3i
high threat

BlueDelta Targets European Defense and Diplomacy with HOOKEDGE Backdoor

The Russian threat group BlueDelta is using a custom batch-script backdoor named HOOKEDGE to target European government and diplomatic entities via macro-enabled Microsoft Word documents that leverage legitimate webhook services for C2.

Word BlueDelta espionage windows phishing c2
1r 3t 1i
high threat

TA4922 Deploys PackClient RAT Framework

The Chinese-speaking threat actor TA4922 is actively using the modular PackClient C2 framework, delivered via tax-themed spearphishing, to conduct surveillance and deploy follow-on tools like ManageEngine RMM.

Remote Monitoring and Management TA4922 rat phishing c2-framework espionage
1r 3t 3i
high advisory

Chinese-Speaking Operator Targets Philippine Nuclear and Naval Infrastructure

A suspected Chinese-speaking operator is targeting Philippine governmental and defense entities by exploiting ownCloud and LiteSpeed Cache vulnerabilities to exfiltrate personnel data and deploy loaders.

PoC ownCloud +2 espionage web-exploitation data-exfiltration
2r 3t 2c updated
medium threat

Dark Caracal Evolving Infrastructure and Targeting

Arctic Wolf Labs identified 249 Dark Caracal malware samples utilizing an Ethereum-based C2 architecture to target the communications sector in Latin America.

Dark Caracal command-and-control malware espionage
1t
high threat

Russian Threat Clusters UNC6293, UNC7005, and UNC5976 Targeted OAuth and Device Code Phishing Campaigns

Three suspected Russian threat clusters are actively conducting targeted phishing campaigns using OAuth abuse, device code manipulation, and AitM attacks via compromised Wi-Fi gateways to hijack credentials and deploy infostealers.

Google Cloud +2 UNC7005 phishing espionage oauth-abuse aitm credential-theft
3t
high threat

Russian-Linked Clusters Abuse Authentication Flows for Targeted Credential Theft

Suspected Russian threat clusters UNC6293 and UNC7005 are abusing legitimate OAuth, app password, and device code authentication workflows to bypass MFA and compromise high-value targets in academia, government, and defense.

Microsoft Account +1 ICE RELIC phishing credential-theft oauth espionage ice-relic
3t 1i
high threat

Mustang Panda Deploys Signed Kernel-Mode Rootkit with CoolClient Backdoor

The threat actor HoneyMyte (Mustang Panda) is utilizing a signed kernel-mode rootkit named msagent.sys to provide stealth capabilities for its CoolClient backdoor, facilitating process, file, and network hiding on compromised Windows systems.

Windows HoneyMyte rootkit backdoor espionage malware
3t 4i
high threat

HoneyMyte CoolClient Backdoor Updated with Kernel-Mode Rootkit

The HoneyMyte APT group has enhanced its CoolClient backdoor with a custom kernel-mode driver that hides malicious artifacts and activity from security software on Windows systems.

Endpoint Secure HoneyMyte backdoor rootkit apt windows espionage
1r 3t
high threat

Jewelbug APT Dual-Purpose Espionage and Fraud Operations

Jewelbug, a China-linked mercenary APT, uses a custom C2 platform called XG-Web to conduct both state-sponsored espionage and large-scale cryptocurrency theft using custom backdoors and malicious browser extensions.

Jewelbug apt espionage credential-theft malware china middle-east southeast-asia browser-security
3t
high advisory

Project CAV3RN Modular Espionage Framework

Project CAV3RN is a modular espionage framework targeting entities in Israel that uses a .NET NativeAOT-compiled communication module to orchestrate DNS-controlled C2 transport switching between direct HTTPS and Google Apps Script relays.

.NET 8 +1 espionage c2 dns nativeaot modular
1r 4t 3i
critical threat

Russian State-Backed 'LAUNDRY BEAR' Exploits Zimbra Zero-Click Vulnerability

The Russian state-supported threat group LAUNDRY BEAR is exploiting a zero-click vulnerability, dubbed 'beehive,' in the Zimbra Collaboration Suite (ZCS) webmail service, actively stealing sensitive emails and gaining persistent access to compromised networks since July 2025 by merely viewing a malicious email, with Western organizations across various sectors being targeted.

Zimbra Collaboration Suite LAUNDRY BEAR phishing zero-click espionage state-sponsored zimbra email-theft
3t
critical threat

TA488 Exploits Zimbra Mailservers with Half-Click Vulnerability CVE-2025-66376

Russia-aligned threat actor TA488 (Void Blizzard, Laundry Bear) exploited CVE-2025-66376, a critical XSS vulnerability in Zimbra Collaboration Suite webmail, for at least five months in 2025 via crafted emails to gain persistent access, exfiltrate user credentials, 2FA codes, and bulk emails from Ukrainian government and US defense industrial base targets.

PoC Zimbra Collaboration Suite +10 TA488 +2 espionage xss zimbra apt state-sponsored half-click cve-2025-66376
2r 9t 3c 7i updated
high advisory

Midyear Assessment of Iran-Linked Cyber Threat Landscape

SentinelOne Labs' midyear assessment highlights that Iran-linked cyber operations, involving groups like MuddyWater/Seedworm, Screening Serpens, APT42, and persona groups such as Handala, focus on persistent access, espionage, and selective disruption, often leveraging social engineering, compromised service providers, and RMM abuse, with increasing risk to operational technology environments.

iran espionage destructive-malware social-engineering operational-technology rmm supply-chain threat-assessment +1
12t
high advisory

New GoSerpent Malware Targets Southeast Asian Governments and Diplomats for Espionage

A sophisticated Go-based implant, dubbed GoSerpent, has been utilized by an unidentified threat actor since late 2025 to conduct cyber espionage against government and diplomatic entities in Southeast Asia, focusing on long-term access, sensitive data collection, and credential dumping for exfiltration.

espionage malware Go RAT APT Southeast Asia
2r 6t
critical threat

Targeting and Compromise of French Entities Using the Turla Intrusion Set

The Turla intrusion set, operated by the 16th Centre of the Federal Security Service (FSB) of Russia, has been targeting French entities and other strategic organizations globally since at least 2004 for intelligence-gathering purposes, with victims in France including ministries and entities within the diplomatic, defence, justice, and technology sectors.

Turla +4 nation-state espionage APT russia france
high threat

NCSC Warns of State-Sponsored Espionage via IP Cameras Targeting Critical Infrastructure

Russian state-sponsored actors, along with hacktivist groups and cybercriminals, are exploiting IP cameras to spy on critical infrastructure in NATO countries, including the Netherlands, prompting NCSC to advise organizations and home users to secure their devices through updates, network segmentation, and attack surface reduction.

Russian state-sponsored actors ip-camera espionage critical-infrastructure state-sponsored advisory network-segmentation security-best-practices
2t
critical threat

FortiBleed Campaign: 73,932 FortiGate Systems Credentials Exposed

A Russian-speaking threat group utilized a large dataset of administrative and VPN credentials, likely sourced from exposed FortiGate configuration files and active credential harvesting, to access government, critical infrastructure, and multinational corporate networks, resulting in widespread data exfiltration.

FortiGate +1 Russian-speaking threat group credential-theft fortios state-sponsored espionage data-exfiltration russian-speaking critical-infrastructure government
3r 9t 1i
high advisory

CrowdStrike 2026 Technology Threat Landscape Report: China's Ambitions Fuel Attacks

The CrowdStrike 2026 Technology Threat Landscape Report highlights the pervasive targeting of the technology sector by China-nexus and eCrime adversaries, employing tactics like password spraying, vulnerability exploitation, supply chain compromises (e.g., Axios npm package, GitHub repositories), and malware distribution (macOS info stealers via OpenClaw lures) to achieve intelligence collection, intellectual property theft, and financial extortion.

Axios npm package +1 intelligence-collection espionage supply-chain-compromise software-supply-chain extortion state-sponsored ecrime macos +1
2r 6t
high advisory

Global Stock Exchange Hit by Monthslong Email Campaign

An unknown threat actor gained continuous administrative access to a senior finance executive's Microsoft Outlook mailbox at a global stock exchange for at least five months, deploying custom infostealers via scheduled tasks and exfiltrating sensitive emails through a Dropbox-based command and control channel after an initial lateral movement event.

Microsoft Outlook +2 espionage financial-sector email-exfiltration persistence living-off-the-land windows advanced-persistent-threat
3r 7t
high threat

ESET APT Activity Report Q4 2025–Q1 2026 Highlights Various Threat Actor Campaigns

ESET's APT Activity Report for Q4 2025 and Q1 2026 highlights diverse campaigns by China, Iran, North Korea, and Russia-aligned threat actors, including espionage, supply chain compromise, and destructive attacks.

Ivanti VPN appliances +2 Lazarus Group +4 apt espionage supply-chain wiper
2r 3t
high threat

Secret Blizzard Upgrades Kazuar Backdoor to Modular P2P Botnet

The Russian hacker group Secret Blizzard has evolved the Kazuar backdoor into a modular P2P botnet designed for persistence, stealth, and data collection, utilizing kernel, bridge, and worker modules for command and control and data exfiltration.

Exchange Web Services +2 Turla +4 kazuar p2p botnet espionage windows
2r 4t
critical threat

UAT-4356 FIRESTARTER Backdoor Targeting Cisco Firepower Devices

UAT-4356 is actively targeting Cisco Firepower devices running FXOS, exploiting CVE-2025-20333 and CVE-2025-20362 to deploy the FIRESTARTER backdoor which allows remote access and control by injecting malicious shellcode into the LINA process.

Firepower eXtensible Operating System +2 UAT-4356 firestarter cisco backdoor network espionage
2r 2t 2c 2i