Skip to content
Threat Feed

Tag

Government

3 briefs RSS
high advisory

GoSerpent Backdoor and Stowaway RAT Target Government Entities in Southeast Asia for Data Exfiltration

An unnamed threat actor is deploying a sophisticated two-phase attack, utilizing the GoSerpent backdoor, Stowaway RAT, and custom tools like ThumbcacheService and TmcLoader/TmcPayload, to persistently collect sensitive data and credentials from government and diplomatic entities in Southeast Asia for exfiltration.

backdoor rat data-exfiltration government southeast-asia
3r 9t
high threat

Armored Likho APT Leverages BusySnake Stealer with AI-Generated Loaders and Phishing

The Armored Likho APT group is conducting a spear-phishing campaign against government and energy sectors in Russia, Kazakhstan, and Brazil, using AI-generated loaders and the Python-based BusySnake Stealer to exfiltrate credentials and sensitive data.

Armored Likho apt infostealer phishing python windows government energy
2r 10t
critical threat

FortiBleed Campaign: 73,932 FortiGate Systems Credentials Exposed

A Russian-speaking threat group utilized a large dataset of administrative and VPN credentials, likely sourced from exposed FortiGate configuration files and active credential harvesting, to access government, critical infrastructure, and multinational corporate networks, resulting in widespread data exfiltration.

FortiGate +1 Russian-speaking threat group credential-theft fortios state-sponsored espionage data-exfiltration russian-speaking critical-infrastructure government
3r 9t 1i