Chinese cyberespionage campaign targets key Asian sectors
The CL-UNK-1068 group uses custom malware, modified open-source utilities, and legitimate system tools to maintain long-term access.
The extensions were modified to disable browser protections, inject malicious code, and steal data.
The CL-UNK-1068 group uses custom malware, modified open-source utilities, and legitimate system tools to maintain long-term access.
The campaign, observed in February 2026, directs users to launch Windows Terminal using the Windows + X u2192 I shortcut.
The malware uses the Deno runtime environment to execute malicious commands on compromised systems.
In brief: Cisco warns of two actively exploited flaws in Catalyst SD-WAN Manager, researchers details a new iOS exploit kit called u2018Coruna,u2019 and more.
Authorities seized and took offline 330 domains used by Tycoon2FA.
In addition to Cobalt Strike, Silver Dragon deploys a suite of custom post-exploitation tools, including SilverScreen, SSHcmd, and the GearDoor backdoor.