China-linked espionage campaign targeting telecom and government networks
As part of the campaign, 53 organizations across 42 countries were compromised, with suspected infections spanning at least 20 additional nations.
As part of the campaign, 53 organizations across 42 countries were compromised, with suspected infections spanning at least 20 additional nations.
Cisco’s threat hunting team said that the flaw has been exploited in the wild since at least 2023.
Following the Valencia floods, Anonymous Fénix allegedly targeted multiple public administration websites, accusing authorities of responsibility for the disaster.
Researchers believe the group is Armenian-speaking and connected to Russian infrastructure.
Mercenary Akula is thought to be a financially motivated mercenary entity with links to cyber espionage and psychological operations.
Sanctions also target two Trickbot members who allegedly helped Operation Zero and their own exploit brokerage firm.
Analysis of domain registration data indicates that the threat actors are using a rotating set of domains and cloud hosting services to deliver malware.
This marks the first time the Medusa ransomware has been linked to North Korean threat actors.
The observed campaign deploys a five-stage infection chain installing a native C implant designed for persistence and lateral movement.
The attack begins with social engineering lures promoting free premium software, including pirated office productivity suite installers.
Showing elements 1 - 10