Security News

China-Linked APT Aquatic Panda: 10-Month Campaign, 7 Global Targets, 5 Malware Families
2025-03-21 11:01

The China-linked advanced persistent threat (APT) group. known as Aquatic Panda has been linked to a "global espionage campaign" that took place in 2022 targeting seven organizations. These...

APTs have been using zero-day Windows shortcut exploit for eight years (ZDI-CAN-25373)
2025-03-19 13:48

State-sponsored threat actors and cybercrime groups from North Korea, Iran, Russia, and China have been exploiting a zero-day Windows vulnerability with no fix in sight for the last eight years,...

SideWinder APT Targets Maritime, Nuclear, and IT Sectors Across Asia, Middle East, and Africa
2025-03-11 07:00

Maritime and logistics companies in South and Southeast Asia, the Middle East, and Africa have become the target of an advanced persistent threat (APT) group dubbed SideWinder. The attacks,...

Chinese APT Lotus Panda Targets Governments With New Sagerunex Backdoor Variants
2025-03-05 11:03

The threat actor known as Lotus Panda has been observed targeting government, manufacturing, telecommunications, and media sectors in the Philippines, Vietnam, Hong Kong, and Taiwan with updated...

Silver Fox APT Uses Winos 4.0 Malware in Cyber Attacks Against Taiwanese Organizations
2025-02-27 15:36

A new campaign is targeting companies in Taiwan with malware known as Winos 4.0 as part of phishing emails masquerading as the country's National Taxation Bureau. The campaign, detected last month...

Sandworm APT’s initial access subgroup hits organizations accross the globe
2025-02-13 13:25

A subgroup of Russia’s Sandworm APT has been working to achieve initial and persistent access to the IT networks of organizations working in economic sectors Russia is interested in. “In 2022, its...

North Korean APT Kimsuky Uses forceCopy Malware to Steal Browser-Stored Credentials
2025-02-06 11:05

The North Korea-linked nation-state hacking group known as Kimsuky has been observed conducting spear-phishing attacks to deliver an information stealer malware named forceCopy, according to new...

PlushDaemon APT Targets South Korean VPN Provider in Supply Chain Attack
2025-01-22 08:49

A previously undocumented China-aligned advanced persistent threat (APT) group named PlushDaemon has been linked to a supply chain attack targeting a South Korean virtual private network (VPN)...

China-aligned PlushDaemon APT compromises supply chain of Korean VPN
2025-01-22 06:00

ESET researchers have uncovered a supply chain attack targeting a South Korean VPN provider, carried out by PlushDaemon, a newly identified China-aligned APT group. In this cyberespionage...

Chinese APT Exploits BeyondTrust API Key to Access U.S. Treasury Systems and Documents
2024-12-31 05:42

The United States Treasury Department said it suffered a "major cybersecurity incident" that allowed suspected Chinese threat actors to remotely access some computers and unclassified documents. ...