Threats Tagged 'apt'
View all threats tagged with 'apt'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'apt'
Click on any threat for detailed analysis and mitigation recommendations
The FamousSparrow espionage group, linked to China, has deployed a new backdoor malware named SparroWocky targeting government organizations in Latin America since mid-2025. SparroWocky is a modular C++ backdoor with advanced anti-analysis and evasion techniques, including DLL side-loading, runtime code patching, and thread creation interception to disguise malicious activity. It enables extensive system reconnaissance, file operations, screenshot capture, process creation, and network proxying. Persistence is maintained via Windows services or registry keys. The malware communicates with multiple command-and-control servers over common ports and proxies. The attacks aim to gather intelligence on Latin American governments' responses to U.S. pressure on Chinese economic interests. Join the discussion | Bleeping Computer | 09/17/2026, 09:00:00 UTC Added: 09/17/2026, 09:01:44 UTC |
A critical remote code execution vulnerability (CVE-2026-51990) in Tencent's Sogou Input Method for Windows is actively exploited by the UNC3569 threat group to deploy the GrayRabbit backdoor malware. The attack chain abuses a custom URI handler, an unrestricted URL navigation in an embedded Chromium webview, and a known flaw in an outdated Chromium 80 engine running without sandboxing. Tencent released a patch in version 16.3.0.3498 that validates URL arguments and restricts navigation to approved domains, but the underlying Chromium engine remains outdated and unsandboxed. Join the discussion | Bleeping Computer | 09/16/2026, 00:00:00 UTC Added: 09/13/2026, 14:31:43 UTC |
This entry references a simulation of the Charming Kitten APT adversary, as detailed in a Medium article. It is not a direct report of an active campaign or exploit but rather an adversary simulation intended for security awareness or training purposes. Join the discussion | Reddit BlueTeam | 09/14/2026, 08:37:02 UTC Added: 09/14/2026, 12:17:02 UTC |
This content discusses the impact of AI on the speed at which vulnerabilities can be analyzed and exploited, particularly focusing on dependency management and patch windows. It highlights that AI-assisted tools can rapidly analyze patches and identify vulnerabilities in abandoned or stale dependencies, potentially shrinking the window defenders have to patch before exploitation. The discussion raises concerns about whether traditional patching SLAs are sufficient in the age of AI and suggests that dependency maintenance should be considered part of the security perimeter. Join the discussion | Reddit Cybersecurity | 09/12/2026, 20:15:10 UTC Added: 09/12/2026, 20:46:25 UTC |
The BlueMoon exploit kit chains together three zero-day vulnerabilities—two in Chrome's V8 engine and one in Windows ALPC—to achieve sandbox escape and privilege escalation. Initially used by the China-linked APT Violet Typhoon, it has rapidly proliferated among multiple espionage-motivated threat actors targeting NGOs, aerospace, manufacturing, government, consulting, and financial sectors across the US and Southeast Asia. The vulnerabilities in Chrome were patched on September 3 and 8, 2026, and the Windows privilege escalation was fixed in the September 2026 Patch Tuesday update. BlueMoon's rapid adoption and sharing among threat actors may reflect lowered barriers to exploit development, potentially aided by AI. The exploit kit downloads and executes payloads after successful exploitation. Join the discussion | SecurityWeek | 09/12/2026, 11:10:00 UTC Added: 09/12/2026, 11:17:07 UTC |
Anthropic says multiple threat groups, including the financially motivated and state-sponsored espionage groups linked to Russia and China, tried to abuse its Claude AI model for malicious purposes. [...] Join the discussion | Bleeping Computer | 09/11/2026, 20:19:09 UTC Added: 09/11/2026, 20:31:58 UTC |
A joint Tenable-SentinelOne analysis of 93 CVE-actor attribution pairs reveals that both state-sponsored actors and cybercriminals independently converge on the same edge infrastructure. Special thanks to SentinelOne® Incident Readiness & Response for their contributions to this publication. It is the shared attack surface where state-sponsored threat actors and financially motivated criminal groups independently converge — not the province of a single adversary category, and not exclusively a nation-state problem, despite two years of headlines about China-nexus actors targeting Ivanti, Fortinet, and Palo Alto Networks. The data here tells a different and much broader story. One focused on vendors vs CVEs. Key Takeaways Two independent observation systems, Tenable exposure telemetry across thousands of customer containers and SentinelOne DFIR casework across 66 CVEs, converge 79% on the same vendor attack surfaces despite minimal CVE-level overlap. Twelve CVEs in the combined dataset have confirmed multi-nexus attribution: state-sponsored and criminal actors independently exploiting the same vulnerability, across five nexus categories (China, Russia, DPRK, Iran, ransomware). The exposure picture is flatter than the headlines suggest: Fortinet, the vendor most associated with edge-device attacks in the press, sits mid-pack on container-grain exposure (25%) — well behind F5 (54%) and in a tight 10-point band with Check Point, Ivanti, and Citrix. 54% of customer environments running F5 products have at least one exposed, actively-exploited CVE; Citrix customers show the slowest remediation patterns at 461 days median time to patch. Remediation complexity, particularly of high priority CVEs, leads to a statistically significant 24-day remediation gap, leaving large windows of opportunity for attackers. The same product lines get hit again and again: Ivanti EPMM and Ivanti Connect Secure each show a newly exploited CVE roughly every 8.5 to 13 months. Leverage multiple defense-in-depth strategies: patch as quickly as possible, but also minimize the attack surface (feature-set minimization) and run endpoints in protect mode to better stop lateral movement from attacks that gain initial access. The convergence is the story Twelve CVEs in the combined dataset have confirmed multi-nexus attribution: state-sponsored and criminal actors independently exploiting the same vulnerability, across five nexus categories. Four examples illustrate the pattern: CVE Product Actors (Nexus) Significance CVE-2026-15409 SonicWall SMA1000 UTA0533 (unattributed) + INC Ransomware Espionage-to-ransomware succession on an active zero-day CVE-2023-42793 JetBrains TeamCity APT29 (Russia) + Lazarus (DPRK) Two state-sponsored actors from different nations on the same CVE CVE-2024-3400 PAN-OS GlobalProtect UTA0218 (China) + INC Ransomware China-nexus zero-day reused by ransomware operators CVE-2024-24919 Check Point Quantum PurpleHaze (China) + Fox Kitten (Iran) China and Iran independently exploiting the same gateway vulnerability The remaining eight confirmed multi-nexus CVEs span Fortinet, Citrix, Cisco, and Ivanti product lines. State-sponsored actors and ransomware operators are not operating in separate vulnerability ecosystems. They share the same entry points into the same products. The breadth of the convergence, not any single actor's activity, is the finding. That pattern holds across the full combined analysis. Three conclusions emerge: Vendor attack surfaces are the persistent exploitation target. The same eleven vendors (i.e., Fortinet, Citrix, Ivanti, Palo Alto Networks, Cisco, Juniper, VMware, Microsoft, Oracle, CrushFTP, and Meta's React framework ) appear in both observation systems at 79% convergence, and all seven edge-product vendors converge. Serial exploitation timing on Ivanti products shows the vulnerability-to-exploitation pipeline refreshing at 8.5 to 13-month intervals on the same product lines. This is structural, not episodic. Patch… Join the discussion | CVE Database V5 | 09/10/2026, 17:48:31 UTC Added: 07/14/2026, 20:03:48 UTC |
The BlueMoon exploit kit is a modular tool used by multiple cyber-espionage groups to chain zero-day vulnerabilities in Microsoft Windows and Google Chrome. It combines two Chromium-based browser flaws allowing remote code execution and sandbox escape with a Windows kernel local privilege escalation. Observed since August 2026, BlueMoon has been deployed by Chinese state-sponsored actors targeting NGOs, aerospace, defense, and manufacturing sectors. The kit exploits delays in Chrome stable releases to weaponize recent Chromium fixes. It executes payloads by elevating Chrome renderer privileges and injecting commands to download and run malware loaders. Join the discussion | Bleeping Computer | 09/10/2026, 14:11:34 UTC Added: 09/10/2026, 14:22:17 UTC |
Google's Threat Intelligence Group (GTIG) warns that both criminal and state-sponsored threat actors are increasingly leveraging AI to automate and scale cyberattacks. This use of AI enables lesser-resourced attackers to operate at a scale and speed comparable to nation-state groups. Examples include AI-assisted mass credential harvesting campaigns and exploitation of open source software supply chains. Various nation-state actors, including groups linked to China, Iran, and North Korea, are integrating AI throughout their attack lifecycles for reconnaissance, malware development, social engineering, and cryptocurrency theft. Google actively disrupts adversarial AI projects and hardens its models against misuse, but the rapid evolution of AI-assisted attacks presents ongoing challenges. The threat landscape is evolving with AI as a force multiplier, increasing attack speed and scale without fundamentally changing the persistent nature of cybersecurity conflicts. Join the discussion | SecurityWeek | 09/09/2026, 16:56:25 UTC Added: 09/09/2026, 17:07:15 UTC |
North Korean-aligned threat actors have deployed a sophisticated Linux espionage toolkit targeting automotive and media organizations in South Korea. The toolkit embeds a custom backdoor within HAProxy version 2.8.12, enabling stealthy long-term surveillance through HTTP traffic interception and injection. It also includes trojanized Linux tools and a curl-based RAT for remote command execution, credential harvesting, and persistence. Initial access was gained via exploitation of a Groupware login portal vulnerability. The campaign uses watering-hole techniques and mimics legitimate web traffic to evade detection. The activity is attributed to North Korean threat actors, likely linked to Lazarus or APT37 groups. No patch or remediation guidance is provided in the source. Join the discussion | SecurityWeek | 09/07/2026, 12:12:08 UTC Added: 09/07/2026, 12:22:14 UTC |
Showing 1 to 10 of 176 results