Threats Tagged 'cyber espionage'
View all threats tagged with 'cyber espionage'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cyber espionage'
Click on any threat for detailed analysis and mitigation recommendations
Inside cyber espionage infrastructure 0 A China-nexus infrastructure provider operates as a 'quartermaster' offering reconnaissance, proxy orchestration, and traffic routing services to Chinese cyber espionage actors. The operation consists of four interconnected components: QScan for target reconnaissance, Fast Labyrinth providing encrypted relay networks through co-opted commercial proxy infrastructure, QTRouter managing access to proxy systems, and QTProxy controlling operational nodes. The infrastructure targets research universities, defense networks, government agencies, and critical infrastructure globally, particularly in the U.S., U.K., and Asia-Pacific regions. By exploiting commercial 'Airport' proxy services designed to bypass China's Great Firewall, specifically fastlink.ws, the quartermaster enables multiple threat actors to conduct operations while maintaining anonymity through shared infrastructure, representing a significant evolution in state-sponsored cyber operations. Join the discussion | AlienVault OTX General | 08/26/2026, 22:00:43 UTC Added: 08/27/2026, 22:07:26 UTC |
Analysis of a Modular Cyber Espionage Framework 0 Security researchers have uncovered a sophisticated cyber espionage operation deploying two previously undocumented malware families, OctLurk and SilkLurk, targeting government and public-sector organizations across Central Asia and the Middle East. Both modular backdoors utilize victim-specific decryption mechanisms, extensive obfuscation, and in-memory execution to evade detection. The malware enables credential theft, remote access, network reconnaissance, and plugin-based expansion. Operations began in January 2025, affecting entities in Afghanistan, Kazakhstan, Kyrgyzstan, Syria, Tajikistan, and Uzbekistan. Victims include government offices, foreign affairs ministries, law enforcement agencies, healthcare providers, logistics organizations, research institutions, urban planning facilities, and educational establishments. Attackers deployed additional tools including Impacket's SecretsDump, Browser Password Decryptor, Pandora RC, Fscan, WinRAR, 7-Zip, and PlugX. A companion utility, LurkProxy, proxies a Join the discussion | AlienVault OTX General | 08/07/2026, 10:23:00 UTC Added: 08/07/2026, 10:26:18 UTC |
Showing 1 to 2 of 2 results