Skip to main content

Threats Tagged 'cyber-espionage'

View all threats tagged with 'cyber-espionage'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: cyber-espionage

Threats Tagged 'cyber-espionage'

Click on any threat for detailed analysis and mitigation recommendations

The Iranian-linked cyber-espionage group Tortoiseshell has expanded its malware toolkit with a new reverse SSH tunneling utility disguised as wtsapi32.dll and a C++ backdoor similar to TWOSTROKE malware. The SSH tunnel uses the Windows OpenSSH client to connect to command-and-control servers. The backdoor supports executing files, shell commands, in-memory DLL execution, and file manipulation. Infrastructure analysis shows domains linked to multiple countries including the UAE, Saudi Arabia, UK, Belgium, Canada, Australia, Japan, and the United States, indicating broader targeting beyond the Middle East and US defense and military sectors. The group has been active since 2018 and maintains persistent infrastructure despite domain suspensions. No known exploits in the wild or patches are reported.

Join the discussion

In May 2026, a cyber-espionage campaign by the Armored Likho group (also known as Eagle Werewolf) targeted private individuals and organizations across Russia, including major corporations, public sector entities, IT companies, and educational institutions. The attackers employed fake donation service applications as initial infection vectors. The campaign introduced the Still Toolkit, comprising two Rust-based components: Still Sync, which steals Telegram session data and leverages the Telegram API to extract chat logs and media files, and Still Audio, an implant that conducts covert audio surveillance by detecting speech patterns and recording conversations. The toolkit demonstrates sophisticated capabilities including Dead Drop Resolver techniques, RMS-based voice activity detection, and gRPC-based C2 communications. The campaign shows significant code overlap with previous Armored Likho operations, particularly from February 2026, including identical dropper architecture, encryption algorithms, and inf...

Join the discussion

Two newly identified backdoors, OctLurk and SilkLurk, have been targeting government organizations across Central Asia since January 2025. Victims span Afghanistan, Kyrgyzstan, Tajikistan, Uzbekistan, Kazakhstan, and Syria, affecting healthcare, research, government offices, ministries of foreign affairs, logistics, law enforcement, urban planning, and educational institutions. Both backdoors employ heavily obfuscated loaders customized per victim, using machine-specific data for decryption. They deploy multiple plugins for command execution, file manipulation, credential harvesting, keylogging, network scanning, and remote access. The attackers also utilized LurkProxy for network traffic proxying and deployed additional tools including PlugX, Impacket, FSCAN, and Pandora FMS agents. Analysis indicates both backdoors are operated by the same Chinese-speaking threat actor, though attribution to a specific known group remains unconfirmed. The campaigns demonstrate sophisticated persistence mechanisms and ext...

Join the discussion

The Confucius group, a long-running cyber-espionage actor operating in South Asia, has evolved its tactics from document stealers to Python-based backdoors. Recent campaigns showcase the group's adaptability and growing sophistication, targeting government agencies, military organizations, and critical industries, particularly in Pakistan. The group has transitioned from using WooperStealer to deploying a Python variant of AnonDoor, demonstrating their ability to pivot between techniques, infrastructure, and malware families. Their attack chain includes weaponized Office documents, malicious LNK files, and multiple malware families, employing obfuscation techniques to evade detection. The group's persistence and rapid adaptation highlight the ongoing threat posed by state-aligned malware campaigns in the region.

Join the discussion

RedNovember, a Chinese state-sponsored threat group, has expanded its cyber-espionage activities globally. The group targets high-profile government, intergovernmental, and private sector organizations, focusing on defense, aerospace, and technology sectors. It uses the Go-based backdoor Pantegana and Cobalt Strike for intrusions, exploiting vulnerabilities in perimeter appliances. RedNovember's tactics include combining weaponized proof-of-concept exploits with open-source tools, allowing for scalable operations and attribution obfuscation. The group has shown particular interest in targets across the US, Taiwan, South Korea, and Panama, often aligning its activities with geopolitical events and Chinese strategic interests.

Join the discussion

APT36, a Pakistan-based threat actor, is conducting a cyber-espionage campaign against Indian Government entities, targeting BOSS Linux systems with weaponized .desktop files. The group uses spear-phishing emails to deliver malicious payloads, exploiting the Linux environment to maintain persistent access and evade security controls. The campaign involves sophisticated tactics, including the use of custom malware, command and control servers, and data exfiltration techniques. The attackers leverage newly registered domains and employ various MITRE ATT&CK techniques to execute their operations. This activity demonstrates APT36's increasing sophistication and adaptability in targeting critical government infrastructure.

Join the discussion

APT36, a Pakistan-based threat actor, has launched a sophisticated cyber-espionage campaign targeting the Indian defense sector. The group has adapted its tactics to focus on Linux-based environments, particularly BOSS Linux, used by Indian government agencies. The attack involves phishing emails with a ZIP file containing a malicious .desktop file. When executed, it downloads a legitimate PowerPoint file as a decoy while simultaneously deploying a malicious ELF binary. This multi-stage approach aims to bypass user suspicion and evade traditional security measures. The campaign signifies an advancement in APT36's capabilities and poses an increased risk to critical government and defense infrastructure. Organizations using Linux-based systems are advised to implement robust cybersecurity controls and threat detection mechanisms to mitigate potential risks.

Join the discussion

Showing 1 to 7 of 7 results

Filters:Tag: cyber-espionage
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses