Threats Tagged 'cyber-espionage'
View all threats tagged with 'cyber-espionage'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cyber-espionage'
Click on any threat for detailed analysis and mitigation recommendations
Expands Toolset With New Backdoor, SSH Tunnel 0 The Iranian-linked cyber-espionage group Tortoiseshell has expanded its malware toolkit with a new reverse SSH tunneling utility disguised as wtsapi32.dll and a C++ backdoor similar to TWOSTROKE malware. The SSH tunnel uses the Windows OpenSSH client to connect to command-and-control servers. The backdoor supports executing files, shell commands, in-memory DLL execution, and file manipulation. Infrastructure analysis shows domains linked to multiple countries including the UAE, Saudi Arabia, UK, Belgium, Canada, Australia, Japan, and the United States, indicating broader targeting beyond the Middle East and US defense and military sectors. The group has been active since 2018 and maintains persistent infrastructure despite domain suspensions. No known exploits in the wild or patches are reported. Join the discussion | AlienVault OTX General | 08/26/2026, 17:18:24 UTC Added: 08/26/2026, 18:37:18 UTC |
New Armored Likho tools target Telegram and eavesdropping 0 In May 2026, a cyber-espionage campaign by the Armored Likho group (also known as Eagle Werewolf) targeted private individuals and organizations across Russia, including major corporations, public sector entities, IT companies, and educational institutions. The attackers employed fake donation service applications as initial infection vectors. The campaign introduced the Still Toolkit, comprising two Rust-based components: Still Sync, which steals Telegram session data and leverages the Telegram API to extract chat logs and media files, and Still Audio, an implant that conducts covert audio surveillance by detecting speech patterns and recording conversations. The toolkit demonstrates sophisticated capabilities including Dead Drop Resolver techniques, RMS-based voice activity detection, and gRPC-based C2 communications. The campaign shows significant code overlap with previous Armored Likho operations, particularly from February 2026, including identical dropper architecture, encryption algorithms, and inf... Join the discussion | AlienVault OTX General | 08/14/2026, 10:35:18 UTC Added: 08/13/2026, 13:26:13 UTC |
Showing 1 to 2 of 2 results