Threats Tagged 'diplomatic targeting'
View all threats tagged with 'diplomatic targeting'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'diplomatic targeting'
Click on any threat for detailed analysis and mitigation recommendations
Between late September 2025 and early April 2026, the threat group BlueDelta conducted espionage campaigns targeting government and diplomatic organizations in Romania, Spain, and Türkiye. They deployed HOOKEDGE, a lightweight Windows batch-script backdoor, via macro-enabled Word documents with diplomatic-themed lures. HOOKEDGE shares code and tradecraft overlap with the HEADLACE backdoor and abuses legitimate webhook services for command-and-control, payload staging, and data exfiltration. The implant was continuously refined to evade sandbox detection and adapt to webhook service constraints. BlueDelta used a tiered operational model, deploying second-stage payloads with shorter beaconing intervals for high-value targets while preserving initial access infrastructure. Join the discussion | AlienVault OTX General | 08/27/2026, 17:37:41 UTC Added: 08/28/2026, 09:07:13 UTC |
Kazuar is a sophisticated malware attributed to Russian state actor Secret Blizzard, having evolved from a traditional backdoor into a highly modular peer-to-peer botnet ecosystem. The malware comprises three distinct module types—Kernel, Bridge, and Worker—that distribute functionality across infected systems. A leadership election mechanism ensures only one Kernel module communicates externally, reducing detection opportunities. The architecture supports flexible configuration with over 150 options, multiple C2 channels including HTTP, WebSockets, and Exchange Web Services, and extensive data collection capabilities. Secret Blizzard primarily targets government, diplomatic, and defense organizations in Europe, Central Asia, and Ukraine to support Russian foreign policy and military intelligence objectives. The botnet maintains persistent access through sophisticated IPC mechanisms, staged data exfiltration during working hours, and comprehensive anti-analysis checks. Join the discussion | AlienVault OTX General | 05/14/2026, 20:10:32 UTC Added: 05/15/2026, 18:51:38 UTC |
The Chinese-affiliated threat actor UNC6384 is exploiting the ZDI-CAN-25373 Windows vulnerability to deploy PlugX malware targeting European diplomatic entities, specifically in Hungary and Belgium. The attack vector involves spearphishing emails with malicious LNK files themed around diplomatic conferences. The campaign uses DLL side-loading of legitimate Canon printer utilities to evade detection and maintain persistence. UNC6384’s operations have expanded from Southeast Asia to Europe, focusing on espionage related to foreign policy, defense, and economic matters. This campaign demonstrates advanced social engineering and rapid exploitation of new vulnerabilities. The malware provides persistent remote access for intelligence gathering. No known public exploits exist yet, but the threat is active and targeted. The medium severity rating reflects the targeted nature and complexity of the attack. European diplomatic organizations should prioritize mitigation to protect sensitive information and maintain operational security. Join the discussion | AlienVault OTX General | 10/31/2025, 08:35:27 UTC Added: 10/31/2025, 09:08:46 UTC |
Showing 1 to 3 of 3 results