Advanced Persistent Threat (APT) stories
China-aligned TA416 resumes spying on EU & Mideast
Last week
#
phishing
#
email security
#
cybersecurity
China-linked TA416 returns to spying on European diplomats and later expands attacks to Middle Eastern government targets after Iran conflict.
DeepLoad malware steals credentials via ClickFix campaign
This month
#
malware
#
firewalls
#
network infrastructure
ReliaQuest flags DeepLoad malware stealing live credentials in enterprise networks, with AI-style obfuscation, USB spread and hidden WMI persistence.
Commvault adds threat-hunting tools to backup scans
Last month
#
data protection
#
dr
#
ransomware
Commvault adds Hyper Threat Hunting and Deep Inspection to Cloud Threat Scan, linking backup scanning with verified clean recovery after cyber attacks.
China-linked Red Menshen hides inside telecoms networks
Last month
#
uc
#
advanced persistent threat protection
#
supply chain
Rapid7 says China-linked Red Menshen has planted dormant “sleeper cells” inside global telecoms networks to quietly maintain long-term access.
NCC Group warns Iran cyber threats spread worldwide
Last month
#
gaming
#
firewalls
#
network security
Iran-linked cyber attacks are spreading beyond the Middle East, with firms tied to Israel or the US warned they face heightened global risk.
Fake Red Alert app used in Android spyware smishing
Last month
#
endpoint protection
#
mdm
#
phishing
Attackers push fake Red Alert Android app via SMS, turning Israel rocket warning tool into spyware that steals messages, contacts and location.
Conflict sparks surge in Middle East cyber espionage
Last month
#
phishing
#
email security
#
cybersecurity
New research links Iran conflict to a swift surge in tightly targeted cyber espionage across Middle Eastern governments and embassies.
Google report warns identity is weak link in cloud
Last month
#
malware
#
ransomware
#
hybrid cloud
Attackers are ditching malware for stolen identities, misconfigurations and abused AI tools, Google warns in its latest cloud threat report.
Kernel in the crosshairs: The BlackSanta threat campaign targeting recruitment workflows
Last month
#
storage
#
phishing
#
hcm
A stealthy BlackSanta malware spree is hijacking HR recruitment workflows, killing endpoint defence tools and exfiltrating sensitive data.
Bitdefender warns of AI 'vibeware' targeting India
Last month
#
malware
#
firewalls
#
network security
Bitdefender flags AI-powered 'vibeware' malware blitz hitting Indian government targets, using niche languages to overwhelm defences.
Google disrupts China-linked cyber espionage on telecoms
Thu, 26th Feb 2026
#
malware
#
firewalls
#
data protection
Google says it has crippled a China-linked cyber espionage group accused of hacking telecoms and governments in at least 42 countries.
LockBit 5.0 ransomware targets Windows, Linux, ESXi
Wed, 18th Feb 2026
#
malware
#
virtualisation
#
data protection
New LockBit 5.0 ransomware hits Windows, Linux and ESXi in single campaigns, widening blast radius across mixed and virtualised environments.
Okta warns of North Korean fraud in remote tech hiring
Fri, 13th Feb 2026
#
data protection
#
ransomware
#
hcm
Okta warns North Korean operatives are landing remote tech jobs with stolen and synthetic identities to fund the regime and enable cyber attacks.
Hackers ditch noisy ransomware for stealthy data theft
Thu, 12th Feb 2026
#
firewalls
#
data protection
#
dr
Hackers are abandoning noisy ransomware to quietly steal data, as a report finds 80% of top attack techniques now focus on evasion.
Espionage Without Noise: Understanding APT36's Enduring Campaigns
Wed, 11th Feb 2026
#
ddos
#
surveillance
#
supply chain
Indian defence faces a decade-long silent siege as APT36 refines cross-platform cyber espionage with stealthy, persistent RAT campaigns.
CrowdStrike splits LABYRINTH CHOLLIMA into three units
Fri, 30th Jan 2026
#
malware
#
manufacturing
#
crypto
CrowdStrike has split North Korea-linked LABYRINTH CHOLLIMA into three units, two for crypto theft and one for industrial espionage.
LOTUSLITE backdoor targets US policy bodies with lures
Thu, 22nd Jan 2026
#
phishing
#
advanced persistent threat protection
#
email security
Politically themed LOTUSLITE phishing campaign hits US policy bodies, using DLL sideloading and espionage-focused backdoor tactics.
LinkedIn DMs abused to spread Python-based malware
Wed, 21st Jan 2026
#
firewalls
#
endpoint protection
#
devops
Attackers are abusing LinkedIn private messages to deliver Python-based malware via booby-trapped archives, ReliaQuest has warned.
Silver Fox APT & PowerG flaws expose key security risks
Tue, 13th Jan 2026
#
uc
#
encryption
#
iot security
NCC Group links Silver Fox's false-flag malware campaigns to ValleyRAT and uncovers critical PowerG flaws that can fully compromise alarms.
US cyber attack on Venezuela exposes CNI vulnerabilities
Thu, 8th Jan 2026
#
surveillance
#
iot security
#
socs
Alleged US cyber role in Venezuela attack exposes how multi-domain operations can silently compromise critical national infrastructure.