Nation-State Cyber Threats
ESET Publishes OceanLotus (APT32) Research Update — Domestic Targeting in Vietnam
ESET's research update reframes OceanLotus — the targeting is now inward.
Coverage of nation-state cyber threats, including government-backed hackers, cyber espionage campaigns, and geopolitical cyberattacks targeting critical infrastructure and global organizations.
Nation-State Cyber Threats
ESET's research update reframes OceanLotus — the targeting is now inward.
Nation-State Cyber Threats
Another indictment in a Russia-aligned case — but unlike most, this defendant is already in US custody after an extradition from Thailand.
Nation-State Cyber Threats
Consumer compression software remains a reliable initial-access vector in the Russia-Ukraine cyber theater.
Nation-State Cyber Threats
A small-footprint, long-tail Chinese proxy network grows past 1,500 devices — defenders should account for this layer of reconnaissance infrastructure.
Nation-State Cyber Threats
ReliaQuest disclosed OP-512, a previously unreported, China-linked espionage cluster that plants a custom three-web-shell framework on Microsoft IIS servers — the fourth such group to target IIS in a year. For anyone running IIS, it is a prompt to go hunting.
Artificial Intelligence (AI)
Two Mythos threads landed this cycle: TechCrunch reports the NSA is said to be readying Anthropic's Mythos for cyber operations despite a federal restriction, while Anthropic published an analysis of 832 accounts banned for malicious cyber activity, mapped to MITRE ATT&CK.
Nation-State Cyber Threats
A joint Five Eyes advisory warns that Chinese intelligence officers, posing as recruiters and consultants for front companies, are using LinkedIn, Indeed and Upwork to recruit government, military and cleared personnel — and anyone with access to classified or privileged information.
Policy & Government
The Pentagon's top cyber official, Katherine Sutton, says the Defense Department must pull cyber 'out of its silo' and build it into every operation from day one — and must bake security into the AI tools it adopts, rather than treating it as an afterthought.
Iranian Threat Actors
Recorded Future's Insikt Group says Iran's intelligence ministry has expanded its Handala hacking brand into an umbrella for hybrid operations — uniting cyber, physical and influence personas that recruit proxies, for cash, to attack, surveil and sabotage US and Israeli interests.
Nation-State Cyber Threats
Seqrite Labs says the Pakistan-aligned group SideCopy likely ran Operation XENOFISCAL, a spear-phishing campaign that hit Afghanistan's Ministry of Finance and provincial finance offices with the open-source Xeno RAT, delivered through a Pashto-language ZIP-and-LNK lure.
Nation-State Cyber Threats
Seqrite Labs disclosed Operation Dragon Weave, a China-aligned cyber-espionage campaign delivering an AdaptixC2 agent against government, research, academic, technology, and financial-services targets in the Czech Republic and Taiwan via spear-phishing ZIPs.
Nation-State Cyber Threats
Sekoia documented an FSB-linked Gamaredon campaign whose GammaWorm hides fileless VBScript modules inside NTFS Alternate Data Streams to spy on Ukrainian government, military, and critical-infrastructure targets while leaving almost no trace on disk.