Chinese hackers compromised an ISP to deliver malicious software updates

APT StormBamboo compromised a undisclosed internet service provider (ISP) to poison DNS queries and thus deliver malware to target organizations, Volexity researchers have shared. Malware delivery via automatic software updates StormBamboo (aka Evasive… Continue reading Chinese hackers compromised an ISP to deliver malicious software updates

CloudSorcerer – A new APT targeting Russian government entities

Kaspersky discovered a new APT CloudSorcerer targeting Russian government entities and using cloud services as C2, just like the CloudWizard actor. Continue reading CloudSorcerer – A new APT targeting Russian government entities

Chinese hackers are increasingly deploying ransomware, researchers say

Elite state-backed hackers are embracing the use of ransomware to obfuscate their operations. 

The post Chinese hackers are increasingly deploying ransomware, researchers say appeared first on CyberScoop.

Continue reading Chinese hackers are increasingly deploying ransomware, researchers say

Chinese cyber espionage campaign targets ‘dozens’ of Western governments, Dutch officials say

The ongoing operation claims international organizations and the defense industry as its victims, per authorities.

The post Chinese cyber espionage campaign targets ‘dozens’ of Western governments, Dutch officials say appeared first on CyberScoop.

Continue reading Chinese cyber espionage campaign targets ‘dozens’ of Western governments, Dutch officials say

Chinese attackers leverage previously unseen malware for espionage

Sophos released its report, “Operation Crimson Palace: Threat Hunting Unveils Multiple Clusters of Chinese State-Sponsored Activity Targeting Southeast Asia,” which details a highly sophisticated, nearly two-year long espionage campaign against a high-… Continue reading Chinese attackers leverage previously unseen malware for espionage

Moonstone Sleet: A new North Korean threat actor

Microsoft has named yet another state-aligned threat actor: Moonstone Sleet (formerly Storm-1789), which engages in cyberespionage and ransomware attacks to further goals of the North Korean regime. “Moonstone Sleet uses tactics, techniques, and … Continue reading Moonstone Sleet: A new North Korean threat actor

Trusted relationship attacks: trust, but verify

We analyze the tactics and techniques of attackers targeting organizations through trusted relationships – that is, through contractors and external IT service providers. Continue reading Trusted relationship attacks: trust, but verify