Skip to content

English

At least 80 organizations targeted by the China-backed APT41 worldwide last year

At least 80 organizations targeted by the China-backed APT41 worldwide last year

4 malicious campaigns, 13 confirmed victims, and a new wave of Cobalt Strike infections The state-sponsored hacker group APT41 (aka ARIUM, Winnti, LEAD, WICKED SPIDER, WICKED PANDA, Blackfly, Suckfly, Winnti Umbrella, Double Dragon), whose goals are cyber espionage and financial gain, has been active since at least 2007. Group-IB Threat

Members Public
New Evil PLC Attack Weaponizes PLCs To Intrude OT and Enterprise Networks

New Evil PLC Attack Weaponizes PLCs To Intrude OT and Enterprise Networks

Team82 has developed a novel attack that weaponizes programmable logic controllers (PLCs) in order to exploit engineering workstations and further invade OT and enterprise networks. We’re calling this the Evil PLC Attack. Download the full report here (free PDF). The attack targets engineers working every day on industrial networks,

Members Public
Disrupting SEABORGIUM’s ongoing phishing operations

Disrupting SEABORGIUM’s ongoing phishing operations

The Microsoft Threat Intelligence Center (MSTIC) has observed and taken actions to disrupt campaigns launched by SEABORGIUM, an actor Microsoft has tracked since 2017. SEABORGIUM is a threat actor that originates from Russia, with objectives and victimology that align closely with Russian state interests. Its campaigns involve persistent phishing and

Members Public
Iron Tiger Compromises Chat Application MiMi, Targets Windows, Mac, and Linux Users

Iron Tiger Compromises Chat Application MiMi, Targets Windows, Mac, and Linux Users

CTI (Cyber Threat Intelligence) analysis by Trend Micro of a cyber espionage campaign of Iron Tiger APT (Advanced Persistent Threat) group. Iron Tiger (also known as Emissary Panda, APT27, Bronze Union, and Luckymouse) compromising chat application Mimi’s servers in a supply chain attack by HyperBro malware. MiMi is an

Members Public
Pro-Kremlin hackers target Latvia’s parliament after declaring Russia a sponsor of terrorism

Pro-Kremlin hackers target Latvia’s parliament after declaring Russia a sponsor of terrorism

The pro-Russian hacker gang known as Killnet took down the website of Latvia’s parliament on Thursday after lawmakers there designated Russia as a “state sponsor of terrorism.” The parliament’s website went down for several hours after being hit by a distributed denial-of-service (DDoS) attack, which floods websites with

Members Public
Cisco hacked by Yanluowang ransomware gang

Cisco hacked by Yanluowang ransomware gang

On May 24, 2022, Cisco became aware of a potential compromise. Since that point, Cisco Security Incident Response (CSIRT) and Cisco Talos have been working to remediate. Cisco has updated its security products with intelligence gained from observing the bad actor’s techniques, shared Indicators of Compromise (IOCs) with other

Members Public