- 'Hi, This Is IT': Vishing Campaign Turns Microsoft Teams into Attack Surface 2026-09-03 18:03 SecureWorld For years, security teams trained employees to distrust suspicious emails: strange sender addresses, sloppy grammar, a link that doesn't quite match the domain it claims to come from. A new campaign uncovered by Palo Alto Networks' Unit 42 shows …
- BraZetsu Malware Turns Compromised Windows Hosts Into Criminal Marketplace Inventory 2026-09-03 17:43 The Hacker News Cybersecurity researchers have disclosed details of a sophisticated Python-based Windows malware framework called BraZetsu that fuels an underground marketplace commercializing access to compromised hosts. "Unlike the standard infostealer model, …
- IT helpdesk impersonation hits Microsoft Teams once again, with the hackers hiding their activity within legitimate tools 2026-09-03 17:03 TechRadar Follow us Add us as a preferred source on Google Newsletter Subscribe to our newsletter Microsoft warns of Teams‑based campaign where attackers impersonate IT staff Victims tricked into granting remote access, leading to malware, lateral movement, and …
- Hackers’ Own Malware Infection Exposes Their RATs, Phishing Kits and Attack Infrastructure 2026-08-31 07:46 Cyber Security News A malware investigation has exposed the tools and infrastructure used by suspected operators behind a Blind Eagle-linked campaign targeting Colombia and the wider region. The break came after an apparent attacker workstation was infected by a separate …
- Undeclared War Season 2 On Peacock: Sandworm Already Ran This Playbook 2026-08-27 18:01 Tech Times The Undeclared War Season 2 dropped on Peacock today with a claim embedded in its premise that creator Peter Kosminsky has made since the beginning: nothing in the show is invented. Every scenario — the mole inside GCHQ, the Russian malware hiding inside …
- Russian Cyber Espionage Infrastructure Uses Evilginx and OAuth Phishing to Steal Accounts 2026-08-27 09:01 GBHackers Russian-linked cyber espionage operators are expanding account-compromise operations by combining OAuth abuse, device-code phishing, credential-harvesting infrastructure, and suspected Evilginx reverse-proxy setups. GTIG assesses with moderate confidence …
- Nimbus Manticore Expands Toolset With TWOSTROKE-Like Backdoor and SSH Tunneler 2026-08-26 16:45 The Hacker News Ravie LakshmananAug 26, 2026Malware / Cyber Espionage Cybersecurity researchers have discovered additional infrastructure and previously undocumented malware associated with Nimbus Manticore, an Iranian state-sponsored hacking group affiliated with …
- Iranian Hackers Breach UK Power Plant via Compromised Contractor in Major OT Attack 2026-08-25 11:58 WebProNews - Kentucky The cyber incident that forced a temporary shutdown of a UK power plant last month has brought renewed attention to the persistent threats posed by state-sponsored hacking groups. According to a detailed report published by The Register, the attack has …
- Your MFA Won’t See This: Identity Security’s Blind Spot Inside Teams… 2026-08-21 19:06 Cybersecurity Insiders The moment an attacker owns a valid collaboration account, their phishing and file transfers look like ordinary teamwork, and controls built around email and the login screen never fire. Unit 42, the Palo Alto Networks threat-research team, calls this the …
- Poland’s CERT Warns of Active Exploitation of Critical Zimbra Collaboration Suite Flaw 2026-08-21 14:27 Security Affairs Poland’s CERT Warns of Active Exploitation of Critical Zimbra Collaboration Suite Flaw CERT Polska confirmed active exploitation of CVE-2026-73570, a critical unauthenticated RCE in Zimbra Collaboration Suite patched on July 20. CERT Polska, Poland’s …
- Fake Conferences, OAuth and WhatsApp: Inside Russia’s New Espionage Tactics 2026-08-21 14:23 Security Affairs Fake Conferences, OAuth and WhatsApp: Inside Russia’s New Espionage Tactics Google tracks three Russia-linked espionage clusters using phishing and legitimate authentication tools to target researchers, diplomats and defense staff. Google’s Threat …
- Suspected Russian Hackers Abuse Google OAuth and WhatsApp Linking to Hijack Accounts 2026-08-20 22:28 The Hacker News Three distinct suspected Russian cyber espionage threat clusters have been observed leveraging legitimate authentication flows to single out individuals working in academia, aerospace and defense, governments, and think tanks across Europe, as well as …
- Hackers breach Polish plant through private mobile network 2026-08-11 17:00 Arabian Post Hackers penetrated a Polish combined heat and power plant through a private cellular network, manipulating industrial controllers and temporarily halting cogeneration at a facility supplying heat to about 50,000 residents. The attack has exposed a …
- Poland's Water Hack Prosecution Names Russians But Can't Reach Them: Default Passwords Opened Plants 2026-08-11 14:35 Tech Times Poland formally charged two Russian nationals for a campaign of 17 cyberattacks on critical infrastructure including seven water and wastewater treatment plants — the first criminal prosecution under Polish law targeting Russian-linked hackers specifically …
- Do not use free hotel Wi-Fi, Microsoft warns travellers 2026-08-10 09:03 India Today Do you frequently use free hotel Wi-Fi while travelling? It’s convenient and can help you get quick access to the internet if your mobile data is not working. But as helpful as it is, you should probably not trust it. Microsoft warns that using free Wi-Fi …
- Microsoft warns travellers of attacks on hotel Wi-Fi; says: Hackers can record your video, audio, steal passwords; how to know and protect yourself 2026-08-10 03:07 The Times of India Microsoft’s Threat Intelligence team has issued a warning to travelers following a series of sophisticated cyberattacks targeting guest Wi-Fi networks at hotels and hospitality venues worldwide. The internet hijacking campaign, dubbed ‘CaptiveCrunch’, has …
- Russian Hackers Exploit Hotel Wi-Fi Networks to Compromise Microsoft 365 Accounts 2026-08-07 11:38 CPO Magazine Microsoft has warned that the Russian advanced persistent threat actor Storm-2945, a sub-cluster of Midnight Blizzard or APT29, is exploiting hotel Wi-Fi networks to breach Microsoft 365 accounts and install custom malware. Midnight Blizzard is linked to …
- SVR Hacked Hotel Login Screens To Plant CornFlake Spyware On Corporate Laptops 2026-08-06 19:02 Tech Times Russia's Foreign Intelligence Service has been running a six-month corporate espionage campaign — named CaptiveCrunch by Microsoft — that turns hotel Wi-Fi login screens into malware delivery systems, deploying three custom-built surveillance tools …
- Microsoft warns travelers of Russian hackers hijacking hotel Wi-Fi networks to steal account credentials 2026-08-06 00:48 TweakTown A Russian hacking group known as Midnight Blizzard, or Cozy Bear, has been running a campaign that specifically targets hotel Wi-Fi networks to get into the devices of government officials, diplomats, and defense industry employees while they travel. …
- 10 PS4 JRPGs Where the Villain Feels More Compelling Than the Hero 2026-08-05 03:41 DualShockers If you ask me, it isn't just the heroes that define a great JRPG, but also their villains. For a JRPG to stick with fans, you need more than just a go-getting protagonist who demonstrates what it means to be a hero. No, you need to give them a powerful …
- Sporting events are getting bigger, and so are the cyberthreats 2026-08-05 00:03 iTWire GUEST OPINION: The FIFA World Cup is one of the largest tournaments in the world. We saw Scottish fans bring joy to Boston, Japanese and Dutch fans chanting together, and South Korean and Mexican fans dancing in the streets. There is beauty in the size of …
- Microsoft warns hackers are targeting hotel Wi-Fi networks 2026-08-04 13:22 6 ABC Action News - Pennsylvania Microsoft is warning travelers about a new threat targeting hospitality venues in "widespread but targeted" internet traffic manipulation attacks. Microsoft Threat Intelligence published a warning on its website Friday, notifying the public about …
- Travelers beware — Microsoft experts warn hotel Wi-Fi can be hijacked to infect your devices with dangerous malware 2026-08-04 13:06 TechRadar Pro Follow us Add us as a preferred source on Google Newsletter Subscribe to our newsletter Microsoft reports Russian APT29 (Midnight Blizzard) hijacking captive portals in hotels and conference centers Victims redirected to fake Microsoft 365 logins or bogus …
- Device Code Phishing Up 1,500% in 2026; Vishing Doubles 2026-08-04 07:28 Dark Reading Phishing is evolving faster than it has in a long, long time. Email-based phishing undisputedly has been the most dominant means of social engineering in the 21st century. It hasn't changed much in that time, and attackers followed pretty much the same …
- Microsoft warns hackers are targeting hotel Wi-Fi networks: What to know, how to protect yourself 2026-08-03 19:30 Good Morning America Microsoft is warning travelers about a new threat targeting hospitality venues in "widespread but targeted" internet traffic manipulation attacks. Microsoft Threat Intelligence published a warning on its website Friday, notifying the public about …
- ⚡ Weekly Recap: Rogue AI Models, $88M Bitcoin Theft, Water-System Attacks and Dangling DNS Hijacks 2026-08-03 16:17 The Hacker News Ravie LakshmananAug 03, 2026Cybersecurity / Hacking This week kept coming back to permission. A model crossed a boundary. A wallet trusted bad randomness. Webmail kept an intruder around. Public systems, package feeds, hotel networks, and login flows …
- Midnight Blizzard Targets Travelers via Captive Portals 2026-08-03 15:25 Infosecurity Magazine Captive portals on hotel and conference Wi-Fi networks have been hijacked to route guests through attacker infrastructure, serving fake browser and operating system updates that install Russian espionage malware. According to research published by …
- Russian State APT Linked to Recent Public Wi-Fi Gateway Hacking 2026-08-03 11:50 SecurityWeek A Russian state-sponsored APT is behind a recent credential theft campaign mounted via hacked public Wi-Fi gateway appliances at organizations running captive portal networks, Microsoft reports. The campaign was flagged roughly a week ago by ReliaQuest, …
- Russian Hackers Hijack Hotel Wi-Fi to Steal Microsoft 365 Tokens 2026-08-01 15:48 Security Affairs Russian Hackers Hijack Hotel Wi-Fi to Steal Microsoft 365 Tokens Microsoft says Russian hackers hijacked hotel Wi-Fi portals to spread malware and steal Microsoft 365 tokens from travelers. Microsoft Threat Intelligence disclosed CaptiveCrunch, a campaign …
- BlackTech APT Deploys BlueShell Linux Backdoor Against Japanese Organizations 2026-07-31 16:27 Cyber Security News BlackTech has been linked to a newly examined Linux backdoor deployment against organizations in Japan, showing how a familiar remote-access tool can be reshaped for cyberespionage. The malware gives intruders a way to run commands, move files, and route …
- BlackTech APT Uses New BlueShell Linux Backdoor in Attacks on Japanese Organizations 2026-07-31 11:44 GBHackers BlackTech, a long-running China-aligned APT group, has adopted a new Linux backdoor built on the BlueShell open-source RAT to conduct post-intrusion operations against Japanese organizations, signaling ongoing toolchain evolution and focused targeting of …
- Google’s Cryptonym Overhaul: Sandworm Relic and the Quest for Clarity in Threat Actor Names 2026-07-31 10:19 WebProNews - Kentucky Google just upended a long-standing headache in cybersecurity reporting. On July 24, 2026, the Google Threat Intelligence Group began rolling out a fresh system for labeling the hackers, spies and thieves that target governments, companies and critical …
- Russian state attackers exploiting misconfigured routers, new multi-nation advisory warns 2026-07-28 21:32 Information Security Buzz AI Summary Russian state-sponsored actors are compromising poorly secured routers and networking devices around the world, with critical infrastructure organisations among the primary targets, reveals a new joint cybersecurity advisory from 20 government …
- 16 Strongest Anime Demon Lords, Ranked 2026-07-27 22:49 OtakuKart Demon Lords are among the most iconic and powerful characters in anime. Some begin as terrifying villains, while others become heroes, antiheroes, or wise rulers who protect their people. Their strength, personalities, and unique journeys make them …
- Google unifies names for tracked cyber threat groups 2026-07-27 04:39 Arabian Post Google has begun introducing a unified naming system for cyber threat actors, replacing overlapping labels used by its security teams with two-word cryptonyms designed to give defenders clearer context about attackers and their likely objectives.The Google …
- Russian hackers target US nuclear scientists after testing cyber tactics in Ukraine 2026-07-25 06:19 Crypto Briefing Star Blizzard group refined phishing campaigns on Ukrainian targets before pivoting to western nuclear research institutions and defense contractors A Russian state-backed hacking group spent a year targeting American nuclear scientists, defense …
- Golden Chickens Resurfaces With Four New Malware Families and Modular Implants 2026-07-24 20:55 The Hacker News Ravie LakshmananJul 24, 2026Threat Intelligence / Browser Security The threat actors behind the Golden Chickens malware-as-a-service (MaaS) ecosystem have resurfaced with four new malware families, indicating that the operators are showing no signs …
- Golden Chickens Launches Four Modular Malware Families to Steal Chrome Credentials and Hijack Browser Sessions 2026-07-24 12:25 GBHackers Golden Chickens, tracked as TAG-195 and also known as Venom Spider, has launched four new modular malware families designed to enhance credential theft, browser session hijacking, and post-exploitation flexibility. The newly identified families TinyEgg, …
- Boulder Police Pray with Anti-Abortion Activists Amid Rising Tensions 2026-07-23 00:38 Colorado Times Recorder Recent social media posts from anti-abortion group White Rose Resistance have raised concerns from pro-abortion nonprofit Cobalt. White Rose Resistance organizer Sean Bateman posted a selfie on Instagram with the caption, “Today is a kill day. Pray for me …
- APT42 Uses AI-Assisted Phishing and TAMECAT Malware to Target Officials 2026-07-22 07:01 VPNCentral Iran-linked cyber espionage group APT42 is combining patient social engineering, AI-assisted research, credential phishing, and an expanded TAMECAT backdoor to target government and defense officials. The group also approaches policy experts and relatives …
- New Law Would Help Taiwan’s Communications Sector Work Around Chinese Cable Slicing 2026-07-21 21:28 The Foundation for Defense of Democracies (FDD) Taiwan is increasingly looking abroad to strengthen its domestic communications resilience. On July 21, Taiwan’s Legislative Yuan unanimously passed a bill that eases restrictions on foreign firms seeking to enter its telecommunications sector, …
- Russian State-Sponsored Hackers Targeting Critical Infrastructure Routers 2026-07-21 05:53 JD Supra - California A joint cybersecurity advisory from the United States and 12 allied nations was released this week warning critical infrastructure operators that Russian state-sponsored hackers from Federal Security Service (FSB) Center 16 are actively exploiting poorly …
- State-Sponsored Russian Hackers Exploit Vulnerable Routers to Compromise Critical Infrastructure 2026-07-20 22:22 CPO Magazine Russian hackers are exploiting poorly configured routers to compromise critical infrastructure, a cybersecurity advisory by the FBI, CISA, and the security agencies of 15 U.S. allies warns. The attacks, executed by Russia’s Federal Security Service (FSB) …
- ⚡ Weekly Recap: WordPress RCE, SonicWall 0-Days, AI Service Attacks, SharePoint 0-Day and More 2026-07-20 16:48 The Hacker News Ravie LakshmananJul 20, 2026Cybersecurity / Hacking A single request should not be able to do this much. But this week, small inputs led to code execution, memory loss, stolen keys, and disabled security tools. The paths were often simple: exposed …
- GoSerpent Backdoor Looted Police and Biometric Data Across Southeast Asia for Five Years 2026-07-17 14:07 Tech Times For at least five years, a sophisticated espionage operation quietly worked its way through Southeast Asian government networks, harvesting police complaint files, biometric databases, and diplomatic records without triggering a single public alarm. …
- Iran-nexus actors using AI to enhance cyber playbook 2026-07-16 17:35 Cybersecurity Dive - Massachusetts Threat actors linked to Iran are using artificial intelligence to enhance their cyber and information warfare capabilities, putting the U.S. and its allies at higher risk of asymmetric attack, according to a report released Thursday by Recorded Future. …
- CISA Warns Russian Hackers Are Exploiting 18-Year-Old Cisco IOS Flaw 2026-07-16 12:12 VPNCentral CISA has warned that Russian state-sponsored hackers are actively exploiting CVE-2008-4128, an 18-year-old cross-site request forgery vulnerability in end-of-life Cisco IOS devices. The flaw can let an attacker manipulate an authenticated administrator’s …
- UK and Allies Warn Russian FSB Hackers Are Compromising Routers Worldwide 2026-07-16 12:11 VPNCentral The UK and 11 partner countries have warned that hackers linked to Russia’s Federal Security Service are actively compromising poorly configured routers around the world. The campaign targets internet-facing network equipment that uses weak credentials, …
- US and allied Governments’ Recommendations: Securing Network Devices Against Russian APT Groups 2026-07-16 00:05 Security Affairs US and allied Governments’ Recommendations: Securing Network Devices Against Russian APT Groups US and allies warn of Russian APT groups targeting routers and network devices to compromise critical infrastructure worldwide. The US and allied governments …
- Russian hackers on the rise, warns ASD and global security partners 2026-07-15 21:00 RiotACT The Australian Signals Directorate says Russian cyberattacks on public and private organisations are on the rise. Photo: Juice Flair. Russian hackers are attacking key industries in Australia, trying to break into the systems of financial services, health …
- Russian Hackers Turn Home Routers Into Stealth Weapons Against Critical Infrastructure 2026-07-15 10:20 WebProNews - Kentucky Russian state hackers keep finding new ways to hide. This time, they target the router sitting in your home or small office. The latest alert from U.S. authorities paints a troubling picture. Operators linked to the Federal Security Service, or FSB, scan …
- 18 Forgotten Action Anime That Felt Like Summer Blockbusters 2026-07-14 22:47 OtakuKart Action anime has produced some of the most unforgettable battles, breathtaking animation, and high-stakes stories in the medium. While blockbuster hits like Attack on Titan, Demon Slayer, and Jujutsu Kaisen often dominate the conversation, many other …
- US, Allies Warn of Russian Cyberattacks Targeting Critical Infrastructure Routers 2026-07-14 19:09 SecurityWeek Russian state-sponsored advanced persistent threat (APT) actors are targeting networking devices to compromise critical infrastructure worldwide, the US and its allies warn. The activity involves scanning for poorly secured devices, mainly routers, for …
- US and security allies warn Russian attacks on critical infrastructure are ramping up against 'poorly configured and vulnerable networking devices worldwide' 2026-07-14 16:14 TechRadar Pro Follow us Add us as a preferred source on Google Newsletter Subscribe to our newsletter NSA, FBI, CISA, and 15 allied agencies warn Russia’s FSB Center 16 is exploiting weak/default credentials and old Cisco flaws to compromise critical infrastructure …
- FBI Issues Warning As Russia’s FSB Center 16 Hackers Target Routers 2026-07-14 14:37 Forbes Russia's FSB Center 16 hackers attack routers in the West. LightRocket via Getty Images The Federal Security Service of the Russian Federation, the successor to the Soviet KGB and better known as the FSB, has deployed its Center 16 hackers to attack …
- Spy agency warns active Russian hackers targeting Australian industry 2026-07-14 07:52 ABC (Australian Broadcasting Corporation) The Australian Signals Directorate (ASD) has issued a joint warning alongside nearly two dozen partner agencies about Russian-linked hackers targeting critical Australian industries. The ASD has highlighted poorly secured network devices as easy targets …
- Russian FSB Hackers Target Critical Infrastructure Through Vulnerable Routers, Global Agencies Warn 2026-07-14 07:48 International Business Times Singapore Russian state-sponsored cyber actors linked to the Federal Security Service (FSB) Center 16 continue to exploit poorly configured and vulnerable networking devices worldwide, targeting organizations across critical infrastructure sectors. The latest …
- NSA warns Russian FSB is exploiting weak routers to target critical infrastructure 2026-07-14 07:43 Decode39 A new joint cybersecurity advisory says Russia’s FSB Center 16 is still exploiting vulnerable routers and poorly configured networks worldwide. The warning, co-signed by U.S., Five Eyes and European agencies including Italy’s AISE and AISI, points to a …
- Supo, FDI warn companies of Russian cyber espionage 2026-07-14 00:46 Daily Finland The Finnish Security Intelligence Service (Supo) and the Finnish Defence Intelligence (FDI) on Monday warned companies of Russian cyber espionage campaign targeting poorly configured network devices, said Supo in a press release. The Finnish authorities …
- FSB Center 16 Exploited Default Router Passwords to Map Critical Infrastructure for Years 2026-07-14 00:17 Tech Times A Russian intelligence unit that has been quietly stealing network maps from critical infrastructure operators around the world — not through sophisticated zero-day exploits, but through factory-default passwords on routers that organizations never changed …
- Officials once again warn defenders that Russian hackers are targeting network devices 2026-07-13 16:11 CyberScoop Russian state-sponsored hackers are breaking into critical infrastructure around the world by exploiting poorly configured and vulnerable networking devices, authorities from the United States and 12 additional countries said in a joint cybersecurity …
- Russian State Hackers Target Vulnerable Routers Worldwide, Joint Advisory Warns 2026-07-13 15:26 Infosecurity Magazine Cybersecurity agencies from 12 countries have issued a fresh warning that a Russian state-sponsored cyber unit is actively targeting vulnerable routers worldwide. The joint advisory detailed how Russian Federal Security Service (FSB) Center 16 cyber actors …
- Supo warns companies of Russian cyber espionage campaign 2026-07-13 12:14 Yle Uutiset Hackers target corporate network infrastructure rather than home internet users. Open image viewer File photo. Image: Jorma Vihtonen / Yle The Finnish Security Intelligence Service (Supo) and the Finnish Defence Intelligence Agency are warning …
- UK and EU impose sanctions on hacking groups linked to Kremlin 2026-07-13 11:48 Computer Weekly The UK and the European Union have issued sanctions against individuals and organisations linked to Russian-backed cyber attacks. In their first joint cyber-sanctions package, the UK and Europe has targeted 24 individuals and entities linked to the Russian …
- NCSC issues warning over Russian intelligence-backed threat group 2026-07-13 11:44 IT Pro Follow us Add us as a preferred source on Google Newsletter Subscribe to our newsletter The National Cyber Security Centre (NCSC) has urged UK organizations to remain vigilant for attacks waged by Russian state-backed hackers. As part of an advisory …
- Microsoft just broke custom folder icons in Windows, and the reason is a bug from 2003 2026-07-07 03:02 XDA Summary Windows now ignores untrusted desktop.ini files, breaking custom folder icons to fix a security hole. The change closes a 23-year-old Explorer trust vulnerability exploited via desktop.ini. Custom icons still work from trusted sources or by …
- ExtraHop® Report Finds Nearly Half of Ransomware Victims Suffer Data Theft Before Detection 2026-06-25 09:13 Financial IT ExtraHop®, a leader in modern network detection and response (NDR), today released the 2026 ExtraHop Global Threat Landscape Report, exposing the reality of modern cyber defense in the age of AI. The comprehensive analysis examines an environment where …
- Hackers breach Singapore networks for 2.5 weeks before detection 2026-06-24 21:30 Singapore Business Review North Korea-linked hackers and AI risks test firms’ defences. Nearly half (47%) of Singapore’s ransomware victims failed to detect network breaches until after their corporate data had already been stolen, a catastrophic spike from just 15% last year. …
- OceanLotus Compromised FireAnt MetaKit to Target Stock Investors With SPECTRALVIPER 2026-06-16 08:38 VPNCentral OceanLotus used a software supply-chain attack against FireAnt MetaKit to target stock investors in Vietnam with the SPECTRALVIPER backdoor. The campaign ran from around October 2025 to March 2026 and abused a trusted update mechanism used by investment …
- Azerbaijan’s New Cybersecurity Agency Targets Rising Russian and Iranian Digital Threats 2026-06-15 13:31 UNITED24 Media Azerbaijani President Ilham Aliyev has signed a decree creating a National Cybersecurity Agency to shield the country from rising digital threats, including hacking of Russian and Iranian origin. This was reported by Ukraine's Foreign Intelligence …
- Windows 11 June 2026 Update Kills Folder Icons: 23-Year-Old Shell Bug Finally Closed 2026-06-13 14:37 Tech Times If your carefully customized network folder icons vanished after this week's Windows update, you are not looking at a bug. Microsoft's June 9, 2026 Patch Tuesday update KB5094126 — which applies to Windows 11 24H2 and 25H2 — and its companion …
- OceanLotus APT Compromises FireAnt MetaKit in Supply-Chain Attack on Stock Investors 2026-06-11 21:09 Cyber Security News A notorious hacking group has been caught targeting stock investors in Vietnam through a supply chain attack, hijacking a popular investment software platform to deliver a powerful backdoor. The operation, carried out by OceanLotus (also known as APT32), …
- OceanLotus Hits Vietnam Investors With SPECTRALVIPER in FireAnt Attack 2026-06-11 19:40 The Hacker News The Vietnam-aligned threat actor known as OceanLotus has been attributed to two distinct campaigns that targeted domestic entities and stock investors with a backdoor known as SPECTRALVIPER. The campaigns involve a prolonged cyber espionage operation aimed …
- OceanLotus Targets Stock Investors in FireAnt MetaKit Supply-Chain Hack 2026-06-11 15:52 GBHackers OceanLotus APT has executed a precision supply‑chain operation that implanted its SPECTRALVIPER backdoor into FireAnt MetaKit, a popular Vietnamese market‑data component. Telemetry collected from mid‑2024 through early 2026 shows OceanLotus (aka APT32) …
- Vietnam-aligned OceanLotus pivots to spy on domestic targets as it takes a more selective approach abroad, ESET Research finds 2026-06-11 10:04 Knox County News - Nebraska From mid-2024 to February 2026, Vietnam-aligned APT group OceanLotus compromised the network of a Vietnamese infrastructure and transport construction corporation with its signature implant, SPECTRALVIPER. From October 2025 to March 2026, OceanLotus …