apt

Hijacked Hotel Wi-Fi Pushes Fake Updates to Deliver Surveillance Malware
A sophisticated threat actor, tracked as Storm-2945 and linked to Russia's SVR, has been hijacking hotel Wi-Fi networks to distribute malware. The attackers redirect users to fake update pages, tricking them into downloading a remote access trojan called CornFlake, which can steal sensitive data and provide surveillance capabilities. The operation, dubbed CaptiveCrunch, also leverages stolen authentication tokens to gain further access.

Russian Espionage Group Exploited Zimbra Zero-Day to Steal Mail and 2FA Codes
A sophisticated Russian espionage campaign, attributed to the group TA488 (also known as LAUNDRY BEAR or Void Blizzard), has been actively exploiting a zero-day vulnerability in Zimbra Collaboration's webmail client since at least July 2025. This flaw allowed attackers to steal sensitive data, including emails, contact lists, browser-saved passwords, and two-factor authentication codes, by simply having a user view a specially crafted HTML email. The vulnerability, identified as CVE-2025-66376, was patched by Zimbra in November 2025, but the attackers continued to leverage it for months prior to the fix.

Hackers abuse ViPNet software to target Russian govt agencies
An advanced threat actor, potentially Chinese-speaking, is targeting Russian government and other high-value organizations by abusing the update mechanism of ViPNet, a popular Russian cybersecurity product. The campaign, active since at least May and dubbed HelloNet, involves injecting malicious DLLs into the ViPNet update directory, which then load further malware payloads like proxies, backdoors, and log cleaners. Researchers have low confidence in the attribution due to weak evidence.

Chinese APT Group Linked to DigiCert Breach and Code Signing Certificate Theft
Researchers have linked a Chinese cybercrime group, known as GoldenEyeDog and CylindricalCanine, to a security incident at DigiCert that resulted in the theft of code-signing certificates. This group has previously targeted the gambling and gaming industries.

China-Linked APT Expands Arsenal With New ‘Leash’ Backdoors
A China-linked advanced persistent threat (APT) group, identified as LapDogs, has reportedly enhanced its malicious toolkit. Security researchers have observed the deployment of three new backdoors: LongLeash, DogLeash, and JarLeash, which are designed to compromise small office/home office (SOHO) routers.

China-Linked APT Expands Proxy Network With New Malware
A China-linked advanced persistent threat group, identified as UAT-7810, is reportedly expanding its network of proxy servers. This expansion is being facilitated by the deployment of new malware, according to research from Cisco Talos.

Armored Likho Hits Government, Energy Sectors With BusySnake Stealer
Cybersecurity researchers have identified a new threat actor, dubbed Armored Likho, targeting government and energy sectors in Russia, Kazakhstan, and Brazil with a sophisticated phishing campaign. The operation utilizes a custom-built Python infostealer named BusySnake, designed to steal credentials, sensitive documents, and other high-value data. The attackers employ AI-generated payloads to obscure their activities and maintain persistence through various methods, including reverse SSH tunneling.

MassTraction Exploits Roundcube Flaws at US, Canadian Universities
A threat group known as UNK_MassTraction, believed to be linked to China, is exploiting vulnerabilities in Roundcube webmail to gain unauthorized access to sensitive research mail servers at universities in the United States and Canada. The attackers are reportedly stealing user sessions to achieve this access.

Chinese hackers develop LONGLEASH malware to expand ORB network
Chinese state-sponsored hackers, identified as UAT-7810, have developed new malware named LONGLEASH. It is being used to expand their ORB network by compromising internet-facing devices, specifically targeting unpatched Ruckus routers.

Iran-Linked Hackers Using Modular C&C Framework in Cyberattacks
An Iran-linked threat actor is using an adaptable modular command-and-control framework in cyberattacks. It compromised IT service providers to reach high-value targets primarily in Israel.

Cavern Manticore: Exposing Iran-Linked Modular C2 Framework
A new modular command-and-control framework, dubbed 'Cavern Manticore,' has been observed in the wild, attributed to an Iran-nexus threat actor targeting Israeli government and IT sectors. The framework utilizes a .NET foundation but employs diverse compilation formats to evade analysis. Attackers gain initial access by exploiting legitimate software deployment features, such as RMM tools, to infiltrate victim environments.

Armored Likho digging a snake pit: inside the covert BusySnake Stealer campaign
A new phishing campaign has been identified, attributed to a previously unknown APT group named Armored Likho. This group targets government agencies and the electric power sector in Russia, Brazil, and Kazakhstan. They employ a diverse toolkit, including a new Python-based infostealer called BusySnake Stealer, and utilize AI-generated payloads to evade detection and complicate attribution.