Advanced Persistent Threat (APT) stories
Okta warns of North Korean fraud in remote tech hiring
Last week
#
apt
Okta warns North Korean operatives are landing remote tech jobs with stolen and synthetic identities to fund the regime and enable cyber attacks.
Hackers ditch noisy ransomware for stealthy data theft
Last week
#
apt
Hackers are abandoning noisy ransomware to quietly steal data, as a report finds 80% of top attack techniques now focus on evasion.
Espionage Without Noise: Understanding APT36’s Enduring Campaigns
Last week
#
apt
Indian defence faces a decade-long silent siege as APT36 refines cross-platform cyber espionage with stealthy, persistent RAT campaigns.
NGINX config tampering enables stealth web traffic hijack
This month
#
apt
Attackers are hijacking live web sessions by stealthily tampering with NGINX configs, silently relaying traffic via rogue servers.
CrowdStrike splits LABYRINTH CHOLLIMA into three units
Last month
#
apt
CrowdStrike has split North Korea-linked LABYRINTH CHOLLIMA into three units, two for crypto theft and one for industrial espionage.
LOTUSLITE backdoor targets US policy bodies with lures
Last month
#
apt
Politically themed LOTUSLITE phishing campaign hits US policy bodies, using DLL sideloading and espionage-focused backdoor tactics.
LinkedIn DMs abused to spread Python-based malware
Last month
#
apt
Attackers are abusing LinkedIn private messages to deliver Python-based malware via booby-trapped archives, ReliaQuest has warned.
Silver Fox APT & PowerG flaws expose key security risks
Last month
#
apt
NCC Group links Silver Fox’s false-flag malware campaigns to ValleyRAT and uncovers critical PowerG flaws that can fully compromise alarms.
US cyber attack on Venezuela exposes CNI vulnerabilities
Last month
#
apt
Alleged US cyber role in Venezuela attack exposes how multi-domain operations can silently compromise critical national infrastructure.
Storm-0249 hijacks security tools to fuel ransomware
Last month
#
apt
Storm-0249 hijacks trusted security and Windows tools to stealthily broker high-value network access for ransomware operators.
Chinese hackers fake Teams downloads in false flag ploy
Thu, 18th Dec 2025
#
apt
Chinese state-backed hackers mimic Microsoft Teams downloads in a false flag campaign to infect Chinese speakers and blame Russian actors.
CrowdStrike hits 100% in latest MITRE ATT&CK tests
Thu, 11th Dec 2025
#
apt
CrowdStrike’s Falcon platform scores 100% detection and protection with zero false positives in MITRE ATT&CK’s toughest cloud-era tests.
WARP PANDA cyberespionage group targets US cloud networks
Fri, 5th Dec 2025
#
apt
China-linked WARP PANDA cyberespionage group targets US cloud networks, exploiting vulnerabilities in Microsoft 365, VMware, and more for sustained data access.
ThreatBook unveils ATI for APAC cyber risk detection & insight
Thu, 2nd Oct 2025
#
apt
ThreatBook launches its Advanced Threat Intelligence solution to enhance cyber risk detection in Asia Pacific, analysing billions of attack records daily.
Phantom Taurus: new Chinese group targets governments in Asia & Africa
Thu, 2nd Oct 2025
#
apt
Phantom Taurus, a new Chinese state-backed group, targets governments and telecoms in Africa, the Middle East, and Asia with advanced espionage tools and tactics.
Broadcom patches VMware zero-day exploited for nearly a year
Thu, 2nd Oct 2025
#
apt
Broadcom patches a VMware zero-day flaw exploited for nearly a year, allowing attackers root access to virtual machines in certain configurations.
WatchGuard launches FireCloud Total Access for Zero Trust SASE
Fri, 26th Sep 2025
#
apt
WatchGuard launches FireCloud Total Access, a hybrid SASE service offering Zero Trust security for MSPs and IT teams to protect remote and hybrid workforces.
Chinese cyber group targets US policy bodies during trade talks
Thu, 18th Sep 2025
#
apt
A Chinese cyber group has targeted US government and policy organisations with spearphishing attacks amid trade talks, using advanced tactics to gain persistent access.
EggStreme malware targets Philippine military in Chinese cyber campaign
Thu, 11th Sep 2025
#
apt
Chinese-linked EggStreme malware targets Philippine military firm, signalling rising espionage efforts in Asia-Pacific by advanced threat groups.
Singapore CISOs face rising cyber risks, insider threats & AI worry
Thu, 28th Aug 2025
#
apt
Singapore CISOs face rising cyber risks with 91% reporting data loss, growing insider threats, and concerns over AI amid escalating pressure and preparedness gaps.