CuraSec

tag: Espionage · 10 items

2026-08-28 · The Hacker News · source ↗ #apt28#backdoor#espionage
  • Engineer — Skip
  • SOC/IR — Act: APT28-linked HOOKEDGE is a new Windows batch-script backdoor actively used against government and diplomatic targets in Europe; hunt for suspicious batch-script persistence mechanisms and lateral movement patterns consistent with APT28 TTPs (ATT&CK: T1059.003) in Windows endpoint telemetry since September 2025.
  • Leader — Learn: APT28 has deployed a novel backdoor against European government and diplomatic organizations — relevant for sector-risk awareness and to brief leadership if your organization has European government ties or similar exposure profile.
2026-08-21 · Google Threat Intelligence · source ↗ #russian-apt#oauth-abuse#espionage
  • Engineer — Plan: OAuth consent-flow abuse by APT29-linked clusters is a real attack surface for any organization using third-party OAuth integrations; audit configured OAuth app permissions and enforce stricter conditional access policies to reduce the social-engineering foothold these groups exploit.
  • SOC/IR — Act: Three active Russian clusters are running persistent campaigns against high-value sectors using OAuth flow hijacking and captive-portal redirects — pull Google’s full IOC list, hunt for anomalous OAuth token grants or device-code auth attempts since mid-2025, and tune detections for captive-portal redirect chains tied to UNC7005 TTPs documented by Reliaquest and Microsoft.
  • Leader — Plan: If your organization falls in academia, aerospace/defense, government, or think tanks, queue a targeted user-awareness briefing on OAuth and device-code phishing before next quarter; the APT29 lineage of UNC6293 elevates this beyond routine phishing and warrants a conversation with your security team about protective intelligence coverage.
2026-08-21 · The Hacker News · source ↗ #oauth-abuse#espionage#account-hijacking
  • Engineer — Learn: Describes a novel technique where threat actors weaponize legitimate OAuth device-authorization flows and WhatsApp multi-device linking to hijack accounts without traditional phishing; no patch exists but worth reviewing whether your OAuth app consent and device-link flows have anomaly logging enabled.
  • SOC/IR — Plan: Three named Russian espionage clusters are running active campaigns against academia, defense, and government targets using legitimate auth flows — build or tune detections for unusual OAuth device-code grant activity and unauthorized WhatsApp device registration events, and prioritize coverage if your org is in a targeted sector.
  • Leader — Learn: Nation-state espionage clusters are persistently targeting academia, aerospace/defense, government, and think tanks in the US and Europe; useful context for sector-specific threat briefings but no immediate leadership action is defined without disclosed IOCs or confirmed victim organizations.
2026-08-20 · The Hacker News · source ↗ #apt#espionage#malware
  • Engineer — Skip
  • SOC/IR — Learn: Five previously undocumented RAT families (DriveSilkRAT, CookiETagRAT, NomadRAT, GoginRAT, NodeEdgeRAT) are worth tracking as new tooling enters the threat landscape; however, the summary provides no IOCs, ATT&CK mappings, or detection specifics — revisit if a fuller technical write-up with indicators is published.
  • Leader — Skip
2026-08-14 · BleepingComputer · source ↗ #threat-actor#espionage#government
  • Engineer — Skip
  • SOC/IR — Learn: Jewelbug’s dual-mission posture — running espionage and financially motivated fraud in parallel — is useful context for triage when attributing activity against government targets, but no IOCs or ATT&CK-mapped TTPs are surfaced to enable detection work now.
  • Leader — Learn: The actor’s government and military targeting scope is worth adding to sector threat context, but with no vendor breach, no disclosed compromise method, and no enrichment signals, this does not require leadership action this week.
  • Engineer — Plan: If your organization runs Zimbra webmail, review the Unit 42 report for any patched CVEs or configuration mitigations tied to this JavaScript injection vector, and audit Zimbra servers for unauthorized script modifications.
  • SOC/IR — Act: Pull the full Unit 42 report for IOCs and TTPs, then hunt for anomalous JavaScript execution or unexpected credential harvesting activity in Zimbra server logs since the campaign’s observed start date.
  • Leader — Learn: A Russian espionage actor is actively harvesting credentials from enterprise Zimbra deployments — useful context for sector threat briefings, but no immediate leadership action is indicated unless Zimbra is a core part of your environment.
2026-07-23 · BleepingComputer · source ↗ #data-breach#government#espionage
  • Engineer — Skip
  • SOC/IR — Learn: A ten-month undetected compromise of a government education portal is a useful dwell-time reference case; no IOCs or TTPs are published, so no immediate detection action is possible.
  • Leader — Learn: Illustrates risk of extended dwell time in auxiliary systems (online education portals) that hold sensitive personnel data — useful framing for third-party and non-core-system risk reviews.
2026-07-21 · The Hacker News · source ↗ #microsoft-365#c2-abuse#espionage
  • Engineer — Plan: Novel Graph API abuse using calendar write access highlights over-permissioned OAuth app risk. Audit which apps hold Microsoft Graph calendar read/write scopes and revoke unnecessary permissions this quarter.
  • SOC/IR — Act: The year-2050 calendar event timestamp is a highly specific, huntable indicator — sweep M365 audit logs for calendar events created with 2050 dates and flag Graph API calls that write calendar entries with large attachments.
  • Leader — Learn: Espionage actors using legitimate Microsoft 365 infrastructure for C2 blurs the line between sanctioned SaaS activity and intrusion; useful context for understanding the M365-as-attack-surface risk but no immediate leadership action required.
2026-07-17 · The Hacker News · source ↗ #espionage#apt#malware
  • Engineer — Learn: No specific software vulnerabilities or exploited CVEs are mentioned; this is a novel malware family used in targeted government espionage. No patch, reconfiguration, or supply-chain exposure applies to typical enterprise engineers.
  • SOC/IR — Learn: The summary provides no IOCs or ATT&CK-mapped TTPs to hunt or detect against; useful actor-profile context, but actionable detection work would require the full Kaspersky report with indicators.
  • Leader — Learn: Nation-state espionage campaign with a narrow sectoral focus (Southeast Asian governments and diplomats); worth noting for boards of regional government contractors, but no vendor exposure or regulatory trigger for most enterprises.
2026-07-12 · The Hacker News · source ↗ #apt#espionage#government
  • Engineer — Skip
  • SOC/IR — Learn: Multi-group espionage campaign targeting government law enforcement portals offers useful actor-profiling context, but no IOCs or ATT&CK mappings are surfaced in available signals to drive immediate detection or hunting work.
  • Leader — Skip