Cybersecurity News

Filters
Tag
Reset

Filtered by tag: apt × Clear

Spark RAT Targets Cambodia, Abuses Vulnerable OPSWAT Driver to Disable Security Tools

Matched: health

A campaign targeting Cambodia is deploying Spark RAT, an open-source remote access trojan, using lure themes including government notices, public health materials, and real estate content. The attack abuses a vulnerable OPSWAT driver to disable security tools, broadening its potential victim pool across individuals and organizations in the region.

Iran-Linked Hackers Expand Attacks With New Backdoor and Reverse SSH Tunnels

Matched: Australia

Iran-linked group Tortoiseshell has expanded espionage operations using a Windows backdoor and reverse SSH tunnelling tool. Both components masquerade as wtsapi32.dll and use DLL hijacking. The backdoor runs commands, transfers files and beacons via HTTPS; the tunnel routes attacker traffic through port 443 into victim networks. Group-IB identified additional infrastructure with country-themed subdomains suggesting targets across the Middle East and Europe.

'Jewelbug' APT Balances State Espionage & Cryptocurrency Theft

Matched: cryptocurrency

Researchers have identified a threat actor dubbed "Jewelbug," a hackers-for-hire group conducting both state-sponsored espionage and cryptocurrency theft through the same infrastructure. The dual-purpose operation — mixing intelligence gathering with financial crime — is unusual, suggesting the group serves government clients while simultaneously running independent profit-driven attacks, blurring the line between nation-state and cybercriminal activity.

Shattering the Dream – When a Job Offer Becomes a Zero-Day Attack

North Korean hackers linked to Operation Dream Job have been targeting aerospace and defense companies worldwide since early 2026, using fake job offers as lures. Victims receive malicious PDF files requiring a modified viewer that executes embedded malware. Check Point Research identified the campaign as exploiting a zero-day vulnerability, continuing a long-running North Korean strategy of disguising cyberattacks as recruitment outreach.