Cybersecurity News
Filters
Filtered by tag: apt × Clear
Spark RAT Targets Cambodia, Abuses Vulnerable OPSWAT Driver to Disable Security Tools
Matched: health
A campaign targeting Cambodia is deploying Spark RAT, an open-source remote access trojan, using lure themes including government notices, public health materials, and real estate content. The attack abuses a vulnerable OPSWAT driver to disable security tools, broadening its potential victim pool across individuals and organizations in the region.
Iran-Linked Hackers Expand Attacks With New Backdoor and Reverse SSH Tunnels
Matched: Australia
Iran-linked group Tortoiseshell has expanded espionage operations using a Windows backdoor and reverse SSH tunnelling tool. Both components masquerade as wtsapi32.dll and use DLL hijacking. The backdoor runs commands, transfers files and beacons via HTTPS; the tunnel routes attacker traffic through port 443 into victim networks. Group-IB identified additional infrastructure with country-themed subdomains suggesting targets across the Middle East and Europe.
'Jewelbug' APT Balances State Espionage & Cryptocurrency Theft
Matched: cryptocurrency
Researchers have identified a threat actor dubbed "Jewelbug," a hackers-for-hire group conducting both state-sponsored espionage and cryptocurrency theft through the same infrastructure. The dual-purpose operation — mixing intelligence gathering with financial crime — is unusual, suggesting the group serves government clients while simultaneously running independent profit-driven attacks, blurring the line between nation-state and cybercriminal activity.
Shattering the Dream – When a Job Offer Becomes a Zero-Day Attack
North Korean hackers linked to Operation Dream Job have been targeting aerospace and defense companies worldwide since early 2026, using fake job offers as lures. Victims receive malicious PDF files requiring a modified viewer that executes embedded malware. Check Point Research identified the campaign as exploiting a zero-day vulnerability, continuing a long-running North Korean strategy of disguising cyberattacks as recruitment outreach.
