Mustang Panda Deploys Signed Windows Rootkit in Updated CoolClient Backdoor
Mustang Panda (aka HoneyMyte) has been observed deploying an updated version of the CoolClient backdoor that includes a signed Windows kernel-mode rootkit,…
Mustang Panda (aka HoneyMyte) has been observed deploying an updated version of the CoolClient backdoor that includes a signed Windows kernel-mode rootkit,…
Apple has issued a fresh batch of threat notifications to customers in 110 countries, warning that they may be targeted by mercenary…
The China-linked threat actor known as Jewelbug has been observed conducting cyber espionage against governments and militaries while simultaneously running a cryptocurrency…
Jewelbug is a China-based hackers-for-hire group that conducts cyber espionage against governments and militaries in the Middle East, Southeast Asia, and South…
Afghan telecom providers and South Asian critical infrastructure organizations are the targets of a new campaign delivering a previously undocumented backdoor called…
APT36, also known as Transparent Tribe, is a Pakistan-aligned threat actor that has historically targeted government, military, and diplomatic organizations in India…
North Korean IT workers are increasingly infiltrating government agencies and businesses by applying for remote jobs, passing interviews, and obtaining legitimate credentials.…
The North Korean threat actor known as Lazarus Group has been attributed to the zero-day exploitation of a newly patched Microsoft Windows…
Security researchers created a fictitious cryptocurrency startup and hired three individuals they believe were North Korean IT operatives, as part of an…
Chrome Remote Desktop is a remote access tool that allows users to control computers remotely. A suspected North Korean operative installed it…