China-Linked UAT-7810 Expands ORB Network With New LONGLEASH Malware
A Chinese threat actor tracked as UAT-7810 is actively refining its bespoke malware to expand its Operational Relay Box (ORB) network by…
A Chinese threat actor tracked as UAT-7810 is actively refining its bespoke malware to expand its Operational Relay Box (ORB) network by…
DOGLEASH is a passive backdoor that can execute arbitrary shellcode on a compromised Linux device. It was deployed by UAT-7810 against compromised…
A critical use-after-free vulnerability in the Linux Kernel-based Virtual Machine (KVM) hypervisor, tracked as CVE-2026-53359 and named 'Januscape', allows a guest virtual…
Cybersecurity researchers at LevelBlue have identified a new Java-based remote access trojan (RAT) named QuimaRAT, which is capable of targeting Windows, Linux,…
QuimaRAT is a Java-based remote access trojan (RAT) advertised under a malware-as-a-service (MaaS) model, capable of targeting Windows, Linux, and macOS. It…
Quima Control, also known as QuimaRAT, is a remote administration tool with 74 Windows and 46 macOS and Linux modules. It is…
Sygnia, tracking the China-nexus group as Velvet Ant, discovered that the group backdoored Linux PAM and OpenSSH components to maintain persistent access…
PAM is a Linux authentication framework that was backdoored by Velvet Ant to allow secret password access and credential theft. The group…
Operation Highland is a campaign by the China-linked Velvet Ant group that backdoored Linux PAM and OpenSSH components to maintain persistent access…
Arch Linux is a Linux distribution known for its rolling release model. Its community repository, AUR, was targeted in the Atomic Arch…