📱 IBM accusĂ© d'avoir dissimulĂ© plusieurs intrusions d'APT10 entre 2013 et 2016
📝 📰 **Source** : TechCrunch, publiĂ© le 5 juin 2026.
📖 cyberveille : https://cyberveille.ch/posts/2026-06-08-ibm-accuse-d-avoir-dissimule-plusieurs-intrusions-d-apt10-entre-2013-et-2016/
🌐 source : https://techcrunch.com/2026/06/05/former-cyber-executive-turned-whistleblower-accuses-ibm-of-covering-up-several-data-breaches/
#APT10 #AT_T #Cyberveille
IBM accusé d'avoir dissimulé plusieurs intrusions d'APT10 entre 2013 et 2016

📰 Source : TechCrunch, publiĂ© le 5 juin 2026. Cet article rapporte le contenu d’une plainte judiciaire dĂ©posĂ©e en 2020 par William Barlow, ancien vice-prĂ©sident de la threat intelligence chez IBM jusqu’en aoĂ»t 2019, et dont le scellement vient d’ĂȘtre levĂ©. 🎯 Contexte de l’affaire Barlow accuse IBM d’avoir subi plusieurs intrusions par des acteurs Ă©tatiques Ă©trangers sur une dĂ©cennie, et d’avoir dĂ©libĂ©rĂ©ment dissimulĂ© ces incidents sans notifier les autoritĂ©s compĂ©tentes ni les clients gouvernementaux. IBM est un fournisseur majeur de cybersĂ©curitĂ© pour le gouvernement fĂ©dĂ©ral amĂ©ricain, ce qui rend la dissimulation allĂ©guĂ©e particuliĂšrement significative.

CyberVeille

IBM, AT&T Face Allegations of Concealing Data Breaches

A shocking lawsuit alleges that tech giants IBM and AT&T may have concealed massive data breaches, with Chinese hackers reportedly infiltrating IBM's network over 56,000 times between 2013 and 2016. The allegations, made by a former IBM vice president, claim the company knowingly kept the breaches under wraps.

https://osintsights.com/ibm-att-face-allegations-of-concealing-data-breaches?utm_source=mastodon&utm_medium=social

#DataBreach #Apt10 #China #NationState #ConcealedIntrusions

IBM, AT&T Face Allegations of Concealing Data Breaches

IBM and AT&T face allegations of concealing data breaches learn how APT 10 infiltrated their networks and what it means for cybersecurity now.

OSINTSights

Stone Panda (APT 10) continues global espionage campaigns tied to China’s MSS.
🎯 Targets: healthcare, defense, academia
đŸ› ïž Tools: Mimikatz, BloodHound, Impacket
🌍 Active in the U.S., UK, Japan, India & more
Espionage vs disruption — which do you see as their long-term mission?
Follow @technadu for continuous APT tracking.

#StonePanda #APT10 #CyberEspionage #ChinaAPT #ThreatActor #Cyble

#ESETresearch has uncovered the #MirrorFace Operation AkaiRyĆ«, which extends the group’s usual focus beyond Japan into Europe. The initial lure centered around Expo 2025 in Japan, compromising a Central European diplomatic institute.
https://www.welivesecurity.com/en/eset-research/operation-akairyu-mirrorface-invites-europe-expo-2025-revives-anel-backdoor/

Surprisingly, #MirrorFace used #ANEL – a backdoor historically linked only to #APT10 – highlighting a shift in the group’s tactics and reinforcing suspicions that MirrorFace could be part of the APT10 umbrella.
Operation AkaiRyĆ« began with targeted spearphishing emails referencing the victim’s past correspondence and Expo 2025 , persuading recipients to download malicious attachments.
Once the files were opened, a layered compromise chain ensued . Collaborating with the victim allowed us to perform in-depth analysis, shedding light on MirrorFace’s post-compromise behavior – from credential harvesting to dropping additional tools for lateral movement.

#MirrorFace used an intricate execution chain to stealthily run a highly tweaked #AsyncRAT within #WindowsSandbox, hampering detection efforts. This is the first time we’ve seen MirrorFace employ AsyncRAT.
In another twist, #MirrorFace utilized #VSCode remote tunnels, a tactic enabling covert access and command execution on compromised machines. This approach has also been seen with other China-aligned cyberespionage groups.
The group primarily leveraged #ANEL as a first-stage backdoor, #HiddenFace – MirrorFace’s flagship backdoor – was dropped later in the attack to bolster persistence . Notably absent this time was #LODEINFO, which #MirrorFace typically employs.

We presented our findings about Operation AkaiRyƫ conducted by #MirrorFace at @jpcert_ac on January 22, 2025: https://jsac.jpcert.or.jp.
IoCs available in our GitHub repo: https://github.com/eset/malware-ioc/tree/master/mirrorface

Operation AkaiRyƫ: MirrorFace invites Europe to Expo 2025 and revives ANEL backdoor

ESET researchers uncovered MirrorFace activity that expanded beyond its usual focus on Japan and targeted a Central European diplomatic institute with the ANEL backdoor.

Guess Who’s Back - The Return of ANEL in the Recent Earth Kasha Spear-phishing Campaign in 2024

Trend Micro has identified a spear-phishing campaign active in Japan since June 2024. Evidence about the malware used by this campaign suggests this was part of a new operation by Earth Kasha.

Trend Micro

Happy Thursday everyone!

Today's #readoftheday is brought to you by the Cybereason Security Services Team as they report their findings from a campaign they dubbed #CuckooSpear, and this is just part 1!

They attributed this campaign to #APT10, found some new tools and capabilities that the group has, and discuss the luring techniques, and much more! They talk about the techniques and tactics that they observed, they tools and LOLBAS's that were abused.

SPEAKING of techniques, APT10 used three different ways to gain persistence: scheduled tasks were created, they abused WMI Consumer Event (a method of subscribing to certain system events, then enabling an action of some sort), and creating Windows services.

This report provides great insight to the adversaries techniques, and I look forward to the rest of the parts! Enjoy and Happy Hunting!

CUCKOO SPEAR Part 1: Analyzing NOOPDOOR from an IR Perspective
https://www.cybereason.com/blog/cuckoo-spear-analyzing-noopdoor

Intel 471 #ThreatIntel #ThreatHunting #ThreatDetection #HappyHunting Cyborg Security, Now Part of Intel 471

CUCKOO SPEAR Part 1: Analyzing NOOPDOOR from an IR Perspective

In this report, Cybereason confirms the ties between Cuckoo Spear and APT10 Intrusion Set by tying multiple incidents together and disclosing new information about this group’s new arsenal and techniques.

Chinese hackers have unleashed a never-before-seen Linux backdoor

SprySOCKS borrows from open source Windows malware and adds new tricks.

Ars Technica
APT10: Tracking down LODEINFO 2022, part II

In the second part of this report, we discuss improvements made to the LODEINFO backdoor shellcode in 2022.

Kaspersky
Die Firmen stammen aus unterschiedlichen Branchen, einige aus der Automobilindustrie. Hinter dem Angriff soll laut Symantec die Hackergruppe Cicada stecken.
Japanische Firmen in 17 LĂ€ndern von Cyberattacke betroffen
Japanische Firmen in 17 LĂ€ndern von Cyberattacke betroffen

Die Firmen stammen aus unterschiedlichen Branchen, einige aus der Automobilindustrie. Hinter dem Angriff soll laut Symantec die Hackergruppe Cicada stecken.

Side note: this website dubbed "Intrusion Truth: We hunt APTs" (http://intrusiontruth.wordpress.com) appears to be leaking a few elements (names, addresses) of Chinese officials from the #APT10 group before the initial indictment was made public.
Is this parallel construction in action? đŸ€” https://t.co/fPOFOPHTF9
Intrusion Truth

We hunt APTs