US Charges Chinese Hacker in Cyberespionage Case

The US Department of Justice has extradited Chinese national Xu Zewei from Italy to face charges of conducting cyberespionage operations on behalf of China's intelligence services, targeting victims including COVID-19 researchers. Xu's alleged hacking activities, directed by China's Ministry of State Security, spanned over a year, from February 2020 to…

https://osintsights.com/us-charges-chinese-hacker-in-cyberespionage-case?utm_source=mastodon&utm_medium=social

#Cyberespionage #NationState #China #MinistryOfStateSecurity #Prc

US Charges Chinese Hacker in Cyberespionage Case

US charges Chinese hacker Xu Zewei with cyberespionage, extradited to face computer intrusion charges; learn more about the case now.

OSINTSights

Bad Connection
Uncovering Global Telecom Exploitation by Covert Surveillance Actors https://citizenlab.ca/research/uncovering-global-telecom-exploitation-by-covert-surveillance-actors/

An investigation by the Citizen Lab Team, which uncovers two sophisticated telecom surveillance campaigns and, for the first time, directly links real-world attack traffic to mobile operator signalling infrastructure.

#CyberSecurity #ThreatIntelligence #Surveillance #TelecomSecurity #MobileSecurity #SS7 #NetworkSecurity #CyberEspionage #CitizenLab #Infosec #Privacy #DigitalRights #CyberResearch #SignalInfrastructure #Telecom

Firestarter Malware Evades Cisco Firewall Updates, Persists Across Reboots

A custom backdoor called Firestarter has been discovered evading Cisco firewall updates and persisting across reboots, posing a significant threat to cybersecurity. This sophisticated malware is attributed to a threat actor linked to cyberespionage campaigns, including the notorious ArcaneDoor operation.

https://osintsights.com/firestarter-malware-evades-cisco-firewall-updates-persists-across-reboots?utm_source=mastodon&utm_medium=social

#FirestarterMalware #CiscoFirewall #Uat4356 #Arcanedoor #Cyberespionage

Firestarter Malware Evades Cisco Firewall Updates, Persists Across Reboots

Learn how Firestarter malware evades Cisco firewall updates and persists across reboots. Discover the threat actor behind it and protect your devices now with expert security tips.

OSINTSights

📰 New 'GopherWhisper' APT Group Linked to China Targets Mongolian Government

New China-aligned APT 'GopherWhisper' discovered targeting Mongolian gov't. 🕵️‍♂️ The group uses a Go-lang toolkit and evades detection by using Slack, Discord, and Outlook for C2 communications. #APT #CyberEspionage #GopherWhisper #ThreatIntel

🔗 https://cyber.netsecops.io/articles/new-gopherwhisper-apt-group-targets-mongolian-government/?utm_source=mastodon&utm_medium=social&utm_campaign=twitter_auto

New 'GopherWhisper' APT Group Linked to China Targets Mongolian Government

ESET discovers GopherWhisper, a new China-aligned APT group targeting the Mongolian government with a Go-based malware toolkit that uses Slack, Discord, and Outlook for C2.

CyberNetSec.io

📰 Tropic Trooper APT Targets Chinese Speakers with Trojanized PDF Reader, Uses GitHub for C2

Tropic Trooper (APT23) is back! 🕵️‍♂️ A new campaign uses a trojanized SumatraPDF reader to target Chinese speakers. The malware uses GitHub for C2 and VS Code tunnels for persistent access. #APT #CyberEspionage #TropicTrooper #Infosec

🔗 https://cyber.netsecops.io/articles/tropic-trooper-apt-uses-trojanized-pdf-reader-in-new-espionage-campaign/?utm_source=mastodon&utm_medium=…

Tropic Trooper APT Targets Chinese Speakers with Trojanized PDF Reader, Uses GitHub for C2

The Tropic Trooper APT group (APT23) is targeting individuals in Asia with a trojanized SumatraPDF reader that deploys the AdaptixC2 beacon, using GitHub for C2 and VS Code tunnels for persistence.

CyberNetSec.io
⚠️ Legitimate Intune wipe turned espionage into global disruption Researchers say the same Iran-linked operation hijacked an #Intune admin account to remotely reset up to 200,000 devices in 79 countries after stealing tens of terabytes of data. #ransomNews #Iran #CyberEspionage

Iran’s MOIS Tied to Coordinate...
Russia uses AI to hack Europe, Dutch intelligence warns

The Netherlands says Russian cyberattacks on Europe are accelerating.

POLITICO

Mandiant Report Reveals Evolving Cyber Threat Tactics

Discover the alarming evolution of cyber threats in Mandiant's M-Trends 2026 report, which reveals a stark reality: attackers are now operating under two distinct playbooks, drastically changing the detection, response, and risk landscape. The report uncovers a significant increase in global median dwell time to 14 days, with some attacks lingering for…

https://osintsights.com/mandiant-report-reveals-evolving-cyber-threat-tactics

#Mandiant #Mtrends2026 #CyberEspionage #NorthKorea #DwellTime

Mandiant Report Reveals Evolving Cyber Threat Tactics

Discover evolving cyber threat tactics from Mandiant's M-Trends 2026 report. Learn how adversaries are reshaping detection and response, and stay ahead of breaches now. Read the findings today.

OSINTSights