📰 Iranian APT MuddyWater Masquerades as Ransomware Group in Microsoft Teams-Based Espionage Campaign

⚠️ Iranian APT MuddyWater targets orgs via Microsoft Teams, posing as a ransomware group. The real goal: espionage & data theft. Attackers trick users in screen-shares to steal credentials, bypassing MFA. #MuddyWater #CyberEspionage #ThreatIntel

🔗 https://cyber.netsecops.io

US firms could face exclusion under new EU cyber bill, lead lawmaker says

“I can see the Cybersecurity Act having an impact on U.S. companies if they don’t oblige by the rules,” says Czech Pirate MEP Markéta Gregorová.

POLITICO

MuddyWater hackers exploit Chaos ransomware as cyber-espionage decoy

MuddyWater hackers have cleverly used Chaos ransomware as a decoy to mask their true intentions - and it's not about making a quick buck. Instead, their tactics suggest a more sinister goal, blurring the lines between state-sponsored espionage and cybercrime.

https://osintsights.com/muddywater-hackers-exploit-chaos-ransomware-as-cyber-espionage-decoy?utm_source=mastodon&utm_medium=social

#Muddywater #Iran #Cyberespionage #Statesponsored #Ransomware

MuddyWater hackers exploit Chaos ransomware as cyber-espionage decoy

Learn how MuddyWater hackers exploit Chaos ransomware for cyber-espionage goals. Discover the tactics used and why financial gain wasn't the primary target. Read the analysis now.

OSINTSights

📰 China-Based Silver Fox APT Expands Espionage Campaign Across Asia with Fake Tax Audits

🇨🇳 China-based APT 'Silver Fox' expands its campaign across Asia, using fake tax audit emails to target medical and financial firms. The group has evolved into a dual-purpose espionage & financial threat. 🦊 #APT #SilverFox #CyberEspionage

🔗 https://cyber.netsecops.io

Inside Shadow-Earth-053: A China-Aligned Cyberespionage Campaign Against Government and Defense Sectors in Asia

Pulse ID: 69f97a64033cedf372cf42a0
Pulse Link: https://otx.alienvault.com/pulse/69f97a64033cedf372cf42a0
Pulse Author: Tr1sa111
Created: 2026-05-05 05:04:36

Be advised, this data is unverified and should be considered preliminary. Always do further verification.

#Asia #China #CyberSecurity #Cyberespionage #Espionage #Government #InfoSec #OTX #OpenThreatExchange #bot #Tr1sa111

LevelBlue - Open Threat Exchange

Learn about the latest cyber threats. Research, collaborate, and share threat intelligence in real time. Protect yourself and the community against today's emerging threats.

LevelBlue Open Threat Exchange

Inside Shadow-Earth-053: A China-Aligned Cyberespionage Campaign Against Government and Defense Sectors in Asia

A China-aligned threat group designated SHADOW-EARTH-053 has been conducting cyberespionage operations against government entities and critical infrastructure across at least eight countries in South, East, and Southeast Asia, plus one NATO member state, since December 2024. The group exploits unpatched Microsoft Exchange vulnerabilities, particularly the ProxyLogon chain, to gain initial access and deploys GODZILLA web shells for persistence. ShadowPad implants are staged via DLL sideloading of legitimate signed executables. Nearly half of the compromised environments showed overlap with another intrusion set, SHADOW-EARTH-054, sharing identical tooling including Evil-CreateDump and IOX proxy. The attackers conduct extensive Active Directory reconnaissance, credential harvesting, and mailbox exfiltration targeting high-profile government officials and defense contractors. Multiple tunneling tools including GOST and Wstunnel establish covert command-and-control channels, while lateral movement leverages WM...

Pulse ID: 69f3a95eda9a5492f5d1b6f4
Pulse Link: https://otx.alienvault.com/pulse/69f3a95eda9a5492f5d1b6f4
Pulse Author: AlienVault
Created: 2026-04-30 19:11:26

Be advised, this data is unverified and should be considered preliminary. Always do further verification.

#Asia #China #CredentialHarvesting #CyberSecurity #Cyberespionage #Espionage #Government #InfoSec #Microsoft #NATO #OTX #OpenThreatExchange #Proxy #RAT #ShadowPad #SideLoading #bot #AlienVault

LevelBlue - Open Threat Exchange

Learn about the latest cyber threats. Research, collaborate, and share threat intelligence in real time. Protect yourself and the community against today's emerging threats.

LevelBlue Open Threat Exchange

📰 China-Based Silver Fox APT Expands Espionage Campaign Across Asia with Fake Tax Audits

🇨🇳 China-based APT 'Silver Fox' expands its campaign across Asia, using fake tax audit emails to target medical and financial firms. The group has evolved into a dual-purpose espionage & financial threat. 🦊 #APT #SilverFox #CyberEspionage

🔗 https://cyber.netsecops.io

German prosecutors arrest suspected Russian spy in Berlin

German authorities say the suspect gathered intelligence on military aid to Ukraine and eyed potential sabotage targets.

POLITICO
Hacker who allegedly carried out cyberattacks for China is extradited to U.S. | TechCrunch

Xu Zewei is accused of participating in a Chinese government hacking group that broke into thousands of U.S. organizations and stole COVID-19-related research.

TechCrunch

HAFNIUM-linked suspect faces U.S. indictment.
• 12,700+ orgs impacted
• Exchange exploits at scale
• Research institutions targeted

Full story:
https://www.technadu.com/chinese-national-xu-zewei-extradited-for-hafnium-cyberattacks-appears-in-us-court-for-9-count-indictment/627152/

Your take?

#Infosec #CyberEspionage #HAFNIUM #ThreatIntel