⤷ Title: China-Nexus Espionage: ScatterBrain Obfuscation Tactics Revealed
════════════════════════
𐀪 Author: do son
════════════════════════
ⴵ Time: Fri, 31 Jan 2025 01:46:04 +0000
════════════════════════
⌗ Tags: #Malware #APT41 #Complete Headerless Mode #Complete Mode #Control Flow Graph #POISONPLUG #POISONPLUG.SHADOW #ScatterBrain #Selective Mode #ShadowPad
════════════════════════
𐀪 Author: do son
════════════════════════
ⴵ Time: Fri, 31 Jan 2025 01:46:04 +0000
════════════════════════
⌗ Tags: #Malware #APT41 #Complete Headerless Mode #Complete Mode #Control Flow Graph #POISONPLUG #POISONPLUG.SHADOW #ScatterBrain #Selective Mode #ShadowPad
Cybersecurity News
China-Nexus Espionage: ScatterBrain Obfuscation Tactics Revealed
Discover ScatterBrain, a powerful obfuscating compiler employed by APT41. Understand its role in protecting the advanced modular backdoor POISONPLUG.SHADOW.
⤷ Title: Updated ShadowPad Malware Facilitates Ransomware Deployment in Global Attacks
════════════════════════
𐀪 Author: do son
════════════════════════
ⴵ Time: Fri, 21 Feb 2025 01:43:35 +0000
════════════════════════
⌗ Tags: #Malware #APT41 #Earth Baku #Earth Freybug #Earth Longzhi #ransomware #ShadowPad #ShadowPad malware
════════════════════════
𐀪 Author: do son
════════════════════════
ⴵ Time: Fri, 21 Feb 2025 01:43:35 +0000
════════════════════════
⌗ Tags: #Malware #APT41 #Earth Baku #Earth Freybug #Earth Longzhi #ransomware #ShadowPad #ShadowPad malware
Cybersecurity News
Updated ShadowPad Malware Facilitates Ransomware Deployment in Global Attacks
Explore the evolving threat of ShadowPad malware, now facilitating ransomware attacks linked to Chinese threat actors.
⤷ Title: APT41/RedGolf Infrastructure Briefly Exposed: Fortinet Zero-Days Targeted Shiseido
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 21 Apr 2025 00:15:27 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Malware #APT41 #cyberattack #Exploit #Fortinet #KEYPLUG #RedGolf #Shiseido #threat intelligence #zero_day
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 21 Apr 2025 00:15:27 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Malware #APT41 #cyberattack #Exploit #Fortinet #KEYPLUG #RedGolf #Shiseido #threat intelligence #zero_day
Daily CyberSecurity
APT41/RedGolf Infrastructure Briefly Exposed: Fortinet Zero-Days Targeted Shiseido
A misconfiguration exposed APT41 tools targeting Shiseido, revealing Fortinet exploit scripts, webshells, and reconnaissance tactics.
⤷ Title: APT41 Uses Google Calendar as Covert C2 in Stealthy Cyberespionage Campaign
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 30 May 2025 00:13:13 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #APT41 #C2 #Cyberespionage #Google Calendar #Google Threat Intelligence #malware #state_sponsored #TOUGHPROGRESS
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 30 May 2025 00:13:13 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #APT41 #C2 #Cyberespionage #Google Calendar #Google Threat Intelligence #malware #state_sponsored #TOUGHPROGRESS
Daily CyberSecurity
APT41 Uses Google Calendar as Covert C2 in Stealthy Cyberespionage Campaign
APT41 is exploiting Google Calendar as a covert C2 channel in the TOUGHPROGRESS cyberespionage campaign, targeting government entities with stealthy malware.
⤷ Title: APT41 Unleashes Stealthy Malware Using Google Calendar for Covert C2!
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 10 Jun 2025 00:19:30 +0000
════════════════════════
⌗ Tags: #Cyber Security #APT41 #C2 #Command and Control #Cyberespionage #cybersecurity #Google Calendar #malware #Resecurity #spear_phishing #Taiwan
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 10 Jun 2025 00:19:30 +0000
════════════════════════
⌗ Tags: #Cyber Security #APT41 #C2 #Command and Control #Cyberespionage #cybersecurity #Google Calendar #malware #Resecurity #spear_phishing #Taiwan
Daily CyberSecurity
APT41 Unleashes Stealthy Malware Using Google Calendar for Covert C2!
APT41 is leveraging Google Calendar as a covert C2 channel in a new multi-stage malware campaign targeting a Taiwanese government website.
⤷ Title: Ransomware or Espionage? Fog Ransomware Attack in Asia Raises Suspicion with Rare Toolset
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Sat, 14 Jun 2025 00:16:54 +0000
════════════════════════
⌗ Tags: #Malware #APT41 #Cobalt Strike #Cybercrime #cybersecurity #Espionage #Financial Institution #Fog Ransomware #GC2 #persistence #ransomware #Symantec #Syteca
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Sat, 14 Jun 2025 00:16:54 +0000
════════════════════════
⌗ Tags: #Malware #APT41 #Cobalt Strike #Cybercrime #cybersecurity #Espionage #Financial Institution #Fog Ransomware #GC2 #persistence #ransomware #Symantec #Syteca
Daily CyberSecurity
Ransomware or Espionage? Fog Ransomware Attack in Asia Raises Suspicion with Rare Toolset
Symantec reports a Fog ransomware attack on an Asian bank that used unusual tools like employee monitoring software and an APT-linked backdoor, suggesting possible espionage.
⤷ Title: APT41 Unleashes Full Arsenal in Rare African Cyberespionage Campaign
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 22 Jul 2025 00:06:03 +0000
════════════════════════
⌗ Tags: #Cyber Security #Africa #APT41 #Cobalt Strike #Cyberespionage #Government IT #Impacket #kaspersky #lateral movement #threat group
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 22 Jul 2025 00:06:03 +0000
════════════════════════
⌗ Tags: #Cyber Security #Africa #APT41 #Cobalt Strike #Cyberespionage #Government IT #Impacket #kaspersky #lateral movement #threat group
Daily CyberSecurity
APT41 Unleashes Full Arsenal in Rare African Cyberespionage Campaign
Kaspersky uncovers a sophisticated APT41 cyberespionage campaign targeting African government IT, showcasing the Chinese group's full TTPs, including Impacket and Cobalt Strike.
⤷ Title: APT41’s New Frontier: Chinese Cyberespionage Group Targets African Governments
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 22 Jul 2025 23:42:27 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Africa #APT41 #China #Cobalt Strike #Cyberespionage #Government IT #Impacket #kaspersky #Lateral Movement #Threat Group
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 22 Jul 2025 23:42:27 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Africa #APT41 #China #Cobalt Strike #Cyberespionage #Government IT #Impacket #kaspersky #Lateral Movement #Threat Group
Penetration Testing Tools
APT41's New Frontier: Chinese Cyberespionage Group Targets African Governments
Kaspersky uncovers a new APT41 cyberespionage campaign targeting African government IT services, showcasing the Chinese group's full TTPs and a strategic geographic pivot.
⤷ Title: The Silent Spy: How Chinese Hackers are Exploiting U.S.-China Policy
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 18 Sep 2025 00:19:34 +0000
════════════════════════
⌗ Tags: #Cyber Security #APT41 #china #cybersecurity #Espionage #Hacking #Proofpoint #Spearphishing #TA415 #U.S. #VS Code
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 18 Sep 2025 00:19:34 +0000
════════════════════════
⌗ Tags: #Cyber Security #APT41 #china #cybersecurity #Espionage #Hacking #Proofpoint #Spearphishing #TA415 #U.S. #VS Code
Daily CyberSecurity
The Silent Spy: How Chinese Hackers are Exploiting U.S.-China Policy
A new report reveals Chinese threat actor TA415 is targeting U.S. policy organizations with sophisticated spearphishing campaigns to gather intelligence.
⤷ Title: TA415 Espionage: New Chinese Cyber Attacks Target U.S. Officials
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 19 Sep 2025 07:58:14 +0000
════════════════════════
⌗ Tags: #Cyber Security #APT41 #Brass Typhoon #China #Cyber Espionage #cybersecurity #phishing #TA415 #U.S. government
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 19 Sep 2025 07:58:14 +0000
════════════════════════
⌗ Tags: #Cyber Security #APT41 #Brass Typhoon #China #Cyber Espionage #cybersecurity #phishing #TA415 #U.S. government
Penetration Testing Tools
TA415 Espionage: New Chinese Cyber Attacks Target U.S. Officials
A Chinese state-linked group, TA415, launched a new cyber espionage campaign targeting U.S. government and think tanks with advanced phishing tactics.
⤷ Title: China APT Infiltrates US Policy Nonprofit in Months-Long Espionage Campaign Using DLL Sideloading
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 10 Nov 2025 00:16:35 +0000
════════════════════════
⌗ Tags: #Cyber Security #APT41 #Broadcom #China APT #DLL Sideloading #Espionage #Non_Profit Target #Scheduled Task #US Policy
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 10 Nov 2025 00:16:35 +0000
════════════════════════
⌗ Tags: #Cyber Security #APT41 #Broadcom #China APT #DLL Sideloading #Espionage #Non_Profit Target #Scheduled Task #US Policy
Daily CyberSecurity
China APT Infiltrates US Policy Nonprofit in Months-Long Espionage Campaign Using DLL Sideloading
A China-linked APT targeted a U.S. policy nonprofit for weeks in April 2025. The group used DLL sideloading via a VipreAV binary and msbuild.exe scheduled tasks to achieve SYSTEM persistence for espionage.
⤷ Title: The Silent Listener: New DRBControl Backdoor Variant Uses Network Sniffing to Evade Detection
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 18 Dec 2025 03:48:07 +0000
════════════════════════
⌗ Tags: #Malware #APT27 #APT41 #Cyber Espionage #DLL Sideloading #DRBControl #IIJ #malware analysis #Mofu Loader #Promiscuous Mode #ShadowPad #Type 1 Backdoor
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 18 Dec 2025 03:48:07 +0000
════════════════════════
⌗ Tags: #Malware #APT27 #APT41 #Cyber Espionage #DLL Sideloading #DRBControl #IIJ #malware analysis #Mofu Loader #Promiscuous Mode #ShadowPad #Type 1 Backdoor
Penetration Testing Tools
The Silent Listener: New DRBControl Backdoor Variant Uses Network Sniffing to Evade Detection
Japanese company Internet Initiative Japan (IIJ) has reported observing a new variant of the malware known as Type
⤷ Title: Ink Dragon’s Global Mesh: How Chinese Spies Turn Compromised Government Servers into C2 Relay Nodes
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 18 Dec 2025 00:27:49 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #APT41 #ASP.NET #Check Point Research #cyber_espionage #Earth Alux #IIS Listener #Ink Dragon #Microsoft Graph API #Relay Network #ShadowPad
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 18 Dec 2025 00:27:49 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #APT41 #ASP.NET #Check Point Research #cyber_espionage #Earth Alux #IIS Listener #Ink Dragon #Microsoft Graph API #Relay Network #ShadowPad
Daily CyberSecurity
Ink Dragon’s Global Mesh: How Chinese Spies Turn Compromised Government Servers into C2 Relay Nodes
Ink Dragon is weaponizing government servers in Europe using a relay-centric mesh. By hijacking IIS servers, they mask C2 traffic across global networks.
⤷ Title: Taiwan Faces 2.6 Million Cyberattacks Daily from China
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 08 Jan 2026 00:01:43 +0000
════════════════════════
⌗ Tags: #Cyber Security #APT41 #Critical Infrastructure #Cyber Warfare #Energy Sector Security #Hybrid Warfare #infosec #Mustang Panda #Taiwan NSB
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 08 Jan 2026 00:01:43 +0000
════════════════════════
⌗ Tags: #Cyber Security #APT41 #Critical Infrastructure #Cyber Warfare #Energy Sector Security #Hybrid Warfare #infosec #Mustang Panda #Taiwan NSB
Daily CyberSecurity
Taiwan Faces 2.6 Million Cyberattacks Daily from China
Recently, Taiwan’s National Security Bureau (NSB) has released a comprehensive report detailing a massive surge in state-sponsored cyber aggression. The analysis for the year 2025 paints a grim pi…
⤷ Title: The Tenfold Surge: China’s 2025 Cyber Blitz on Taiwan’s Power Grid
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 08 Jan 2026 08:45:35 +0000
════════════════════════
⌗ Tags: #Cyber Security #APT41 #China #Critical Infrastructure #Cyber Espionage 2026 #Energy Sector #Hybrid Warfare #ICS Security #Mustang Panda #NSB #Taiwan
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 08 Jan 2026 08:45:35 +0000
════════════════════════
⌗ Tags: #Cyber Security #APT41 #China #Critical Infrastructure #Cyber Espionage 2026 #Energy Sector #Hybrid Warfare #ICS Security #Mustang Panda #NSB #Taiwan
Information Security News
The Tenfold Surge: China’s 2025 Cyber Blitz on Taiwan’s Power Grid
In its most recent assessment, Taiwan’s National Security Bureau has characterized 2025 as an epoch in which Chinese cyber incursions transcended mere background noise to become an instrument of s…
⤷ Title: Dragon in the Archives: How “Amaranth-Dragon” Weaponized a WinRAR Zero-Day to Spy on Southeast Asia
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 06 Feb 2026 02:47:01 +0000
════════════════════════
⌗ Tags: #Cyber Security #Vulnerability #Amaranth_Dragon #APT41 #CVE_2025_8088 #Cyber Espionage #DLL side_loading #Havoc framework #Southeast Asia #Spear Phishing #Tech News 2026 #TGAmaranth RAT #Winrar
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 06 Feb 2026 02:47:01 +0000
════════════════════════
⌗ Tags: #Cyber Security #Vulnerability #Amaranth_Dragon #APT41 #CVE_2025_8088 #Cyber Espionage #DLL side_loading #Havoc framework #Southeast Asia #Spear Phishing #Tech News 2026 #TGAmaranth RAT #Winrar
Penetration Testing Tools
Dragon in the Archives: How "Amaranth-Dragon" Weaponized a WinRAR Zero-Day to Spy on Southeast Asia
In 2025, Southeast Asia witnessed a pronounced escalation in cyber-espionage operations, meticulously cloaked in missives pertaining to regional