⤷ Title: Earth Alux APT Group: Unveiling Its Espionage Toolkit
════════════════════════
𐀪 Author: do son
════════════════════════
ⴵ Time: Tue, 01 Apr 2025 01:05:32 +0000
════════════════════════
⌗ Tags: #Cyber Security #Cobeacon #Earth Alux #Earth Alux APT #RAILSETTER #VARGEIT backdoor
════════════════════════
𐀪 Author: do son
════════════════════════
ⴵ Time: Tue, 01 Apr 2025 01:05:32 +0000
════════════════════════
⌗ Tags: #Cyber Security #Cobeacon #Earth Alux #Earth Alux APT #RAILSETTER #VARGEIT backdoor
Daily CyberSecurity
Earth Alux APT Group: Unveiling Its Espionage Toolkit
Explore the capabilities of Earth Alux, an APT group using intricate tools for cyber-espionage in strategic sectors globally.
⤷ Title: BPFDoor Backdoor Used in Asia, Middle East Cyberespionage
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 16 Apr 2025 00:12:07 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Malware #APT #backdoor #BPF #BPFDoor #Cyberespionage #Earth Bluecrow #malware #network_security #Red Menshen
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 16 Apr 2025 00:12:07 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Malware #APT #backdoor #BPF #BPFDoor #Cyberespionage #Earth Bluecrow #malware #network_security #Red Menshen
Daily CyberSecurity
BPFDoor Backdoor Used in Asia, Middle East Cyberespionage
Trend Micro uncovers BPFDoor backdoor used in cyberespionage across Asia and the Middle East, attributing it to the Red Menshen APT group
⤷ Title: Legitimate Windows Tool Abused: mavinject.exe Used for Stealthy DLL Injection by Threat Actors
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 22 Apr 2025 00:33:19 +0000
════════════════════════
⌗ Tags: #Cybercriminals #App_V #APT #ASEC #cybersecurity #DLL injection #Earth Preta #Lazarus Group #malware injection #mavinject.exe #signed binary abuse #Windows Security
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 22 Apr 2025 00:33:19 +0000
════════════════════════
⌗ Tags: #Cybercriminals #App_V #APT #ASEC #cybersecurity #DLL injection #Earth Preta #Lazarus Group #malware injection #mavinject.exe #signed binary abuse #Windows Security
Daily CyberSecurity
Legitimate Windows Tool Abused: mavinject.exe Used for Stealthy DLL Injection by Threat Actors
Threat actors abuse Microsoft’s mavinject.exe to inject malicious DLLs into trusted processes, evading detection in stealthy APT campaigns.
⤷ Title: Earth Kurma APT Targets Southeast Asia with Stealthy Cyberespionage
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 29 Apr 2025 00:10:03 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #APT #Cyberespionage #Earth Kurma #Government Hacking #KRNRAT #MORIYA #Rootkits #SIMPOBOXSPY #Southeast Asia #Trend Research
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 29 Apr 2025 00:10:03 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #APT #Cyberespionage #Earth Kurma #Government Hacking #KRNRAT #MORIYA #Rootkits #SIMPOBOXSPY #Southeast Asia #Trend Research
Daily CyberSecurity
Earth Kurma APT Targets Southeast Asia with Stealthy Cyberespionage
Earth Kurma APT campaign targets Southeast Asian governments and telecoms using rootkits, loaders, and cloud services to steal sensitive data.
⤷ Title: Earth Kasha Refines Spear-Phishing Tactics in Espionage Campaign Targeting Taiwan and Japan
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 01 May 2025 00:03:42 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #ANEL #APT10 #cyber_espionage #DNS_over_HTTPS #Earth Kasha #Japan #NOOPDOOR #SharpHide #spear_phishing #Taiwan #Trend Micro
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 01 May 2025 00:03:42 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #ANEL #APT10 #cyber_espionage #DNS_over_HTTPS #Earth Kasha #Japan #NOOPDOOR #SharpHide #spear_phishing #Taiwan #Trend Micro
Daily CyberSecurity
Earth Kasha Refines Spear-Phishing Tactics in Espionage Campaign Targeting Taiwan and Japan
Earth Kasha targets Taiwan and Japan in a March 2025 spear-phishing campaign using ANEL and NOOPDOOR backdoors for stealthy cyber espionage.
⤷ Title: Eyes on Earth: The GEOINT OSINT Blog
════════════════════════
𐀪 Author: Intelligent rose
════════════════════════
ⴵ Time: Fri, 02 May 2025 19:39:25 GMT
════════════════════════
⌗ Tags: #osint #earth #cybersecurity #intelligence #geoint
════════════════════════
𐀪 Author: Intelligent rose
════════════════════════
ⴵ Time: Fri, 02 May 2025 19:39:25 GMT
════════════════════════
⌗ Tags: #osint #earth #cybersecurity #intelligence #geoint
Medium
Eyes on Earth: The GEOINT OSINT Blog
GEOINT, or Geospatial Intelligence, is a part of OSINT (Open-Source Intelligence) that focuses on information related to locations, maps…
⤷ Title: Earth Ammit Strikes Drone Supply Chains: VENOM and TIDRONE Campaigns Expose East Asia’s Critical Infrastructure
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 14 May 2025 00:20:43 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #APT #CLNTEND #CXCLNT #cyber_espionage #Earth Ammit #fiber_based evasion #military cybersecurity #supply chain attack #Taiwan #TIDRONE #Trend Micro #venom
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 14 May 2025 00:20:43 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #APT #CLNTEND #CXCLNT #cyber_espionage #Earth Ammit #fiber_based evasion #military cybersecurity #supply chain attack #Taiwan #TIDRONE #Trend Micro #venom
Daily CyberSecurity
Earth Ammit Strikes Drone Supply Chains: VENOM and TIDRONE Campaigns Expose East Asia’s Critical Infrastructure
Earth Ammit’s VENOM and TIDRONE campaigns target Taiwan and South Korea’s drone, military, and satellite sectors via stealthy supply chain attacks.
⤷ Title: Earth Lamia: China-Linked APT Targets Global Industries with Custom Backdoors
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 28 May 2025 00:01:21 +0000
════════════════════════
⌗ Tags: #Cyber Security #APT #backdoor #china #CVE #cyber_espionage #Earth Lamia #malware #PULSEPACK #sql injection
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 28 May 2025 00:01:21 +0000
════════════════════════
⌗ Tags: #Cyber Security #APT #backdoor #china #CVE #cyber_espionage #Earth Lamia #malware #PULSEPACK #sql injection
Daily CyberSecurity
Earth Lamia: China-Linked APT Targets Global Industries with Custom Backdoors
Earth Lamia, a China-linked APT, is targeting critical industries worldwide using SQL injection, CVEs, and custom backdoors like PULSEPACK.
⤷ Title: Operation DRAGONCLONE: China Mobile Tietong Hit by Advanced APT Attack
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 10 Jun 2025 00:27:20 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #APT #China Mobile Tietong #China_aligned threat actors #Cyberespionage #cybersecurity #DLL Sideloading #Earth Lamia #UNC5174 #VELETRIX #VShell
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 10 Jun 2025 00:27:20 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #APT #China Mobile Tietong #China_aligned threat actors #Cyberespionage #cybersecurity #DLL Sideloading #Earth Lamia #UNC5174 #VELETRIX #VShell
Daily CyberSecurity
Operation DRAGONCLONE: China Mobile Tietong Hit by Advanced APT Attack
Seqrite Labs uncovers Operation DRAGONCLONE, a sophisticated APT campaign targeting China Mobile Tietong with VELETRIX and VShell malware.
⤷ Title: Ongoing Attacks Exploit GeoServer RCE Flaw (CVE-2024-36401) to Install NetCat and XMRig CoinMiner
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 10 Jul 2025 00:11:17 +0000
════════════════════════
⌗ Tags: #Malware #Vulnerability Report #ASEC #CoinMiner #cybersecurity #Earth Baxia #Fortinet #GeoServer #GIS #netcat #rce #Remote Code Execution #Trend Micro #Vulnerability #XMRig
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 10 Jul 2025 00:11:17 +0000
════════════════════════
⌗ Tags: #Malware #Vulnerability Report #ASEC #CoinMiner #cybersecurity #Earth Baxia #Fortinet #GeoServer #GIS #netcat #rce #Remote Code Execution #Trend Micro #Vulnerability #XMRig
Daily CyberSecurity
Ongoing Attacks Exploit GeoServer RCE Flaw (CVE-2024-36401) to Install NetCat and XMRig CoinMiner
GeoServer's RCE flaw (CVE-2024-36401) is actively exploited to deploy NetCat reverse shells and XMRig CoinMiners on Windows/Linux, hijacking resources.
⤷ Title: Chinese Salt Typhoon Infiltrated US National Guard Network for Months
════════════════════════
𐀪 Author: Deeba Ahmed
════════════════════════
ⴵ Time: Thu, 17 Jul 2025 10:54:23 +0000
════════════════════════
⌗ Tags: #Security #Cyber Attacks #China #Cyber Attack #Cybersecurity #Earth Estries #FamousSparrow #GhostEmperor #National Guard #Salt Typhoon #UNC2286
════════════════════════
𐀪 Author: Deeba Ahmed
════════════════════════
ⴵ Time: Thu, 17 Jul 2025 10:54:23 +0000
════════════════════════
⌗ Tags: #Security #Cyber Attacks #China #Cyber Attack #Cybersecurity #Earth Estries #FamousSparrow #GhostEmperor #National Guard #Salt Typhoon #UNC2286
Hackread
Chinese Salt Typhoon Infiltrated US National Guard Network for Months
Follow us on Bluesky, Twitter (X), Mastodon and Facebook at @Hackread
⤷ Title: Google’s “Virtual Satellite” is Here: New AI Model AlphaEarth Foundations Maps the Planet with Unprecedented Detail
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 01 Aug 2025 02:22:57 +0000
════════════════════════
⌗ Tags: #Technology #AI #AlphaEarth Foundations #climate change #Earth Observation #Environmental Monitoring #Geospatial Data #google #Virtual Satellite
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 01 Aug 2025 02:22:57 +0000
════════════════════════
⌗ Tags: #Technology #AI #AlphaEarth Foundations #climate change #Earth Observation #Environmental Monitoring #Geospatial Data #google #Virtual Satellite
Daily CyberSecurity
Google's "Virtual Satellite" is Here: New AI Model AlphaEarth Foundations Maps the Planet with Unprecedented Detail
Google launches AlphaEarth Foundations, an AI model that functions as a "virtual satellite," integrating vast data to monitor and analyze changes across Earth with unprecedented speed and detail.
⤷ Title: Salt Typhoon APT Targets Global Telecom and Energy Sectors, Says Darktrace
════════════════════════
𐀪 Author: Deeba Ahmed
════════════════════════
ⴵ Time: Tue, 21 Oct 2025 19:06:41 +0000
════════════════════════
⌗ Tags: #Cyber Attacks #Security #China #Cyber Attack #Cybersecurity #Deed RAT #Earth Estries #europe #GhostEmperor #Malware #RAT #Salt Typhoon #SNAPPYBEE
════════════════════════
𐀪 Author: Deeba Ahmed
════════════════════════
ⴵ Time: Tue, 21 Oct 2025 19:06:41 +0000
════════════════════════
⌗ Tags: #Cyber Attacks #Security #China #Cyber Attack #Cybersecurity #Deed RAT #Earth Estries #europe #GhostEmperor #Malware #RAT #Salt Typhoon #SNAPPYBEE
Hackread
Salt Typhoon APT Targets Global Telecom and Energy Sectors, Says Darktrace
A group of state-sponsored (APT) actors, known as Salt Typhoon, remains a significant threat to networks across the globe, reveals the latest report from cybersecurity research firm Darktrace.
⤷ Title: China-Aligned APTs Launch “Premier Pass-as-a-Service,” Sharing Access in Coordinated Global Espionage
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 27 Oct 2025 00:10:55 +0000
════════════════════════
⌗ Tags: #Cyber Security #APT Collaboration #China APT #cyber_espionage #Earth Estries #Earth Naga #Premier Pass_as_a_Service #ShadowPad
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 27 Oct 2025 00:10:55 +0000
════════════════════════
⌗ Tags: #Cyber Security #APT Collaboration #China APT #cyber_espionage #Earth Estries #Earth Naga #Premier Pass_as_a_Service #ShadowPad
Daily CyberSecurity
China-Aligned APTs Launch "Premier Pass-as-a-Service," Sharing Access in Coordinated Global Espionage
Trend exposed "Premier Pass-as-a-Service," a model where Earth Estries (access broker) and Earth Naga (APT36) share compromised network access to deploy ShadowPad in a coordinated espionage campaign.
⤷ Title: Environmental impact of AI driven Cybersecurity: Balancing Progress with Planetary Health
════════════════════════
𐀪 Author: Rudhwiq Mayur Balivada
════════════════════════
ⴵ Time: Thu, 27 Nov 2025 07:38:33 GMT
════════════════════════
⌗ Tags: #cybersecurity #earth #ai #green #environment
════════════════════════
𐀪 Author: Rudhwiq Mayur Balivada
════════════════════════
ⴵ Time: Thu, 27 Nov 2025 07:38:33 GMT
════════════════════════
⌗ Tags: #cybersecurity #earth #ai #green #environment
Medium
Environmental impact of AI driven Cybersecurity: Balancing Progress with Planetary Health
Introduction
⤷ Title: “React2Shell” Storm: China-Nexus Groups Weaponize Critical React Flaw Hours After Disclosure
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 05 Dec 2025 02:09:05 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #APT #CVE_2025_55182 #Earth Lamia #Jackpot Panda #rce #React Server Components #React2Shell #zero_day
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 05 Dec 2025 02:09:05 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #APT #CVE_2025_55182 #Earth Lamia #Jackpot Panda #rce #React Server Components #React2Shell #zero_day
Daily CyberSecurity
"React2Shell" Storm: China-Nexus Groups Weaponize Critical React Flaw Hours After Disclosure
Amazon exposed Chinese APTs exploiting the React2Shell zero-day (CVE-2025-55182, CVSS 10.0) hours after disclosure. Earth Lamia and Jackpot Panda are actively targeting unpatched Next.js servers for reconnaissance.
⤷ Title: China APTs Exploiting React Server RCE (CVE-2025-55182) Hours After Disclosure
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 08 Dec 2025 04:18:36 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Vulnerability #AWS MadPot #China APT #CVE_2025_55182 #Earth Lamia #Jackpot Panda #Patch Now #RCE #React2Shell #Supply Chain
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 08 Dec 2025 04:18:36 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Vulnerability #AWS MadPot #China APT #CVE_2025_55182 #Earth Lamia #Jackpot Panda #Patch Now #RCE #React2Shell #Supply Chain
Penetration Testing Tools
China APTs Exploiting React Server RCE (CVE-2025-55182) Hours After Disclosure
Two China-linked hacking groups began exploiting a critical vulnerability in React Server Components just hours after it became
⤷ Title: The Living Mesh: Ink Dragon Turns European Government Servers into a Global ShadowPad Relay Network
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 18 Dec 2025 03:52:47 +0000
════════════════════════
⌗ Tags: #Cyber Security #APT #Check Point Research #Cyber Espionage #Earth Alux #European Security #FINALDRAFT #IIS Malware #Ink Dragon #ShadowPad #SharePoint Exploit
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 18 Dec 2025 03:52:47 +0000
════════════════════════
⌗ Tags: #Cyber Security #APT #Check Point Research #Cyber Espionage #Earth Alux #European Security #FINALDRAFT #IIS Malware #Ink Dragon #ShadowPad #SharePoint Exploit
Penetration Testing Tools
The Living Mesh: Ink Dragon Turns European Government Servers into a Global ShadowPad Relay Network
Researchers at Check Point Research have uncovered a large-scale espionage operation conducted by the Chinese APT group Ink
⤷ Title: Ink Dragon’s Global Mesh: How Chinese Spies Turn Compromised Government Servers into C2 Relay Nodes
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 18 Dec 2025 00:27:49 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #APT41 #ASP.NET #Check Point Research #cyber_espionage #Earth Alux #IIS Listener #Ink Dragon #Microsoft Graph API #Relay Network #ShadowPad
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 18 Dec 2025 00:27:49 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #APT41 #ASP.NET #Check Point Research #cyber_espionage #Earth Alux #IIS Listener #Ink Dragon #Microsoft Graph API #Relay Network #ShadowPad
Daily CyberSecurity
Ink Dragon’s Global Mesh: How Chinese Spies Turn Compromised Government Servers into C2 Relay Nodes
Ink Dragon is weaponizing government servers in Europe using a relay-centric mesh. By hijacking IIS servers, they mask C2 traffic across global networks.
⤷ Title: Phantom in the Machine: Inside Salt Typhoon’s “SnappyBee” Backdoor
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 06 Feb 2026 00:27:36 +0000
════════════════════════
⌗ Tags: #Malware #Advanced Persistent Threat #Cobalt Strike #Darktrace #Deed RAT #Demodex #DLL side_loading #Earth Estries #Malware Analysis #Salt Typhoon #SNAPPYBEE
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 06 Feb 2026 00:27:36 +0000
════════════════════════
⌗ Tags: #Malware #Advanced Persistent Threat #Cobalt Strike #Darktrace #Deed RAT #Demodex #DLL side_loading #Earth Estries #Malware Analysis #Salt Typhoon #SNAPPYBEE
Daily CyberSecurity
Phantom in the Machine: Inside Salt Typhoon’s "SnappyBee" Backdoor
Darktrace dissects SnappyBee (Deed RAT), a stealthy Salt Typhoon backdoor. Learn how it uses DLL side-loading & memory hooking to evade modern AV.