⤷ Title: Sandworm APT Attacks Belarus Military With LNK Exploit and OpenSSH Over Tor obfs4 Backdoor
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Sat, 01 Nov 2025 11:35:46 +0000
════════════════════════
⌗ Tags: #Cyber Security #Belarus Military #DLL Sideloading #LNK Exploit #obfs4 #OpenSSH #Russia APT #SANDWORM #Tor network
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Sat, 01 Nov 2025 11:35:46 +0000
════════════════════════
⌗ Tags: #Cyber Security #Belarus Military #DLL Sideloading #LNK Exploit #obfs4 #OpenSSH #Russia APT #SANDWORM #Tor network
Daily CyberSecurity
Sandworm APT Attacks Belarus Military With LNK Exploit and OpenSSH Over Tor obfs4 Backdoor
Cyble exposed a Sandworm-linked espionage campaign targeting Belarusian military UAV personnel. It uses a malicious LNK file to deploy OpenSSH over Tor obfs4 for stealthy, persistent remote access.
⤷ Title: Operation SkyCloak Targets Russian/Belarusian Military With LNK Exploit and OpenSSH Over Tor Backdoor
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 03 Nov 2025 00:41:01 +0000
════════════════════════
⌗ Tags: #Cyber Security #Belarus Military #DLL Sideloading #LNK Exploit #obfs4 #OpenSSH #Russian Espionage #SkyCloak #Tor network
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 03 Nov 2025 00:41:01 +0000
════════════════════════
⌗ Tags: #Cyber Security #Belarus Military #DLL Sideloading #LNK Exploit #obfs4 #OpenSSH #Russian Espionage #SkyCloak #Tor network
Daily CyberSecurity
Operation SkyCloak Targets Russian/Belarusian Military With LNK Exploit and OpenSSH Over Tor Backdoor
SEQRITE exposed SkyCloak, an espionage campaign targeting Russian/Belarusian military personnel. It uses malicious LNK files to deploy OpenSSH over Tor obfs4 bridges for stealthy, persistent remote access.
⤷ Title: Chinese APT UNC6384 Pivots to Europe, Exploits Windows LNK Flaw to Deploy PlugX via Canon DLL Sideloading
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 03 Nov 2025 00:29:48 +0000
════════════════════════
⌗ Tags: #Cyber Security #Vulnerability Report #Chinese APT #DLL Sideloading #Espionage #European Diplomacy #LNK Exploit #PlugX #UNC6384 #ZDI_CAN_25373
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 03 Nov 2025 00:29:48 +0000
════════════════════════
⌗ Tags: #Cyber Security #Vulnerability Report #Chinese APT #DLL Sideloading #Espionage #European Diplomacy #LNK Exploit #PlugX #UNC6384 #ZDI_CAN_25373
Daily CyberSecurity
Chinese APT UNC6384 Pivots to Europe, Exploits Windows LNK Flaw to Deploy PlugX via Canon DLL Sideloading
Researchers at Arctic Wolf Labs have uncovered an extensive cyber espionage campaign by UNC6384, a Chinese-affiliated threat actor, targeting European diplomatic entities across Hungary, Belgium, …
⤷ Title: Operation Peek-A-Baku: Silent Lynx APT Exploits LNK Flaws to Deploy Reverse Shells via GitHub Against Central Asian Diplomacy
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 04 Nov 2025 00:18:01 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #APT #Central Asia #Espionage #LNK Exploit #Operation Peek_A_Baku #reverse shell #Silent Lynx
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 04 Nov 2025 00:18:01 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #APT #Central Asia #Espionage #LNK Exploit #Operation Peek_A_Baku #reverse shell #Silent Lynx
Daily CyberSecurity
Operation Peek-A-Baku: Silent Lynx APT Exploits LNK Flaws to Deploy Reverse Shells via GitHub Against Central Asian Diplomacy
Seqrite exposed Silent Lynx APT targeting Central Asia and Russia with Operation Peek-A-Baku. The group uses LNK files and GitHub to deploy Laplas reverse shells and SilentSweeper for espionage intelligence.
⤷ Title: APT-C-60 Targets Japan: New SpyGlace Malware Uses VHDX LNK and GitHub Tasking for Persistent Espionage
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 06 Nov 2025 00:07:30 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #APT_C_60 #cyber_espionage #Github C2 #Japan #Job Scam #LNK Exploit #SpyGlace #VHDX
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 06 Nov 2025 00:07:30 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #APT_C_60 #cyber_espionage #Github C2 #Japan #Job Scam #LNK Exploit #SpyGlace #VHDX
Daily CyberSecurity
APT-C-60 Targets Japan: New SpyGlace Malware Uses VHDX LNK and GitHub Tasking for Persistent Espionage
JPCERT exposed APT-C-60 targeting Japan via VHDX LNK files in phishing emails. The SpyGlace malware uses GitHub to fetch encrypted commands and statcounter for victim telemetry.
⤷ Title: Kimsuky APT Deploys Dual KimJongRAT Payloads, Switching Between PE/PowerShell Based on Windows Defender Status
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 25 Nov 2025 00:16:35 +0000
════════════════════════
⌗ Tags: #Malware #DPRK APT #Dual Payload #GitHub Releases #KimJongRAT #Kimsuky #LNK Exploit #Windows Defender Bypass
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 25 Nov 2025 00:16:35 +0000
════════════════════════
⌗ Tags: #Malware #DPRK APT #Dual Payload #GitHub Releases #KimJongRAT #Kimsuky #LNK Exploit #Windows Defender Bypass
Daily CyberSecurity
Kimsuky APT Deploys Dual KimJongRAT Payloads, Switching Between PE/PowerShell Based on Windows Defender Status
ENKI exposed a Kimsuky APT campaign using a dual PE/PowerShell payload that switches based on Windows Defender status to deploy KimJongRAT. The malware steals Chrome AppBound keys via GitHub Releases C2.
⤷ Title: Operation Hanoi Thief: Hackers Use ‘Pseudo-Polyglot’ LNK/Image to Deploy LOTUSHARVEST Stealer via DLL Sideloading
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 01 Dec 2025 00:42:31 +0000
════════════════════════
⌗ Tags: #Cybercriminals #DLL Sideloading #information stealer #LNK Exploit #LOTUSHARVEST #Operation Hanoi Thief #Pseudo_Polyglot #Recruitment Scam #Vietnam
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 01 Dec 2025 00:42:31 +0000
════════════════════════
⌗ Tags: #Cybercriminals #DLL Sideloading #information stealer #LNK Exploit #LOTUSHARVEST #Operation Hanoi Thief #Pseudo_Polyglot #Recruitment Scam #Vietnam
Daily CyberSecurity
Operation Hanoi Thief: Hackers Use 'Pseudo-Polyglot' LNK/Image to Deploy LOTUSHARVEST Stealer via DLL Sideloading
Operation Hanoi Thief targets Vietnam with a pseudo-polyglot LNK/image file that executes malicious code via ftp.exe. The attack deploys LOTUSHARVEST stealer via DLL sideloading to steal Chrome/Edge credentials.
⤷ Title: Microsoft Finally Patches LNK Flaw (CVE-2025-9491) Exploited by Spies Since 2017
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 05 Dec 2025 03:49:50 +0000
════════════════════════
⌗ Tags: #Vulnerability #0patch #CVE_2025_9491 #Espionage #LNK Flaw #Microsoft #Patch Tuesday #PlugX #windows #zero_day
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 05 Dec 2025 03:49:50 +0000
════════════════════════
⌗ Tags: #Vulnerability #0patch #CVE_2025_9491 #Espionage #LNK Flaw #Microsoft #Patch Tuesday #PlugX #windows #zero_day
Penetration Testing Tools
Microsoft Finally Patches LNK Flaw (CVE-2025-9491) Exploited by Spies Since 2017
Microsoft has quietly patched a long-standing flaw in Windows that had been exploited in real-world attacks for several
⤷ Title: Operation DUPEHIKE Hits Russian HR: Bonus Lure Delivers DUPERUNNER and Adaptix C2 via Process Injection
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 05 Dec 2025 00:35:53 +0000
════════════════════════
⌗ Tags: #Malware #Adaptix C2 #DUPERUNNER #HR Targets #LNK Exploit #Process injection #russia #spear_phishing
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 05 Dec 2025 00:35:53 +0000
════════════════════════
⌗ Tags: #Malware #Adaptix C2 #DUPERUNNER #HR Targets #LNK Exploit #Process injection #russia #spear_phishing
Daily CyberSecurity
Operation DUPEHIKE Hits Russian HR: Bonus Lure Delivers DUPERUNNER and Adaptix C2 via Process Injection
SEQRITE exposed Operation DUPEHIKE targeting Russian HR with a malicious LNK bonus lure. The DUPERUNNER implant uses PowerShell and process injection into explorer.exe to deploy the Adaptix C2 Beacon.
⤷ Title: Patchwork APT Deploys StreamSpy Trojan, Hiding C2 Commands in WebSocket Traffic for Stealth Espionage
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 05 Dec 2025 00:06:43 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #APT #Cyberespionage #File Transfer #LNK File #Patchwork #persistence #StreamSpy #WebSocket C2
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 05 Dec 2025 00:06:43 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #APT #Cyberespionage #File Transfer #LNK File #Patchwork #persistence #StreamSpy #WebSocket C2
Daily CyberSecurity
Patchwork APT Deploys StreamSpy Trojan, Hiding C2 Commands in WebSocket Traffic for Stealth Espionage
Patchwork APT deployed StreamSpy, a new trojan that uses WebSocket for covert C2 and HTTP for file transfer, blending malicious activity with web traffic to evade detection during espionage operations.