⤷ Title: We Saw It Coming: First Reports of an AI-Orchestrated Cyber Espionage Campaign
════════════════════════
𐀪 Author: Phil Stafford
════════════════════════
ⴵ Time: Sun, 16 Nov 2025 18:29:20 GMT
════════════════════════
⌗ Tags: #cybersecurity #mcp_server #ai #anthropic_claude #espionage
════════════════════════
𐀪 Author: Phil Stafford
════════════════════════
ⴵ Time: Sun, 16 Nov 2025 18:29:20 GMT
════════════════════════
⌗ Tags: #cybersecurity #mcp_server #ai #anthropic_claude #espionage
Medium
We Saw It Coming: First Reports of an AI-Orchestrated Cyber Espionage Campaign
The first reported AI-orchestrated cyber espionage campaign just validated what we’ve been warning about. Or did it? Either way, the…
⤷ Title: APT42 Escalation: ‘SpearSpecter’ Targets Officials and Relatives with Custom Malware
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 18 Nov 2025 03:20:39 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #APT42 #CloudflareWorkers #Espionage #IRGC #IsraelNationalDigitalAgency #SocialEngineering #SpearSpecter #Tamecat
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 18 Nov 2025 03:20:39 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #APT42 #CloudflareWorkers #Espionage #IRGC #IsraelNationalDigitalAgency #SocialEngineering #SpearSpecter #Tamecat
Penetration Testing Tools
APT42 Escalation: 'SpearSpecter' Targets Officials and Relatives with Custom Malware
APT42 launched "SpearSpecter," a campaign targeting defense officials and their relatives. It uses personalized social engineering and the stealthy, PowerShell-based TAMECAT malware.
⤷ Title: Iranian APT UNC1549 Infiltrates Aerospace by Hijacking Trusted DLLs and Executing VDI Breakouts
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 19 Nov 2025 01:51:04 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #DCSYNCER.SLICK #DLL hijacking #Espionage #Iran APT #Supply Chain #TWOSTROKE #UNC1549 #VDI Breakout
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 19 Nov 2025 01:51:04 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #DCSYNCER.SLICK #DLL hijacking #Espionage #Iran APT #Supply Chain #TWOSTROKE #UNC1549 #VDI Breakout
Daily CyberSecurity
Iranian APT UNC1549 Infiltrates Aerospace by Hijacking Trusted DLLs and Executing VDI Breakouts
Mandiant exposed UNC1549, an Iranian APT, using DLL search order hijacking on Citrix/VMware to deploy TWOSTROKE and DCSYNCER.SLICK. The group performs VDI breakouts for long-term espionage.
⤷ Title: When AI Goes Rogue: Inside the First Large-Scale Cyberattack Run by Claude
════════════════════════
𐀪 Author: Shin Jara
════════════════════════
ⴵ Time: Fri, 28 Nov 2025 07:57:29 GMT
════════════════════════
⌗ Tags: #ai #threat_intelligence #cybersecurity #espionage #claude
════════════════════════
𐀪 Author: Shin Jara
════════════════════════
ⴵ Time: Fri, 28 Nov 2025 07:57:29 GMT
════════════════════════
⌗ Tags: #ai #threat_intelligence #cybersecurity #espionage #claude
Medium
When AI Goes Rogue: Inside the First Large-Scale Cyberattack Run by Claude
Chinese hackers used Anthropic’s Claude to scale targeted intrusions, turning AI from a coding assistant into a state-backed cyber force
⤷ Title: Bloody Wolf APT Expands to Central Asia, Deploys NetSupport RAT via Custom Java Droppers and Geo-Fencing
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 01 Dec 2025 00:00:21 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #APT #Bloody Wolf #Central Asia #Espionage #Java Dropper #NetSupport RAT #spear_phishing
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 01 Dec 2025 00:00:21 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #APT #Bloody Wolf #Central Asia #Espionage #Java Dropper #NetSupport RAT #spear_phishing
Daily CyberSecurity
Bloody Wolf APT Expands to Central Asia, Deploys NetSupport RAT via Custom Java Droppers and Geo-Fencing
Bloody Wolf APT is targeting Central Asia using custom Java droppers to deploy the NetSupport RAT. The group uses geo-fencing and fake Ministry of Justice lures to achieve stealthy, persistent access for espionage.
⤷ Title: Microsoft Finally Patches LNK Flaw (CVE-2025-9491) Exploited by Spies Since 2017
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 05 Dec 2025 03:49:50 +0000
════════════════════════
⌗ Tags: #Vulnerability #0patch #CVE_2025_9491 #Espionage #LNK Flaw #Microsoft #Patch Tuesday #PlugX #windows #zero_day
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 05 Dec 2025 03:49:50 +0000
════════════════════════
⌗ Tags: #Vulnerability #0patch #CVE_2025_9491 #Espionage #LNK Flaw #Microsoft #Patch Tuesday #PlugX #windows #zero_day
Penetration Testing Tools
Microsoft Finally Patches LNK Flaw (CVE-2025-9491) Exploited by Spies Since 2017
Microsoft has quietly patched a long-standing flaw in Windows that had been exploited in real-world attacks for several
⤷ Title: Russian Calisto APT Targets Reporters Without Borders with Custom AiTM Phishing and “Missing File” Lure
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 05 Dec 2025 00:19:51 +0000
════════════════════════
⌗ Tags: #Cyber Security #AitM Phishing #Calisto #COLDRIVER #Espionage #Reporters Without Borders #RSF #Russian APT #social engineering
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 05 Dec 2025 00:19:51 +0000
════════════════════════
⌗ Tags: #Cyber Security #AitM Phishing #Calisto #COLDRIVER #Espionage #Reporters Without Borders #RSF #Russian APT #social engineering
Daily CyberSecurity
Russian Calisto APT Targets Reporters Without Borders with Custom AiTM Phishing and "Missing File" Lure
Sekoia exposed Russian Calisto APT (FSB-linked) targeting RSF and NGOs with spear-phishing. The attack uses a custom AiTM kit and a "missing file" lure to steal credentials and 2FA codes.
⤷ Title: Iran-Linked MuddyWater Deploys UDPGangster Backdoor, Using UDP Protocol for Covert C2
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 08 Dec 2025 00:18:41 +0000
════════════════════════
⌗ Tags: #Malware #anti_analysis #APT #Espionage #MuddyWater #spear_phishing #Turkey #UDP C2 #UDPGangster
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 08 Dec 2025 00:18:41 +0000
════════════════════════
⌗ Tags: #Malware #anti_analysis #APT #Espionage #MuddyWater #spear_phishing #Turkey #UDP C2 #UDPGangster
Daily CyberSecurity
Iran-Linked MuddyWater Deploys UDPGangster Backdoor, Using UDP Protocol for Covert C2
FortiGuard exposed UDPGangster, a custom UDP backdoor deployed by MuddyWater APT. The malware evades network defenses and analysis by using UDP for C2 and checking for single-core CPUs/low RAM.
⤷ Title: React2Shell: Max-Score RCE (CVSS 10.0) Triggers Widespread Exploitation by Espionage Groups & Miners
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Sat, 13 Dec 2025 08:49:12 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Vulnerability Report #crypto mining #CVE_2025_55182 #Espionage #GTIG #rce #React Server Components #React2Shell #zero_day
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Sat, 13 Dec 2025 08:49:12 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Vulnerability Report #crypto mining #CVE_2025_55182 #Espionage #GTIG #rce #React Server Components #React2Shell #zero_day
Daily CyberSecurity
React2Shell: Max-Score RCE (CVSS 10.0) Triggers Widespread Exploitation by Espionage Groups & Miners
A critical RCE (CVSS 10.0) in React Server Components (CVE-2025-55182) is under widespread exploitation by China-nexus groups deploying MINOCAT and HISONIC backdoors, plus XMRig miners.
⤷ Title: New NANOREMOTE Backdoor Uses Google Drive API for Covert C2 and Links to FINALDRAFT Espionage Group
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 15 Dec 2025 00:42:47 +0000
════════════════════════
⌗ Tags: #Malware #backdoor #C2 #Espionage #FINALDRAFT #Google Drive #NANOREMOTE #OAuth 2.0 #REF7707 #WMLOADER
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 15 Dec 2025 00:42:47 +0000
════════════════════════
⌗ Tags: #Malware #backdoor #C2 #Espionage #FINALDRAFT #Google Drive #NANOREMOTE #OAuth 2.0 #REF7707 #WMLOADER
Daily CyberSecurity
New NANOREMOTE Backdoor Uses Google Drive API for Covert C2 and Links to FINALDRAFT Espionage Group
NANOREMOTE, a new Windows backdoor, leverages the Google Drive API for covert C2 and data exfiltration using OAuth 2.0 tokens. The malware shares a hard-coded AES key with the FINALDRAFT family, linking it to seasoned espionage actors.