⤷ Title: GONEPOSTAL: New Outlook Backdoor by Russia’s APT28 Uses Email for C2
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 10 Sep 2025 00:13:59 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Malware #APT28 #cybersecurity #DLL side_loading #Fancy Bear #GONEPOSTAL #malware #Microsoft Outlook #VBA Macro
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 10 Sep 2025 00:13:59 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Malware #APT28 #cybersecurity #DLL side_loading #Fancy Bear #GONEPOSTAL #malware #Microsoft Outlook #VBA Macro
Daily CyberSecurity
GONEPOSTAL: New Outlook Backdoor by Russia's APT28 Uses Email for C2
A new report reveals GONEPOSTAL, a backdoor by Russia's APT28 that hides in Outlook macros and uses email itself as a covert command-and-control channel for espionage.
⤷ Title: GONEPOSTAL: New Espionage Malware Hijacks Outlook for Covert Attacks
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 11 Sep 2025 08:04:55 +0000
════════════════════════
⌗ Tags: #Malware #APT28 #cybercrime #cybersecurity #Espionage #Kroll #KTA007 #malware #outlook
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 11 Sep 2025 08:04:55 +0000
════════════════════════
⌗ Tags: #Malware #APT28 #cybercrime #cybersecurity #Espionage #Kroll #KTA007 #malware #outlook
Penetration Testing Tools
GONEPOSTAL: New Espionage Malware Hijacks Outlook for Covert Attacks
Researchers uncover GONEPOSTAL, a new malware from the APT28 group that turns Microsoft Outlook into a backdoor for discreet espionage and data exfiltration.
⤷ Title: APT28’s BeardShell Campaign: Steganography, Cloud Abuse, and Persistent Espionage
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 17 Sep 2025 00:13:42 +0000
════════════════════════
⌗ Tags: #Cyber Security #APT28 #cyber_espionage #cybersecurity #malware #russia #threat actor
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 17 Sep 2025 00:13:42 +0000
════════════════════════
⌗ Tags: #Cyber Security #APT28 #cyber_espionage #cybersecurity #malware #russia #threat actor
Daily CyberSecurity
APT28’s BeardShell Campaign: Steganography, Cloud Abuse, and Persistent Espionage
A new APT28 campaign targets Ukraine's military with a blend of steganography, open-source tools, and legitimate cloud services for covert C2.
⤷ Title: Next-Gen Threat: Google Exposes AI-Enabled Malware That Rewrites Its Own Code with Gemini LLM
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 06 Nov 2025 02:15:36 +0000
════════════════════════
⌗ Tags: #Malware #AI_Enabled Malware #APT28 #cybersecurity #Gemini API #Generative AI #Metamorphic Malware #PROMPTFLUX
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 06 Nov 2025 02:15:36 +0000
════════════════════════
⌗ Tags: #Malware #AI_Enabled Malware #APT28 #cybersecurity #Gemini API #Generative AI #Metamorphic Malware #PROMPTFLUX
Daily CyberSecurity
Next-Gen Threat: Google Exposes AI-Enabled Malware That Rewrites Its Own Code with Gemini LLM
Google exposed AI-enabled malware like PROMPTFLUX, which uses the Gemini API to dynamically rewrite its own source code to evade detection. APT28 was seen deploying an LLM-assisted stealer.
⤷ Title: The GRU’s Silent Shift: How BlueDelta Hijacks Ukrainian Webmail Using ngrok and Mocky
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 22 Dec 2025 00:06:34 +0000
════════════════════════
⌗ Tags: #Cyber Security #2FA bypass #APT28 #BlueDelta #Credential Theft #cyber_espionage #Fancy Bear #GRU #Ngrok #phishing #UKR.NET #Ukraine
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 22 Dec 2025 00:06:34 +0000
════════════════════════
⌗ Tags: #Cyber Security #2FA bypass #APT28 #BlueDelta #Credential Theft #cyber_espionage #Fancy Bear #GRU #Ngrok #phishing #UKR.NET #Ukraine
Daily CyberSecurity
The GRU’s Silent Shift: How BlueDelta Hijacks Ukrainian Webmail Using ngrok and Mocky
BlueDelta (APT28) is targeting UKR.NET users with a sophisticated phishing campaign using ngrok and Mocky to bypass security and steal 2FA codes.
⤷ Title: Fancy Bear Returns: APT28 Exploits Office Flaw in “Operation Neusploit”
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 03 Feb 2026 02:18:33 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #APT28 #CVE_2026_21509 #cyber_espionage #Fancy Bear #MiniDoor #Operation Neusploit #PixyNetLoader #RTF Exploit #russia #Zscaler ThreatLabz
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 03 Feb 2026 02:18:33 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #APT28 #CVE_2026_21509 #cyber_espionage #Fancy Bear #MiniDoor #Operation Neusploit #PixyNetLoader #RTF Exploit #russia #Zscaler ThreatLabz
Daily CyberSecurity
Fancy Bear Returns: APT28 Exploits Office Flaw in "Operation Neusploit"
APT28 launches "Operation Neusploit" targeting Europe. Hackers exploit CVE-2026-21509 to deploy MiniDoor malware via RTF files. Patch Office now.
⤷ Title: Op Neusploit: Russian APT28 Uses Microsoft Office Flaw in Malware Attacks
════════════════════════
𐀪 Author: Deeba Ahmed
════════════════════════
ⴵ Time: Tue, 03 Feb 2026 18:01:08 +0000
════════════════════════
⌗ Tags: #Cyber Attacks #Microsoft #Security #APT28 #Cyber Attack #Cybersecurity #europe #Malware #Neusploit #Romania #Russia #Ukraine #Vulnerability #Windows
════════════════════════
𐀪 Author: Deeba Ahmed
════════════════════════
ⴵ Time: Tue, 03 Feb 2026 18:01:08 +0000
════════════════════════
⌗ Tags: #Cyber Attacks #Microsoft #Security #APT28 #Cyber Attack #Cybersecurity #europe #Malware #Neusploit #Romania #Russia #Ukraine #Vulnerability #Windows
Hackread
Op Neusploit: Russian APT28 Uses Microsoft Office Flaw in Malware Attacks
A new campaign by the Russian-linked group APT28, called Op Neusploit, exploits a Microsoft Office flaw to steal emails for remote control of devices in Ukraine, Slovakia, and Romania.
⤷ Title: Three-Day Turnaround: How APT28 Rapidly Weaponized the Latest Microsoft Office Zero-Day
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 05 Feb 2026 04:04:24 +0000
════════════════════════
⌗ Tags: #Cyber Security #Vulnerability #APT28 #CERT_UA #Covenant Grunt #CVE_2026_21509 #Microsoft Office #MiniDoor #Operation Neusploit #PixyNetLoader #RTF exploit #Steganography #Ukraine #Zscaler
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 05 Feb 2026 04:04:24 +0000
════════════════════════
⌗ Tags: #Cyber Security #Vulnerability #APT28 #CERT_UA #Covenant Grunt #CVE_2026_21509 #Microsoft Office #MiniDoor #Operation Neusploit #PixyNetLoader #RTF exploit #Steganography #Ukraine #Zscaler
Penetration Testing Tools
Three-Day Turnaround: How APT28 Rapidly Weaponized the Latest Microsoft Office Zero-Day
The sophisticated threat actor APT28 has commenced the exploitation of a nascent Microsoft Office vulnerability almost immediately following
⤷ Title: APT28 Weaponizes Office Flaw to Spy on NATO & Military
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 09 Feb 2026 00:06:35 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #APT28 #BeardShell #CVE_2026_21509 #Fancy Bear #Filen.io #Military Espionage #NATO Targets #NotDoor #Trellix #WebDAV Exploit
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 09 Feb 2026 00:06:35 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #APT28 #BeardShell #CVE_2026_21509 #Fancy Bear #Filen.io #Military Espionage #NATO Targets #NotDoor #Trellix #WebDAV Exploit
Daily CyberSecurity
APT28 Weaponizes Office Flaw to Spy on NATO & Military
APT28 (Fancy Bear) weaponized CVE-2026-21509 in 24 hours to target NATO. New "BeardShell" and "NotDoor" malware steals emails. Patch Office now.
⤷ Title: Hiding in Plain Sight: APT28’s “Operation MacroMaze” Hits European Govs
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 17 Feb 2026 00:32:54 +0000
════════════════════════
⌗ Tags: #Cyber Security #APT28 #cyber_espionage #Fancy Bear #Forest Blizzard #Lab52 #living_off_the_land #Macro Malware #Operation MacroMaze #Spanish Government #Webhook.site
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 17 Feb 2026 00:32:54 +0000
════════════════════════
⌗ Tags: #Cyber Security #APT28 #cyber_espionage #Fancy Bear #Forest Blizzard #Lab52 #living_off_the_land #Macro Malware #Operation MacroMaze #Spanish Government #Webhook.site
Daily CyberSecurity
Hiding in Plain Sight: APT28's "Operation MacroMaze" Hits European Govs
APT28's "Operation MacroMaze" targets Europe using Spanish gov decoys. The campaign uses "low-tech" macros & Webhook.site to evade detection.