
Weekly Intelligence Snapshot – Week 48
China-nexus group uses new Malware families to infect USBs for Espionage.
Explore our comprehensive archive organized by taxonomy. Discover a wealth of information categorized by subject, theme, or type to enhance your research and understanding.

China-nexus group uses new Malware families to infect USBs for Espionage.

Our tracking of the Mustang Panda group reveals a different DLL sideloading technique from those seen this year.

Pro-Russia hacktivist group From Russia With Love has been deploying Somnia Ransomware in Ukraine since spring 2022. But the #Malware

In our latest Weekly #Intelligence Summary: ASEC Analysis Team has seen LockBit 3.0 Ransomware deployed through Amadey Bot, an Infostealer

Microsoft reports the RaspberryRobin worm is now part of a malware ecosystem and one of the largest active malware distribution

The US publishes its new #NationalSecurity Strategy focussed on China and Russia and emphasizing the key role of the Indo-Pacific

This week the Microsoft Threat Intelligence Center reports on ransomware, “Prestige”, which targets transportation and logistics sectors in Poland and

A CISA advisory reveals vulnerabilities exploited by China-sponsored groups. PatchTuesday: Microsoft fixes 84 #vulnerabilities (inc two 0-day).

This week, we analyze new espionage-driven campaigns related to the Lazarus/ZINC activity cluster.

We are closely following increased geopolitical tensions after the potential sabotage attacks to Nordstream pipelines in the Baltic sea.
Try searching our blog

US-Israel War With Iran Escalates With Increasing Attacks Against Vessels and Energy Infrastructure In the Gulf | Iranian MOIS Cyber Units Integrate Cybercrime Malware and Infrastructure into State Operations

US and Israeli Attacks Against Iran Trigger Regional Escalation, Disrupting Strategic Sectors | Iran-Linked Cyber Operations During the Current Escalation: Hacktivism, State Activity, and Broader Threat Dynamics

Russian-Speaking eCrime Threat Actor Leverages Commercial AI Services to Compromise Over 600 FortiGate Devices | US Supreme Court Strikes Down Trump’s Global Tariffs

UNC6201 Exploiting Zero-day in Dell RecoverPoint to Achieve Persistent Access | Wave of Sabotage Acts Target Italian Railway Network Amid Winter Olympics