Dark Web Profile: APT28

APT28 is a long-running, GRU-linked espionage group that prioritizes stealthy credential access, targeted phishing, and long-term intelligence collection across Europe, North America, and Ukraine. Recent reporting through 2025 highlights new tooling like the LAMEHUG AI-assisted malware and sustained credential/token harvesting campaigns against services such as UKR[.]net. #APT28 #LAMEHUG

Read More
Do You Really Know Your AI Landscape?

Enterprise AI adoption is accelerating, expanding security boundaries across Cloud, SaaS, and Endpoint environments and exposing a complex, AI-driven attack surface. Traditional security tools struggle to protect AI assets, making advanced AI security posture management essential for full visibility, risk assessment, data lineage, and zero-trust enforcement across the AI ecosystem. #HuggingFace #ModelContextProtocol

Read More
Orca State of Cloud Security 2025

The 2025 State of Cloud Security Report highlights escalating challenges in cloud security, including rising data exposure, vulnerabilities, and attack paths exacerbated by AI adoption. It underscores the importance of managing neglected assets, securing Kubernetes environments, and controlling identity and access to mitigate evolving threats. #OrcaResearchPod #APT29 #Log4Shell #Spring4Shell #KubernetesSecurity #AIvulnerabilities

Read More
North Korea-Linked Hackers Target Developers via Malicious VS Code Projects

North Korean threat actors have advanced their hacking tactics by exploiting malicious Visual Studio Code projects to deliver backdoors and malicious payloads. This campaign uses sophisticated multi-stage techniques, including obfuscated JavaScript and task configuration files, to compromise target systems and maintain persistence. #NorthKorea #VisualStudioCode #Backdoor #Vercel #DPRK…

Read More
APT-Grade PDFSider Malware Used by Ransomware Groups

A new malware family called PDFSider is being used in targeted attacks, including by multiple ransomware groups, to deploy advanced backdoors and evade detection. The malware leverages legitimate applications and sophisticated techniques like DLL sideloading and environmental checks to carry out cyberespionage and remote code execution. #PDFSider #MustangPanda #DLLSideloading #Cyberespionage…

Read More
Qilin Ransomware Attack Hits Altius Geotecnia and Yumark Enterprises

The Qilin ransomware group has announced breaches affecting several organizations, including a Spanish engineering firm and a Taiwanese fashion supplier, by exfiltrating sensitive internal data. The stolen data comprises personal identification details, legal documents, and business records, highlighting their aggressive data theft tactics. #QilinRansomware #DataExfiltration #AltiusGeotecnia #YumarkEnterprises…

Read More
Tudou Guarantee Marketplace Halts Telegram Transactions After Processing Over  Billion

A Telegram-based illicit marketplace, Tudou Guarantee, is ceasing its major operations after processing over $12 billion in transactions, marking a significant shift in the cyber fraud landscape. Despite this, other marketplaces like HuiOne Guarantee and Xinbi Guarantee continue to operate, indicating a persistent threat environment. #TudouGuarantee #HuiOneGuarantee #XinbiGuarantee #PrinceGroup #PigButchering…

Read More
Dissecting CrashFix: KongTuke’s New Toy

KongTuke distributed a malicious Chrome extension (NexShield, typosquatting uBlock Origin Lite) that tracks installs via UUID beacons, delays execution, and triggers a browser denial-of-service while displaying a fake “CrashFix” popup to socially engineer victims. The campaign delivers a multi-stage infection chainβ€”using finger.exe as a LOLBin, multi-layer PowerShell obfuscation and DGA domains, and culminating in ModeloRAT and a GateKeeper .NET payload with AES+XOR string encryption. #KongTuke #ModeloRAT

Read More