Operation DRAGONCLONE: China Mobile Tietong Hit by Advanced APT Attack

Seqrite Labs uncovered Operation DRAGONCLONE, a sophisticated Chinese cyber campaign targeting China Mobile Tietong using DLL sideloading, anti-sandbox techniques, and advanced malware like VELETRIX and VShell. The operation demonstrates extensive reuse of infrastructure and tools, highlighting persistent threats from China-aligned groups. #VELETRIX #EarthLamia…

Read More
Stay Ahead of Cyber Threats Sweeping Container Telemetry data

Trend Vision One™ – Threat Intelligence enhances proactive security by providing retrospective scanning and container-aware visibility to detect past and ongoing threats in diverse environments. It integrates real-time data, MITRE ATT&CK mapping, and automated investigations to enable faster, intelligence-driven incident response. #TrendVisionOne #ThreatInsights #ContainerSecurity…

Read More
Threat Analysis of the 3-Stage Combo of Kim Sooki Group

The North Korean hacking group Kimsuky has employed a sophisticated infiltration strategy targeting South Korean users via Facebook, email, and Telegram, disguising malicious files as volunteer activities for defectors. This campaign utilizes Korean-specific compressed files and encoded scripts to evade detection, with significant compromises linked to the AppleSeed malware variant. #Kimsuky #AppleSeed

Read More
Operation DRAGONCLONE: Chinese Telecommunication industry targeted via VELETRIX & VShell malware

A sophisticated cyber campaign named Operation DRAGONCLONE targeted China Mobile Tietong using VELETRIX and VShell malware, employing DLL sideloading, anti-sandbox, and IPfuscation techniques. The activity is linked to China-aligned threat groups UNC5174 and Earth Lamia, with overlaps to multiple post-exploitation tools and infrastructure. #OperationDRAGONCLONE #VELETRIX #VShell #ChinaMobileTietong #UNC5174 #EarthLamia

Read More
AMOS Variant Distributed Via Clickfix In Spectrum-Themed Dynamic Delivery Campaign By Russian Speaking Hackers

A new variant of the Atomic macOS Stealer (AMOS) campaign uses typo-squatted domains mimicking Spectrum to deliver malicious payloads targeting macOS users by harvesting system passwords. The campaign is linked to Russian-speaking cybercriminals and employs multi-platform social engineering tactics with poorly implemented logic in its delivery infrastructure. #AtomicMacOSStealer #SpectrumTyposquatting #RussianCybercriminals

Read More
Cyber Attacks on Government Agencies: Detect and Investigate with ANY.RUN for Fast Response

Government institutions worldwide are increasingly targeted by sophisticated cyberattacks, leveraging phishing emails, fraudulent domains, and malicious PDFs. ANY.RUN’s solutions provide critical tools for detecting, analyzing, and mitigating these threats, enhancing organizational cybersecurity resilience. #FormBook #ScreenConnect #SocialSecurityAdministration…

Read More
Guardz Banks M Series B for All-in-One SMB Security

ThreatSpike, a London-based end-to-end cybersecurity provider, has secured $14 million in Series A funding to expand its unified platform that offers real-time detection, response, and penetration testing. The company’s all-in-one solution aims to simplify cybersecurity for mid-sized businesses by combining automation, threat hunting, and vulnerability testing. #ThreatSpike #SeriesAFunding…

Read More
In-depth Analysis of a 2025 ViperSoftX Variant

The 2025 variant of the ViperSoftX PowerShell stealer showcases enhanced modularity, stealth, and persistence compared to its 2024 predecessor, with upgraded encryption and victim identification techniques. It targets cryptocurrency wallets and browser extensions while employing dynamic infrastructure synchronization and multilayer persistence mechanisms. #ViperSoftX #PowerShellMalware #CryptocurrencyStealer

Read More
Octalyn Stealer: Steals Passwords, Crypto & Browser Data

Octalyn Stealer is a Pascal/Delphi-based information-stealing malware that targets Windows systems from XP to Windows 11, using Telegram’s bot API for stealthy data exfiltration. Its user-friendly control panel and availability on GitHub lower the technical barriers for cybercriminals, enabling widespread dissemination through multiple infection vectors. #OctalynStealer #TelegramBotAPI

Read More
Beyond GenAI: Why Agentic AI Was the Real Conversation at RSA 2025

This article explores the evolving landscape of artificial intelligence, focusing on the distinctions between GenAI, SynthAI, and agentic AI, especially in the context of cybersecurity. It highlights the rising prominence of agentic AI at RSA Conference 2025 and discusses its potential applications and associated challenges. #RSAConference2025 #AgenticAI #SynthAI #GenAI #CybersecurityThreats…

Read More