threat-intel APT28-Linked HOOKEDGE Backdoor Targets European Government and Diplomatic Organizations APT28-linked threat actors, tracked as BlueDelta, have been deploying a new backdoor named HOOKEDGE to target European government and diplomatic organizations since late 2025. HOOKEDGE, a lightweight Windows batch script, is delivered via macro-enabled Word documents and utilizes webhook[.]site for command-and-control,… The Hacker News · 2d ago High ROSPTUapt28hookedgewebhook
threat-intel Russian Hackers Phish EU Officials Over Messaging Apps Russian state-sponsored hackers are increasingly using messaging apps like WhatsApp and Signal to spear-fish EU government officials, bypassing traditional email security measures. The attacks, targeting high-ranking ind… Dark Reading · 3d ago High RUCHIRphishingsocial engineeringmessaging
threat-intel Suspected Russian Hackers Abuse Google OAuth and WhatsApp Linking to Hijack Accounts Three distinct clusters of suspected Russian cyber espionage groups – UNC6293, UNC7005, and UNC5976 – are leveraging legitimate authentication flows to target individuals in academia, aerospace/defense, governments, and… The Hacker News · Aug 20, 2026 High UKARRUoauthapp passworddevice linking
threat-intel Russian hackers hijack hotel Wi-Fi networks to spy on travelers, Microsoft says Russian state-sponsored hackers, linked to the Midnight Blizzard group (part of APT29), are compromising hotel Wi-Fi networks worldwide to steal traveler login credentials and install espionage malware. The campaign uses… The Record · Aug 3, 2026 High RUUKSAhotel wifiespionagecaptive portal
threat-intel New GoSerpent Malware Targets Southeast Asian Governments and Diplomats for Espionage A previously undocumented Go-based malware, GoSerpent, has been actively targeting government and diplomatic entities in Southeast Asia since 2021, with a renewed surge in activity in 2026. Developed by the threat actor… The Hacker News · Jul 17, 2026 High BAAPmalwareespionagedata theft
threat-intel GoSerpent: a persistent threat evolves with sophisticated data collection and exfiltration A sophisticated, evolving threat actor, potentially linked to TetrisPhantom, has been targeting government and diplomatic entities in Southeast Asia since late 2025 with a campaign utilizing tools like GoSerpent, Stowawa… Securelist · Jul 16, 2026 High VNTHproxyremote accessdata exfiltration
threat-intel Google Details Turla's New STOCKSTAY Backdoor Used in Ukraine Espionage Attacks Google Threat Intelligence Group (GTIG) has identified a new backdoor, STOCKSTAY, developed and deployed by the Russian state-sponsored threat actor Turla. This multi-component backdoor, built using .NET and leveraging a… The Hacker News · Jun 26, 2026 High CVE-2025-8088UKITNEespionagebackdoorrussia