< ciso
brief />
Tag Banner

All news with #nation state actor tag

206 articles

DoJ Revises Statement on China-Linked Hacking Targets

🛡️ The U.S. Department of Justice corrected a prior press release to state several federal agencies were "among the targets" of QTFY, a China-linked threat actor, rather than confirmed victims. The update clarifies the government affidavit and follows disruptions by the FBI of domains tied to QTFY's tools. The actor, tied to Nanjing Xinjiuwei and allegedly funded by the MSS, provided reconnaissance and proxy services to enable espionage.
read more →

FBI Disrupts China-Linked QTFY Botnet Operations

🔒 The U.S. Department of Justice and FBI announced the disruption of two hacking platforms, QScan and QTRouter, used by the China-linked group QTFY to target U.S. critical infrastructure and sensitive networks. Lumen Black Lotus Labs, which tracked the group since 2018, collaborated with the FBI after observing extensive targeting of research and public sector organizations. QScan infected IoT devices to build a proxy mesh while QTRouter and associated services obfuscated attack origins using compromised routers, commercial proxy services, and leased VPSs. The court-authorized seizure of hard-coded domains caused the platforms to cease operations.
read more →

US Treasury Targets Iran-Linked Cyber Actors

🛡️ The U.S. Department of the Treasury announced Operation Economic Outcast, imposing sanctions on nearly 60 Iran-linked entities, individuals, and vessels across nuclear, missile, oil, and cyber networks. The measures target an MOIS-affiliated cyber group accused of widespread compromises of U.S. critical infrastructure and financially motivated theft, and designate five individuals tied to the Tehran-based Mabna Institute. Treasury and partner agencies emphasized cutting Iran's financial lifelines, while the State Department’s Rewards for Justice offers up to $10 million for information on malicious cyber actors.
read more →

Massive DDoS Disrupts Norway’s Government Services

🔒 A large DDoS attack began at 03:38 CEST, disrupting the Norwegian Digitalization Agency (Digdir) and its provider Vivicta, affecting public-service logins, electronic IDs and signatures, secure digital mail, and inter-agency data exchange. Several services were briefly unavailable and some, including ID-porten and eSignering, remain partially inaccessible, causing login errors and slow responses. Digdir reports stabilization of many systems, no evidence of a security breach or personal data compromise, and has notified NSM and Datatilsynet. This is the third recent DDoS against Digdir; there is no official attribution but media have speculated about Russian involvement.
read more →

US Imposes Sanctions Targeting Mabna Cyber Unit

🔒 The US announced Operation Economic Outcast on August 24, targeting nearly 60 individuals and entities to disrupt financial flows sustaining Iran. Five people linked to the Mabna Institute were sanctioned, following a Department of Justice indictment of 17 alleged members for long-running cyber-espionage. OFAC also published 30 crypto addresses tied to four defendants, with blockchain analysis tracing roughly $16.8m of funds. The measures expand sectoral sanctions, increasing compliance burdens for crypto and financial firms.
read more →

Operation QUICSILVER: QUICAgent Targets Myanmar Networks

🛡️ Cybersecurity researchers have uncovered Operation QUICSILVER, a cyber espionage campaign targeting Myanmar's government and IT sectors that uses graduation ceremony invitation lures to deliver a Go-based backdoor named QUICAgent. First seen in April 2026, the multi-stage attack abuses a Windows Shortcut (LNK) and the legitimate ftp.exe binary as a LOLBAS to reconstruct and deploy the payload from hidden files inside a VHD. QUICAgent employs sandbox evasion, fetches a C2 address via Cloudflare Workers, and communicates over QUIC on UDP/443, while maintaining persistence through a Startup LNK.
read more →

White House Memo Expands Private Cyber Operations Role

📝 This week's Threat Source newsletter by Mick Baccio examines a recent presidential memorandum directing DOJ and DHS to create a program that allows private companies to conduct government-authorized cyber surveillance and effects operations against transnational criminal organizations. The piece highlights operational questions about attribution, intelligence handling, and geopolitical risk, and notes Talos reporting on AI-driven Chinese cybercrime group UAT-10147 and critical active exploits.
read more →

ThreatsDay: Signed Drivers, AI Risks, and RCEs

🛡️ This week’s ThreatsDay highlights multiple vectors where trusted components and weak checks are repurposed for attack. Research shows Microsoft-signed drivers can be abused for kernel operations, and a critical Gogs RCE (CVSS 10.0) enables remote code execution via Git hooks. Other items include a large-scale Iran-linked academic espionage case, DLL sideloading campaigns, BYOVD abuse, guardrail-free AI services, and exposed refrigeration controllers.
read more →

Most organizations unprepared for agentic AI attacks

🔒 The NSA and Five Eyes agencies warn that AI lowers barriers for malicious actors while bolifying defenders, but current defenses remain asymmetric. Agentic tools can speed detection and response, yet many organizations deploy AI faster than they test it, leaving gaps in measurement and performance. Recent incidents like the OpenAI–Hugging Face breach show triage is insufficient and underscore the need for continuous validation and realistic simulations.
read more →

Apple Alerts Users of Mercenary Spyware in 110 Countries

🔔 Apple has sent fresh threat notifications to an unspecified number of customers it suspects were targeted by mercenary spyware in 110 countries, adding to over 150 countries notified since late 2021. The company characterizes these as high-confidence alerts for individuals likely singled out due to their roles, such as journalists, activists, politicians, and diplomats. Apple declined to attribute the attacks to specific actors and cautioned that sharing diagnostic details could help attackers refine tactics. It provides notifications via iPhone alerts, email from "threat-notifications@email.apple[.]com," and a banner on the user's Apple Account page, and recommends security steps including updating software, enabling 2FA, and using Lockdown Mode.
read more →

White House memo expands private cyber offensive role

📝A White House memorandum signed by President Donald Trump directs the National Coordination Center (NCC) to create a program enabling vetted U.S. private companies to conduct cyber surveillance and cyber effects operations against foreign Transnational Criminal Organizations (TCOs). The NCC must implement the program within 60 days and impose oversight, minimization, and reporting requirements to prevent operations from targeting U.S. persons or systems. The move broadens private sector involvement in offensive cyber actions, while raising legal and security concerns given existing prohibitions on private actors conducting cyber attacks without court authorization.
read more →

Multi‑agent AI attack breaches government networks

🔒 Researchers report a multi-day, near-autonomous cyberattack using open-source AI agents that targeted government systems in Asia, compromising credentials and probing sensitive agencies. The campaign, observed in early July, used parallel agents to map networks, exploit APIs, and move laterally via single sign‑on integrations, producing large volumes of exfiltrated files and cracked credentials. Vendors and experts warn the incident underscores a widening gap between the falling cost of capable attacks and the higher cost of defense.
read more →

DeadLock Ransomware Leverages Blockchain to Resist Takedown

🔒 Microsoft researchers detail a new DeadLock ransomware operation that uses blockchain-backed services and decentralized networks to harden its infrastructure. The group, active since mid-2025, employs double-extortion tactics and hosts leak posts and configuration data on the Polygon blockchain. Victims span multiple European industries, while attackers use Session and Wasabi to protect communications and stolen files, complicating takedown efforts.
read more →

North Korean hackers accused of robbing state banks

🔒 North Korea's state-trained hackers, long known for stealing from foreign banks and crypto exchanges, are reported to have targeted their own country's central financial institutions. Arrests on 12 July by the National Intelligence Agency allegedly disrupted a scheme to siphon funds from the Chosun Central Bank and the Foreign Trade Bank using encrypted communication and crypto laundering. The suspects are said to be discharged veterans trained by the same military unit behind Lazarus Group, and equipment and phones were seized during raids.
read more →

UK updates National Risk Register with cyber scenarios

🔒 The UK government has expanded its National Risk Register to include several new cyber-related scenarios affecting digital infrastructure, water systems, policing, and a potential large-scale IT outage. The July 14 update also adds a section on interference in democratic processes, covering attacks on election infrastructure and online information operations. Likelihoods are generally assessed as low but impacts range from moderate to catastrophic, prompting plans for a national resilience campaign to boost household preparedness.
read more →

Rival Chinese and Indian Cyber Espionage Hits Pakistan

🔒 SentinelLabs reports that suspected China- and India-linked cyber operators targeted multiple Pakistani law enforcement systems between February 2024 and April 2026, focusing on Balochistan Police. The compromise affected servers hosting biometric records, case files and tenant registrations, and included implants in a public Complaint Management System. Analysts linked PlugX, ShadowPad and Cobalt Strike to China-nexus activity and Remcos to a suspected India-nexus actor. The incidents underscore risks from centralized police IT systems and concentrated intelligence value.
read more →

EU and UK announce joint cyber sanctions on Russia

🛡️ The EU and the UK issued coordinated sanctions targeting Russian individuals, entities, and intelligence units accused of orchestrating cyberattacks across Europe. Designations include GRU and FSB-linked officers, cybercriminals, and private firms alleged to recruit hackers and run malware operations. Officials cite sustained campaigns against government and critical infrastructure since 2010 and recent disruptive attempts in Poland. The measures follow broader EU proposals to strengthen cybersecurity and precede additional sanctions on foreign companies tied to attacks.
read more →

Multiple nation-linked groups target Pakistani police

🛡️ Cybersecurity researchers disclosed sustained espionage targeting Pakistani law enforcement between February 2024 and April 2026, impacting Balochistan Police and other agencies. Compromised assets included network appliances, web servers for police applications, and a Fortinet FortiMail gateway, with a Complaint Management System used to host implants. Four threat clusters deployed PlugX, ShadowPad, Cobalt Strike, and Remcos RAT, linking the activity to China- and India-nexus actors. The dual targeting by adversaries and partners underscores the high intelligence value of law enforcement systems.
read more →

AI's accelerating role in cybersecurity risks

🛡️ Five Eyes agencies warned that AI's rapid development raises cyber risks, particularly autonomous hacking and automated attacks. Bruce Schneier explains that AI widens the gap between skill and ability, enabling less-skilled actors to cause greater harm while also offering defensive tools. He argues that guardrails on large platforms won't stop open-source models and urges using AI for defense across all heightened risks.
read more →

Evolution of the Pro‑Russia Influence Ecosystem

🛡️ Four years into Russia’s invasion of Ukraine, the pro‑Russia influence ecosystem has shifted from wartime tools back toward a global strategic asset. GTIG observes expansion of covert information operations, revived hacktivism, and increasing use of generative AI across planning and content creation. The ecosystem blends state, state‑aligned, and independent actors, targeting the West, Russia’s near abroad, the Middle East, Africa, and domestic audiences while exploiting media mimicry, cyber‑enabled IO, and direct dissemination.
read more →