Live

Intelligence Feed

Latest threat intelligence articles from trusted security sources, auto-processed to extract entities, IoCs, and TTPs.

Filtered by source: Kaspersky-labs Clear filter
Cyberespionage campaign PassiveNeuron targets machines running Windows Server | Securelist

3w ago · Kaspersky-labs

The PassiveNeuron campaign is a sophisticated cyberespionage operation targeting government, financial, and industrial organizations in Asia, Africa, and Latin America. It primarily compromises Windows Server machines, often through SQL server exploitation, and deploys custom APT implants such as Neursite and NeuralExecutor. The attackers use a multi-stage DLL loader chain with anti-sandbox techniques and have shifted to using GitHub-based dead drop resolvers for C2 configuration in newer variants. Attribution remains challenging, but TTPs suggest a Chinese-speaking threat actor with low confidence.

9 IoCs 3 Actors 1 Malware
How we linked ForumTroll APT to Dante spyware by Memento Labs | Securelist

3w ago · Kaspersky-labs

In March 2025, Kaspersky identified a sophisticated cyber espionage campaign dubbed Operation ForumTroll, targeting Russian and Belarusian organizations via spear phishing emails with personalized links. The attack exploited a zero-day vulnerability in Google Chrome (CVE-2025-2783) to escape the browser sandbox, leveraging a logical flaw in Windows IPC handling of pseudo-handles. The threat actor used LeetAgent, a custom spyware, and was linked to the commercial Dante spyware developed by Memento Labs (formerly Hacking Team), indicating a well-resourced and persistent threat actor conducting long-term surveillance operations.

15 IoCs 1 Actors 1 Malware