Proofpoint describes TA4922 as a fast-evolving Chinese-speaking threat group expanding from East Asia to Europe, using Atlas RAT, RomulusLoader, SilentRunLoader, and Winos4.0 to conduct targeted credential phishing, data theft, and malware delivery. https://t.co/Zj3YfK2iXM
TA416 (#MustangPanda) continues to target Mongolia 🇲🇳 with cyber espionage activity.
They are deploying #PlugX via a multi-stage SVG smuggling technique. The initial SVG contains heavily obfuscated layers that eventually trigger "ZIP smuggling" to drop the malicious archive.
The SVG payload was completely FUD (0/61 on VirusTotal).
IOCs:
🔹 SVG MD5: df78df95a79f3f764a6da9638624e4a0
🔹 ZIP MD5: 20063941491e5727cb2cbf824c656294 (previously noted by @smica83)
#ThreatIntel #MalwareAnalysis #APT
#ESETresearch released its latest APT Activity Report (Oct 2025–Mar 2026): 🇨🇳China-aligned groups focused on Venezuela, Gulf states, and AI & robotics industry in 🇰🇷South Korea, while 🇰🇵North Korea-aligned APTs targeted the nuclear sector. Full report: https://t.co/5Dzgqwuz9q
ESET
Webworm: New burrowing techniques
ESET researchers analyzed the 2025 activity of Webworm, a China-aligned APT group.
The group uses GitHub to stage its malware.
https://t.co/wPDbpWowcL
We announced a lot of Gemini updates at #GoogleIO, including:
- A complete redesign of the Gemini experience with Neural Expressive
- Agentic experiences coming to Gemini with Daily Brief & Gemini Spark
- Gemini Omni & 3.5 Flash models
- and more!
Catch up on everything here 🧵