So bildet Moskau seine Nachwuchsspione aus:
Russland überzieht Deutschland und den Westen mit Cyberattacken und Lügenkampagnen. Geleakte Dokumente, die @derspiegel vorliegen, zeigen nun, wie Moskau die Angreifer schult – in einem geheimen Uniprogramm. https://t.co/SGzFRUwQDr
‼️Nowe śledztwo: zdobyliśmy ponad 2000 str. dokumentów, które pokazują, jak ukryty w prestiżowej uczelni tajny wydział szkoli dla GRU hakerów, sabotażystów i oficerów wywiadu.
https://t.co/zy98r8GY7P @VSquare_Project@InsiderEng@derspiegel@lemondefr@DelfiEE@guardian
New: @InsiderEng and its consortium partners obtained 2,000 documents from Bauman University in Moscow. There’s a secret Department 4 embedded within the school that acts as a Hogwart’s for the GRU— feeding fresh talent to Unit 29155, Fancy Bear and Sandworm. The curriculum is written and taught by spies. https://t.co/VrYpMGTtxr
Seqrite’s analysis shows Operation GriefLure used real decoys from a grieving victim to spear-phish Vietnam’s Viettel and Philippines’ St. Luke’s, delivering a rapid, multi-stage, fileless payload via LNK/BATCH, with China-nexus attribution. https://t.co/KuCgnD4UL1
🔎🇷🇺Inside Russia's elite Bauman University, a secret department trains the GRU's next-gen hackers, saboteurs & spies. Now, 2,000+ leaked docs expose how its graduates feed the units behind Russia's cyberattacks, election interference, and NATO sabotage. https://t.co/5TTRIaWZj7
🚩Silver Fox Targets Russia and India With ABCDoor Malware
https://t.co/dW90MxlKme
Silver Fox is back with a tax-themed phishing campaign, targeting organizations in India and Russia with ABCDoor, a new Python-based backdoor.
The campaign used fake tax audit notices, malicious archives, a modified RustSL loader, ValleyRAT, geofencing, VM checks, and persistence tricks to stay on infected systems.
More than 1,600 phishing emails were flagged between early January and early February, with activity seen across industrial, consulting, retail, and transportation sectors.
#ThreatIntelligence #SilverFox #Malware #Phishing #CyberSecurity
🇨🇳 China PLA “Rocket Force & Intelligence Data” Allegedly for Sale
A dark web post claims that data linked to multiple Chinese PLA (People’s Liberation Army) units is being offered for sale.
📊 Claim Includes:
• PLA Cyberspace Force Technology Research Institute
• Rocket Force science & intelligence units
• Strategic Support Force research entities
• Naval & aerospace military research institutes
🧠 Details:
• Seller claims access to “fresh” PLA-related data
• Mentions willingness to provide samples to buyers
• Targets organizations such as think tanks
• Payment requested via XMR (Monero)
⚠️ Assessment:
• No technical evidence provided:
No dataset preview
No schema or file structure
Broad and high-profile claims without proof
📊 Status: Unverified
⸻
#CyberSecurity #ThreatIntel #China #PLA #DarkWeb #DDW
Silver Fox (also known as CL-STA-0048), a threat group based in China, targeted Japanese based companies with a phishing campaign. With the invoice coming from:
• `rakuten[.]co[.]jp` (brand abuse, not IOC)
• hxxp://missallanahstarr[.]com/ (UNSAFE LINK: used for initial access)
• 137[.]220[.]153[.]175:886 (C2 server)
Being tied to multiple other attacks using ValleyRAT, with it's predecessor known as Ghost-rat, initial attribution was tied to Silver Fox through their common TTP's. With `163[.]com` registrant email being a strong indicator of Chinese-origin actor. A contradictory "Kyoto, Saitama" address fabricated to appear Japanese. Along with both the C2 and delivery infrastructure hosted in Hong Kong, consistent with Silver Fox's known infrastructure preference, and a fabricated Japanese WHOIS with contradictory prefectures:
missallanahstarr[.]com
├── Resolves → 103[.]115[.]56[.]66 (AS55933 Cloudie Limited, Hong Kong)
│ └── hostname: unknown.itsidc[.]com (ITSIDC infrastructure)
├── WHOIS email: lugai665@163[.]com (NetEase — Chinese email provider)
├── WHOIS address: "Kyoto, Saitama, JP" (contradictory prefectures = fabricated)
├── Updated: 2026-04-15 (day before campaign)
└── NS: share-dns[.]com / share-dns[.]net
Along with the presence of unmodified Chinese-language default strings confirming this is a Chinese-market RAT builder. However, Silver Fox has documented overlaps with Winnti/Wicked Panda (APT41) tooling, but this campaign's tradecraft is more consistent with Silver Fox's commercial fraud operations than Wicked Panda espionage focus.
What distinguishes this malware is its geographic kill switch mechanism that queries the Windows Registry for specific applications before execution:
•HKCU\Software\Console\
•HKCU\SOFTWARE\IpDates_info
The attack exploits a documented vulnerability in Dell/Waves Audio's MaxxAudio software, using `MaxxAudioConrol64.exe` as its entry. With the next startup `MaxxAudioAPOShell64.dll` loads an improper registry key allowing the attacker to insert their own DLL to take over the system. With Windows DLL search order loading the malicious DLL first.
To keep itself hidden it uses a custom protocol over TCP to beacon itself to the C2 server (137[.]220[.]153[.]175:886). Along with sleep obfuscation (memory protection cycling), VM/sandbox detection, and AV process termination.
This is part of a continued campaign in Asia, with Silver Fox and other Chinese based actors escalating attacks on emails, Telegram, SEO-poisoned websites, etc.
#Malware #CyberSecurity #CybersecurityNews #ThreatIntel
https://t.co/Prn8ZqArHF