← BACK TO FEED
TAG

espionage6 articles

The Guy Hired to Catch Spies Was Busy Being One

Nathan Vilas Laatsch, a 29-year-old IT specialist who worked in the DIA's Insider Threat Division, pleaded guilty after being caught in an FBI sting operation passing classified information to what he believed were foreign spies. Ironically, his role at the DIA involved identifying potential leakers and supporting internal investigations, knowledge he intended to exploit to avoid detection. He was arrested in May 2025 after making two dead-drops of top-secret documents in an Arlington, Virginia park, having transcribed the classified information by hand and hidden the notes in his socks.

31 Aug 2026

APT28 Is Back With a New Backdoor and the Same Old Tricks

Researchers at Recorded Future have attributed a series of cyberattacks targeting government and diplomatic organizations in Romania, Spain, and Türkiye (between late 2025 and early 2026) to Russian state-sponsored group APT28, based on strong code and technique overlaps with the group's previously known tooling. The campaigns deploy a newly identified backdoor called HOOKEDGE — a Windows batch script delivered via macro-enabled Word documents — which uses webhook.site services for command-and-control, payload retrieval, and data exfiltration to blend in with normal network traffic. HOOKEDGE has been continuously refined over the campaign period and is considered a direct successor to APT28's earlier HEADLACE backdoor, with high-value targets receiving a more aggressive second-stage implant offering operators greater interactive control.

31 Aug 2026

New Zealand Intelligence: China Used Astronomy Cover to Plant Spy Kit on Kiwi Soil

New Zealand's Security Intelligence Service (NZSIS) has alleged that Chinese organisations, including the Purple Mountain Observatory, attempted to install ground-based space infrastructure in New Zealand to collect military intelligence, with the agency successfully disrupting the activity. China is rated as the only country targeting New Zealand at scale, with additional concerns raised over Chinese military intelligence using fake job advertisements on professional networking sites to recruit and gather sensitive information. The report also highlights growing domestic threats from violent extremism, noting that the internet has vastly complicated the task of identifying genuine threats amid vast volumes of toxic online content.

17 Aug 2026

New Backdoors OctLurk and SilkLurk Linked to Chinese-Speaking Hackers Hitting Central Asian Governments

A suspected Chinese-speaking threat actor has been conducting cyberattacks against government and public sector organisations across Central Asia and Syria since January 2025, targeting sectors including healthcare, law enforcement, and foreign affairs ministries. The campaign deploys two newly identified backdoors — OctLurk and SilkLurk — alongside a network proxying tool called LurkProxy, enabling capabilities such as credential theft, keylogging, remote access, and data exfiltration. Both backdoors operate primarily in memory and use victim-specific encoding tied to machine details, making detection and reverse engineering significantly more difficult.

2 Aug 2026

GoSerpent Malware Has Been Quietly Raiding Southeast Asian Governments for Months

Cybersecurity researchers at Kaspersky have uncovered a previously undocumented malware called GoSerpent, which has been targeting government and diplomatic entities in Southeast Asia since late 2025 for espionage and long-term intelligence gathering. The malware connects to a command-and-control server to deploy secondary payloads capable of credential dumping, file collection, and data exfiltration, while also supporting SOCKS5 proxying to mask attackers' true IP addresses. The campaign shares similarities with the known threat actor TetrisPhantom, though definitive attribution remains uncertain, and a separate but related espionage operation by DoNot Team was also disclosed, targeting Bangladesh's military using spear-phishing emails.

19 Jul 2026

BusySnake: The Python Stealer Quietly Targeting Governments and Power Grids

A threat actor called Armored Likho has been conducting cyber espionage and financially motivated attacks against government agencies and energy sector organisations in Russia, Brazil, and Kazakhstan, using spear-phishing emails as the initial entry point. The group deploys a newly discovered Python-based malware called BusySnake Stealer, which harvests credentials, browser cookies, keystrokes, cryptocurrency wallets, and Telegram data, while evading detection through dynamic bytecode encryption and obfuscation techniques. Kaspersky has linked Armored Likho to the previously tracked Eagle Werewolf cluster, noting the group is actively refining its toolkit — including integrating reverse SSH tunnelling directly into the stealer — and may be using AI tools to assist in generating its first-stage payloads.

15 Jul 2026