ZeroHour

Search: “mfa”

3 stories in the last 3d

SilkParasite-Linked Malware Infrastructure Traced Back Four Years Across Central Asianew

Hunt.io links SpiceRAT C2 servers to China-nexus SilkParasite espionage targeting Central Asian governments, with related infrastructure active since 2022.

Hunt.io and researcher Guy Yasur traced a cluster of SpiceRAT command-and-control servers active from late 2025 to August 2026 to infrastructure linked to the China-nexus SilkParasite espionage operation. Shared parent domains, a certificate resembling an Uzbek railway entity, and a cloned RTX Corporation homepage appearing on 13 servers connect SpiceRAT systems to NodeEdgeRAT and NomadRAT infrastructure. Passive DNS records show related subdomains as early as mid-2022, suggesting the infrastructure has existed for at least four years. Hostnames impersonate government, energy and telecom targets across Turkmenistan, Tajikistan, Uzbekistan, Kyrgyzstan and Kazakhstan.

Cyber Security News · 42m agoThreat actor in the wild

NCSC and Allies Warn of Iranian Spyware Campaign

NCSC, FBI and AIVD warn Iranian-backed actors deliver Chosen Brick spyware to regime critics via social engineering; stolen data has surfaced on pro-Iranian leak sites.

NCSC, the FBI and the Netherlands' AIVD published a joint advisory warning that a Tehran-backed campaign, active since at least 2025, targets dissidents, activists and journalists with Chosen Brick spyware. The malware persists via Windows registry keys, adds Microsoft Defender exclusions, uses Telegram for C2, and captures screens, audio, emails and Telegram or WhatsApp messages. Stolen data has surfaced on pro-Iranian leak sites in some cases, raising risks to victims' personal safety.

Infosecurity Magazineupdated · 5h agofirst · 1d agoThreat actor in the wild 7 sources

Iranian cyber targeting of dissidents, activists and journalists

UK NCSC, FBI, and Dutch AIVD expose CHOSEN BRICK spyware used by Iranian state actors against dissidents, activists, and journalists worldwide.

A joint advisory from the UK NCSC, FBI, and Dutch AIVD details CHOSEN BRICK, a Windows spyware family used by Iranian state cyber actors since at least 2025 against dissidents, activists, and journalists in the UK, US, and Netherlands. Actors build rapport on WhatsApp and Telegram impersonating known contacts or platform support, then deliver disguised payloads resembling apps such as Telegram, Norton, RunwayML, or fake MRI results. The malware persists via HKCU Run registry keys, adds Microsoft Defender exclusions, and uses a unique Telegram bot C2 per victim. Capabilities include screen capture, microphone recording, process enumeration, email and messaging data theft, file deletion, and system wiping; victim data has appeared on pro-Iranian leak sites.

NCSC UK · 2d agoThreat actor in the wild2