ZeroHour

Search: “cyber-espionage”

30 stories

Armored Likho expands its cyber-espionage toolkit

Kaspersky reports the Armored Likho espionage group now delivers its new Still Toolkit via fundraising-themed lures to steal Telegram data and eavesdrop on victims.

Kaspersky researchers describe a new campaign by the Armored Likho espionage actor. The campaign masquerades as fundraising efforts and delivers a newly developed Still Toolkit designed to steal Telegram data and eavesdrop on victims. The update expands the group's toolkit and continues its espionage-focused targeting.

Kaspersky Securelist · Aug 13, 2026Threat actor in the wild

MILE TEA: Cyber Espionage Campaign Targets Asia Pacific Businesses and Government Agencies

Unit 42 names MILE TEA, a cyber-espionage campaign since 2011 targeting Japanese and Taiwanese businesses and government agencies with e-ticket phishing lures and Elirks-family malware.

Unit 42 tracks the MILE TEA espionage campaign, observed as early as 2011, targeting Japanese trading, petroleum, and mobile companies, a Beijing office of a Japanese public organization, and a Taiwanese government agency. The primary infection vector is spear-phishing emails with attachments, mostly custom executable installers posing as flight e-tickets, dropping Elirks, Micrass, or Logedrut as initial bridgehead malware. Elirks and Logedrut retrieve encrypted C2 addresses from attacker-posted blog articles, decoded with Base64 and TEA or DES ciphers. The campaign's focus shifted from Taiwan to Japan around 2013.

Palo Alto Unit 42 · Aug 17, 2026Threat actor in the wild1