ZeroHour

Search: “Tailored Access Operations”

2 stories in the last 24h

Iranian Hackers Use Fake MRI Results to Infect Victims With CHOSEN BRICK Spyware

Iranian state-linked hackers deliver CHOSEN BRICK Windows spyware via fake MRI results to surveil dissidents, activists, and journalists in the UK, US, and Netherlands.

A joint advisory from the UK NCSC, FBI, and the Netherlands' AIVD links Iranian state-linked actors to CHOSEN BRICK, a Windows spyware family used for long-term surveillance since at least 2025. Targets are approached on WhatsApp or Telegram with tailored lures such as fake MRI scan results or application files, and operators often redirect victims to personal devices to bypass corporate controls. The malware persists via Run registry keys, adds antivirus exclusions, uses a per-victim Telegram bot for command and control, and exfiltrates data through cloud storage and proxy services. Capabilities include screenshots, audio recording, email and messaging theft, command execution, file deletion, data wiping, and some victims' details have appeared on pro-Iranian leak sites for harassment.

Cyber Security Newsupdated · 2h agofirst · 13h agoThreat actor in the wild 6 sources

Mapping out your unknown: A threat hunter’s guide to GitHub

Datadog Security Labs publishes a threat-hunting guide with audit-log queries to detect GitHub token theft, device code phishing, and source code exfiltration.

Datadog's threat-hunting guide covers GitHub audit log queries for detecting compromised accounts, stolen personal access tokens, and malicious OAuth app authorizations. Attackers typically obtain credentials through phishing, credential stuffing, leaked secrets, or device code phishing, then map private repositories, exfiltrate source code, and pivot into connected cloud and CI/CD environments. The guide maps detections to MITRE techniques like T1078 and T1528 and documents GitHub logging quirks affecting attribution, token metadata, and visibility fields.

Datadog Security Labs · 22h agoResearch in the wild1