Chinese state-backed group TA416 has reemerged with intensified cyber espionage campaigns targeting European governments, following a quiet period since 2023. Proofpoint reported that the group's renewed activity began…
A cyber espionage campaign utilizing the GoSerpent backdoor has infiltrated government networks in Southeast Asia for over five years, harvesting sensitive police and biometric data. The operation, revealed by…
The Chinese state-sponsored group Mustang Panda, also known as HoneyMyte, conducted a cyberespionage campaign targeting government officials and diplomats worldwide. This operation involved malicious emails disguised as…
The HoneyMyte APT group has developed a new cyberespionage campaign utilizing a malicious kernel-mode driver to deploy the ToneShell backdoor. This driver, signed with a stolen digital certificate, operates as a rootkit…
In mid-2025, the Chinese APT group Mustang Panda launched cyber-espionage attacks using a signed kernel-mode rootkit to deploy the ToneShell backdoor. The attacks targeted government organizations in Southeast and East…
A Chinese-linked threat group, associated with HoneyMyte, is utilizing a new kernel rootkit to obscure its ToneShell backdoor. This cyber campaign has primarily targeted government networks in Southeast and East Asia,…
HoneyMyte, also known as Mustang Panda or Bronze President, has been active in espionage campaigns targeting government entities in Asia and Europe, particularly Southeast Asia. The group has deployed multiple…
The HoneyMyte APT group, also known as Mustang Panda or Bronze President, has enhanced its CoolClient malware to include capabilities for stealing browser login information. This upgrade poses a significant risk to…