MalWhere?
banner
malwhere.bsky.social
MalWhere?
@malwhere.bsky.social
👨‍💻APT Insights
🕵️‍♂️Tracking Cyber-Espionage Threats
💻Uncovering the Dark Side of the Digital World
👇Latest Threat Analysis & Updates

https://malwhere.substack.com/
🚨 ShinyHunters claims it breached the FBI, stealing data on current and former agents and job applicants. The group said it targeted the agency in retaliation for a May 2026 warning about its extortion tactics. #ShinyHunters #Cybersecurity
September 25, 2026 at 9:38 AM
🚨Researchers found 13 npm packages delivering a previously undocumented JavaScript stealer dubbed WeaselBiscuit. It shares functionality with DPRK-linked BeaverTail and OtterCookie, but is smaller and stripped of many of their capabilities. #WeaselBiscuit #Cybersecurity
September 22, 2026 at 9:38 AM
🚨UPDATE: Internal records reviewed by WSJ reportedly show Chinese cybersecurity firm ZRON pursuing a model combining hacking, data brokerage and AI. Its platform was designed to aggregate private/public data, analyze it and produce intelligence for government customers. #Cybersecurity #China #ZRON
September 16, 2026 at 9:19 AM
🚨China-linked UNC3569 exploited a Sogou Input Method flaw to deploy GRAYRABBIT. Gen says a crafted link could reach Sogou's outdated Chromium 80 browser, whose sandbox was disabled. Tencent patched the link handler in April 2026. #UNC3569 #GRAYRABBIT #Cybersecurity
September 11, 2026 at 9:18 AM
🚨 #Cybersecurity #WeChat: Researchers at Calif built a zero-click worm that can hijack a WeChat account through an incoming call. The victim need not answer or touch the phone. The caller must be an existing WeChat contact. Tencent has since blocked the exploit for all users globally now #APT #IoT
September 9, 2026 at 9:46 AM
🚨 #Cybersecurity #China #PlugX : U.S. authorities disrupted QTFY, a China-linked espionage operation active since 2018. The group targeted Energy, Justice, HHS, NASA and the Federal Reserve, plus defense, telecoms, utilities and hospitals. The operation also connects to wider China-linked activity.
August 27, 2026 at 11:39 AM
🚨#ToxicPanda 2.0 has expanded 349 targeted apps and 167 remote commands. Zimperium says it abuses VPN permissions to block Google Play and Play Services, disrupting Play Protect, updates and app verification before deploying its payload. Distribution uses AWS-hosted buckets #Cybersecurity #Android
August 26, 2026 at 9:02 AM
🚨 #Cybersecurity #SilkParasite: Bitdefender Labs uncovered a China-nexus cyberespionage operation targeting Central Asian governments. Seven RAT families were found, including five previously undocumented. The toolset is lean, modular and professionally engineered for stealth while reducing exposure
August 20, 2026 at 9:55 AM
🚨 Funky Mantis (DevMan) has evolved from a file-encryption toolkit into a full ransomware-as-a-service (RaaS) platform. Affiliates can build ransomware, buy network access, negotiate with victims, and manage attacks through a central web panel. #CyberSecurity #ransomeware #FunkyMantis
July 23, 2026 at 7:48 AM
🚨 OpenAI has disclosed an unprecedented AI security incident after an experimental ChatGPT model escaped its testing sandbox and autonomously hacked AI platform during a cyber capability evaluation. The model reportedly sought benchmark answers by exploiting vulnerabilities. #CyberSecurity #AI
July 22, 2026 at 12:56 PM
Post 1/2
🚨 Healthcare software firm Craneware has disclosed a cyberattack that resulted in unauthorized access and data exfiltration. Investigators confirmed employee data and subset of customer and partner records were accessed. #CyberSecurity #DataBreach #CraneWare
July 20, 2026 at 8:43 AM
🚨 Researchers have documented what may be the first ransomware attack conducted entirely by an autonomous AI agent. #JadePuffer exploited a Langflow vulnerability, then autonomously performed reconnaissance, credential theft, privilege escalation and lateral movement. #CyberSecurity #AI #ThreatIntel
July 8, 2026 at 12:33 PM
🚨 Operation DragonReturn is a suspected China-linked phishing campaign targeting Indian taxpayers, accountants, and finance teams. Victims receive fake Income Tax Department emails designed to deliver malware disguised as official tax software. #CyberSecurity #ThreatIntel #Phishing #DragonReturn
July 6, 2026 at 12:55 PM
🚨 A threat actor is allegedly selling a 7GB intelligence package linked to Chinese firm ZRON, claiming it contains malware, surveillance tools, intelligence reports, and operational documentation spanning Asia, Europe, the Americas, and Eurasia. #CyberSecurity #ThreatIntel #ZRON #China #Leaks
July 1, 2026 at 11:05 AM
🚨 Leaked documents show Japan's Ground Self-Defense Force unknowingly used counterfeit USB drives infected with malware. The devices, reportedly linked to a Chinese cyber operation, were connected to 50+ military systems, including those handling classified data. #CyberSecurity #ThreatIntel #USB
June 30, 2026 at 11:02 AM
Post 1/3
🚨 New Windows Defender flaw CVE-2026-50656 ("RoguePlanet") has a public PoC exploit before a patch is available. The bug exploits a race condition in Defender and can lead to SYSTEM-level privilege escalation on Windows 10 & 11. #CyberSecurity #Windows #ThreatIntel #RougePlanet
June 18, 2026 at 10:22 AM
Post 1/3
Chinese-linked APT Earth Lusca (Aquatic Panda)has expanded its SprySOCKS malware from Linux to Windows, targeting government organizations in Taiwan, Thailand, Pakistan, and Honduras. The move significantly broadens its cyber-espionage reach. #CyberSecurity #APT #ThreatIntel #aquaticpanda
June 16, 2026 at 11:31 AM
🚨 A new npm supply-chain attack has infected 36 packages with IronWorm, a Rust-based infostealer targeting developer environments. The malware hunts for AWS, OpenAI, Anthropic, npm credentials, SSH keys, crypto wallets, and other sensitive secrets. #CyberSecurity #SupplyChainAttack #npm
June 5, 2026 at 9:23 AM
🚨FrostyNeighbor, a Belarus-aligned APT, is escalating cyber-espionage ops across Eastern Europe—targeting Ukraine’s government, military, and critical sectors with spearphishing, exploits, and evolving malware chains. #CyberSecurity #APT #ThreatIntel #FrostyNeighbour #Belarus
May 20, 2026 at 8:44 AM
🚨As energy markets shift, cyber espionage is following. A China-linked APT, FamousSparrow, has targeted an oil & gas firm in Azerbaijan—marking a rare move into a region traditionally dominated by Russian cyber activity. #CyberSecurity #APT #ThreatIntel #FamousSparrow #China
May 19, 2026 at 8:36 AM
🚨Iran-linked MuddyWater hackers masked a cyber-espionage campaign as a Chaos ransomware attack. Using Microsoft Teams social engineering, they gained access, stole credentials, and established persistence—blurring the line between APT and cybercrime. #CyberSecurity #MuddyWater #ThreatIntel #Iran
May 6, 2026 at 1:57 PM
🚨APT37 (aka ScarCruft/Ricochet Chollima) is pushing a new campaign—this time weaponizing a video game platform. Their known “BirdCall” backdoor now has an Android variant, turning trojanized apps into full-fledged spyware. #CyberSecurity #APT37 #Malware
May 5, 2026 at 9:46 AM
🚨Threat group UNC6692 uses email bombing + fake IT helpdesk calls via Microsoft Teams to deploy “Snow” malware. Victims install a fake patch that drops a malicious extension for data theft after credential compromise. #CyberSecurity #Infosec #Malware #Snow #Microsoft
April 27, 2026 at 9:37 AM