#APTGroups
China-linked APT group UAT-8302 has targeted South American governments since late 2024 and southeastern European agencies in 2025, deploying custom malware like NetDraft during post-exploitation phases. #Brazil #APTGroups #CyberEspionage
China-Linked UAT-8302 Targets Governments Using Shared APT Malware Across Regions
Cisco Talos attributes a China-nexus APT tracked as UAT-8302 to attacks on South American governments since late 2024 and southeastern European agencies in 2025, with post-exploitation marked by deployment of custom malware. The group uses tools such as the .NET backdoor NetDraft (NosyDoor), CloudSorcerer, VShell and SNOWRUST, and appears to share...
www.hendryadrian.com
May 5, 2026 at 11:15 PM
European Commission hit by cloud breach via compromised Trivy update and stolen AWS key; TeamPCP/ShinyHunters exfiltrate 92 GB from europa.eu clients. Fortinet EMS patch released, DPRK-linked Drift heist lasts 6 months. #Europe #DataBreach #APTGroups
Cybersecurity News | Daily Recap [06 Apr 2026]
Daily Recap, The daily briefing highlights a European Commission cloud breach caused by a compromised Trivy update and a stolen AWS key, with TeamPCP/ShinyHunters exfiltrating 91–92 GB of data from europa.eu clients. It also covers urgent Fortinet FortiClient EMS CVE-2026-35616 fixes, REvil affiliates UNKN and Daniil Shchukin linked to numerous attacks and €35.4 million in damages, a six-month DPRK-backed Drift heist, the Axios npm compromise attributed to UNC1069 (WAVESHAPER.V2), 36 malicious npm packages, React2Shell credential harvesting campaigns, device-code phishing via EvilTokens, QR phishing schemes, the Voxbeam robocall case, the NI Education Authority outage, LinkedIn BrowserGate, and ULP data-quality concerns for infostealer feeds. #Trivy #TeamPCP #ShinyHunters #EuropeanCommission #FortiClientEMS #CVE-2026-35616 #REvil #UNKN #DaniilShchukin #AnatolyKravchuk #Drift #UNC1069 #WAVESHAPER #Axios #React2Shell #EvilTokens #QRPhishing #Voxbeam #EducationAuthority #BrowserGate #ULPBurnout
www.hendryadrian.com
April 7, 2026 at 10:00 PM
Iran’s MOIS and IRGC rapidly expanded cyberattack infrastructure in the six months before the Feb 2026 US/Israeli strikes, mobilizing 60 hacktivist groups and APTs via complex multi-tier networks. #Iran #APTgroups #Cyberwar
Iran Readied Cyberattack Capabilities for Response Prior to Epic Fury
Augur Security’s analysis shows a significant buildup of Iran-linked MOIS and IRGC cyber infrastructure in the six months before the February 28, 2026 US/Israeli strikes, enabling rapid post-strike operations against the US, Israel, and Gulf states. A coordinated surge of roughly 60 hacktivist groups and established APTs—using multi-tier hosting and shell-company...
www.hendryadrian.com
March 19, 2026 at 6:40 PM