Espionage
GTIG Tracks Three Russian Clusters Weaponizing App Passwords, OAuth Consent, and WhatsApp Linking
Google's Threat Intelligence Group details three Russia-nexus clusters — UNC6293, UNC7005, UNC5976 — abusing app-password generation, OAuth consent flows, and WhatsApp device linking to hijack accounts of diplomats, academics, and defense researchers without tripping MFA.
OctLurk and SilkLurk: New Backdoors Hit Central Asian Government Networks
Kaspersky attributes a year-plus cyberespionage campaign against Central Asian and Syrian government networks to a suspected Chinese-speaking actor wielding two new memory-resident backdoors, OctLurk and SilkLurk, plus a custom proxy tool called LurkProxy.
TELESHIM: An East Asia-Linked APT Hides Its C2 Inside Telegram to Backdoor Middle East Governments
Zscaler ThreatLabz uncovers TELESHIM, MIXEDKEY, and BINDCLOAK — a new East Asia-linked malware toolset that abuses the Telegram Bot API for command-and-control against Middle East government targets.