Install
State‑Linked Operations
Campaigns tied to state actors and their cutouts.
- 1 Tracked terms
- Last 30 days Feed window
What this topic collects on
An article joins this feed when it matches these terms. Each one is also a search of its own.
Related topics
Latest in State‑Linked Operations
North Korea Hackers Stole Crypto in Fake Job Interviews
10+ hour, 54+ min ago (19+ words) State-linked North Korean hackers used fake technical job interviews to install malware, capture credentials and steal millions in cryptocurrency....
Iran-Linked Hackers target Windows Machines through WhatsApp and Telegram
1+ day, 23+ hour ago (444+ words) Cybersecurity Insiders An Iranian hacking group has reportedly launched a new spyware campaign targeting Windows users through popular messaging platforms such as WhatsApp and Telegram. The campaign comes amid heightened geopolitical tensions involving Iran and the United States, raising concerns…...
SparroWocky: A New Backdoor for Latin American Governments by FamousSparrow
2+ day, 3+ hour ago (1523+ words) 1. Basic Information Original Title: Beware the SparroWock: The backdoor that bites, the commands that catch Source: ESET Research Published Date: 2026-09-17 Updated Date: None Severity: High Severity Justification: According to ESET observations, approximately 90% of FamousSparrow targets were concentrated in Latin America…...
Report: North Korea Deploying Unlawful Laborers Overseas
2+ day, 13+ hour ago (106+ words) The North Korean regime is deploying its laborers overseas in violation of United Nations sanctions. What would you like to watch today? Report: North Korea Deploying Unlawful Laborers Overseas NTD Evening News Full Broadcast (Sept. 17) NTD Good Morning Full Broadcast…...
China-Aligned FamousSparrow Deploys SparroWocky Backdoor Across Latin America
3+ day, 3+ hour ago (467+ words) The China-aligned state-sponsored threat actor known as FamousSparrow has been observed deploying a previously unreported backdoor called SparroWocky in attacks targeting multiple countries in Latin America since at least August 2025. "SparroWocky is a modular, C++ backdoor," ESET security researchers Alexandre…...
CHOSEN BRICK: Iranian Windows Surveillance Malware Using Telegram C2
3+ day, 2+ hour ago (1514+ words) 1. Overview Original Title: Iranian cyber targeting of dissidents, activists and journalists Source: NCSC, FBI, AIVD Published: 2026-09-15 Updated: None Severity: High Basis for Severity: The joint government advisory reports real-world compromises targeting dissidents, activists, and journalists worldwide since at least 2025. The…...
Russia taps North Korean workers to make drones under fake visas- Moneycontrol.com
3+ day, 10+ hour ago (378+ words) Quick, easy & completely paperless. Russia is increasingly mobilizing North Korean workers to build military drones for use against Ukraine in defiance of international sanctions, giving Pyongyang a key source of revenue to fund its unlawful weapons programs, the US and…...
Iranian hackers use CHOSEN BRICK Windows malware to spy on targets
4+ day, 8+ hour ago (587+ words) Hackers hijack HBO Max Reddit account to push malware in ClickFix ads Homebrew 7.0.0 gets built-in GUI, better security controls Dutch NCSC: Critical Check Point VPN flaws exploitation is imminent New Android malware encrypts files, steals data, and harasses victims Anthropic…...
US, UK, Dutch Agencies Expose Iranian ‘Chosen Brick’ Surveillance Malware
4+ day, 5+ hour ago (491+ words) US, UK, and Dutch government agencies published a report detailing the malware, and the FBI described the abuse of Telegram for C&C. Cybersecurity and intelligence agencies in the US, UK, and Netherlands have issued a joint advisory warning of a…...
Chosen Brick spyware uses Telegram to target dissidents on Windows – 4sysops
4+ day, 7+ hour ago (24+ words) Iranian state-linked actors are using Chosen Brick, also known as HEAVYGRAM, to spy on dissidents, activists, and journalists through Windows devices. A new joi...