Back to Feed

Tag

Nation-state

State-sponsored campaigns, APT operations, cyber warfare

50 items tagged #nation-state

Articles

Alleged Breach of Shanghai Fudan Microelectronics Leaks 175MB of IC Schematics, Internal Documents, and Intellectual Property

Threat actor s1ic3r leaks 175MB of IC schematics and IP from Shanghai Fudan Microelectronics.

‼️🇨🇳 Alleged Breach of Shanghai Fudan Microelectronics Leaks 175MB of IC Schematics, Internal D...

Shanghai Fudan Microelectronics breach leaks 175MB of IC schematics and internal documents.

Hack-for-hire spyware campaign targets journalists in Middle East, North Africa

Bitter APT group conducts hack-for-hire spyware campaign targeting MENA journalists with ProSpy Android malware.

‼️🇺🇸 Actor coderx shared a 758MB database dump from Eastern Illinois University containing 93 C...

Actor coderx leaked 758MB database from Eastern Illinois University, citing retaliation for Iranian university attacks.

1/2‼️🇨🇴 Threat actors claim to be selling financial data from SUFI, a financing company within...

Threat actors claim to be selling financial data from SUFI, a Grupo Bancolombia financing company.

‼️🇺🇸 A well-known initial access broker is selling root-level remote code execution access to a...

Initial access broker sells root RCE access to US aerospace/defense firewall for $1,000.

‼️🇫🇷 Threat actor NormalLeVrai is selling alleged Service Telecom database containing 2,835,372...

Threat actor NormalLeVrai selling alleged Service Telecom database with 2.8M user records and source code.

Storm-1175 Deploys Medusa Ransomware at 'High Velocity'

Microsoft attributes Medusa ransomware deployments to Storm-1175 exploiting N-day and zero-day vulnerabilities.

‼️🇫🇷 Threat Actor Selling 1.2 Million French FICOBA Banking Leads With IBANs, SSNs, and Tax IDs...

Threat actor sells 1.2M French banking records with IBANs, SSNs, and tax IDs from 15+ banks.

This Hacker (IntelBroker) Kept Embarrassing the FBI https://t.co/G1aTTQ1Tgo

IntelBroker threat actor repeatedly compromised FBI systems and leaked sensitive data.

‼️🇨🇴 NyxarGroup and collaborators are allegedly selling personal information from Colombian gov...

NyxarGroup allegedly selling stolen Colombian government personal data online.

Threat Actor Selling Root RCE Shell Access to Botswana Government Health Portal Firewall for $300

Threat actor Florence selling root RCE access to Botswana health portal firewall for $300.

‼️🇧🇼 Threat Actor Selling Root RCE Shell Access to Botswana Government Health Portal Firewall f...

Threat actor offers root RCE shell access to Botswana government health portal firewall for $300.

‼️🇺🇾 A threat actor claims to have obtained databases from Plan Ceibal, a Uruguayan government...

Threat actor claims breach of Uruguayan Plan Ceibal, exposing 1.2M CREA users and 1M device records.

‼️🇲🇽Threat actor Lvn4t1k0 allegedly leaked personal data from CONALEP Morelos including teacher...

Threat actor Lvn4t1k0 leaks teacher and student data from Mexican education institution CONALEP Morelos.

‼️🇨🇴 The internal and confidential databases of Banco Agrario de Colombia, a state-owned Colomb...

Banco Agrario de Colombia internal databases allegedly leaked by Petro_Escobar and NyxarGroup.

Medusa Ransomware Fast to Exploit Vulnerabilities, Breached Systems

Medusa ransomware group exploits zero-days and fresh vulnerabilities to breach 300+ organizations within days.

Hong Kong Police Can Force You to Reveal Your Encryption Keys - Schneier on Security

Hong Kong police gain power to force encryption key disclosure under National Security Law.

Hong Kong Police Can Force You to Reveal Your Encryption Keys https://t.co/HPa2LFO8Tj

Hong Kong police gain legal power to compel encryption key disclosure.

German Police Unmask REvil Ransomware Leader

German police identify Russian national as REvil/GandCrab ransomware leader.

German authorities identify REvil and GangCrab ransomware bosses

German authorities identify two Russian nationals as leaders of GandCrab and REvil ransomware operations.

Alleged Breach of Colombia's Huila Department Government Extranet Exposes Officer Data, Municipal Offices, and Government Operations Across 8 Municipalities

NyxarGroup breaches Colombia's Huila Department government extranet, exposing officer data and municipal records across

Drift $280M crypto theft linked to 6-month in-person operation

North Korean hackers stole $280M from Drift Protocol via 6-month social engineering and insider compromise operation.

Storm-1175 focuses gaze on vulnerable web-facing assets in high-tempo Medusa ransomware operations

Storm-1175 exploits recently disclosed vulnerabilities to deploy Medusa ransomware in high-velocity campaigns.

‼️🇲🇽 A threat actor claims to be selling a complete Mexican taxpayer database from SAT containi...

Threat actor claims to sell complete Mexican SAT taxpayer database with 13M+ records for $300.

‼️🇲🇽 A threat actor allegedly leaked data from Mexicos Ministry of Health containing RFC, CURP,...

Threat actor leaks Mexico Ministry of Health employee data including RFC and CURP identifiers.

North Korean Hackers Target High-Profile Node.js Maintainers

North Korean UNC1069 targets Node.js maintainers with social engineering to compromise NPM packages.

BKA Identifies REvil Leaders Behind 130 German Ransomware Attacks

German BKA identifies two REvil ransomware leaders behind 130 attacks in Germany.

Germany Doxes “UNKN,” Head of RU Ransomware Gangs REvil, GandCrab

Germany identifies Daniil Maksimovich Shchukin as UNKN, leader of GandCrab and REvil ransomware gangs.

‼️🇨🇴 A threat actor published internal databases from Colombian financial institutions containi...

Threat actor leaks internal databases from Colombian financial institutions with customer data.

The Hack That Exposed Syria’s Sweeping Security Failures

Syrian government X accounts hijacked in March, revealing systemic cybersecurity failures and credential reuse.

Axios npm hack used fake Teams error fix to hijack maintainer account

North Korean UNC1069 compromised Axios npm maintainer via social engineering to publish malicious package versions.

‼️🇺🇸 Root-level firewall access to an unnamed major US financial services corporation with $2B+...

US financial firm with $2B+ revenue's root firewall access allegedly sold by initial access broker.

‼️🇵🇾 Paraguay's Civil Status Registry (Registro del Estado Civil) allegedly has its database pu...

Paraguay's Civil Status Registry database allegedly offered for sale by GordonFreeman on cybercrime forum.

UNC1069 Targets Node.js Maintainers via Fake LinkedIn, Slack Profiles

UNC1069 targets Node.js maintainers via fake LinkedIn/Slack profiles to compromise npm packages.

"Salary Slips.exe." "Dont Delete.exe." "Important.exe." These are the filenames BRUSHWORM copies...

BRUSHWORM malware spreads via USB drives using deceptive filenames targeting South Asian financial institutions.

‼️🇷🇺 Forum IP Leak ▪️Forum: Rehub ▪️IP: 5[.]175[.]247[.]131 ▪️Ports: 22, 25 ▪️ASN: 213501 Oni...

Russian darknet forum Rehub infrastructure details leaked including IP and domain.

Europe’s cyber agency blames hacking gangs for massive data breach and leak | TechCrunch

CERT-EU attributes European Commission breach to TeamPCP; ShinyHunters leaked 92GB of stolen data.

‼️ The European Union's cybersecurity agency announced Thursday that a cyberattack and subsequent...

EU executive branch suffers cyberattack and data breach attributed to TeamPCP cybercriminal group.

2/2‼️🇮🇶🇨🇳 Alleged sale of initial access to: ▪️An Iraq Higher Education Platform ▪️An Africa...

Threat actor allegedly offers initial access to Iraqi education platform, African government system, and Chinese

1/2‼️🇺🇸🇸🇦🌏Alleged sale of initial access to: ▪️A USA Managed Services Provider ▪️A US gover...

Threat actor allegedly offers initial access to US MSP, government contractor, Saudi ministry, and Asian POS provider.

Latin America and the Caribbean Cybercrime Landscape

Insikt Group report on 2025 LAC cybercrime landscape reveals 452 ransomware incidents targeting Brazil, Mexico,

‼️🇸🇦 Saudi Arabia's Chamber of Commerce allegedly had ~478,000 active business contact records...

Saudi Arabia's Chamber of Commerce data breach exposes ~478k business contact records on cybercrime forum.

Die Linke German political party confirms data stolen by Qilin ransomware

Qilin ransomware group claims attack on Die Linke German political party, threatens data leak.

‼️🇺🇸🇨🇦 United States and Canada Police Tipline Databases, dubbed "BlueLeaks 2.0," are alleged...

8.3M police tipline records from US and Canada allegedly breached and sold on cybercrime forum.

‼️🇻🇳 A massive dataset allegedly containing 80 million Vietnamese telephone lines and 70 millio...

80M Vietnamese phone numbers and 70M voice recordings leaked on cybercrime forum.

Blast Radius of TeamPCP Attacks Expands Amid Hacker Infighting

TeamPCP supply chain attacks expand as ShinyHunters and Lapsus$ claim involvement.

TrueConf Zero-Day Exploited in Asian Government Attacks

Chinese hackers exploit TrueConf zero-day in Asian government attacks via compromised update server.

UNC1069 Social Engineering of Axios Maintainer Led to npm Supply Chain Attack

UNC1069 social engineered Axios npm maintainer to publish trojanized package versions.

Drift Loses $285 Million in Durable Nonce Social Engineering Attack Linked to DPRK

Drift loses $285M in sophisticated durable nonce social engineering attack linked to North Korea.