Russian APT28 Hackers Targeting 13 Nations in Ongoing Cyber Espionage Campaign

APT28, also known as ITG05, BlueDelta, Fancy Bear, Forest Blizzard, FROZENLAKE, Iron Twilight, Sednit, Sofacy, and TA422, is conducting a highly targeted cyber espionage campaign that primarily focuses on European entities involved in humanitarian aid allocation, utilizing lures related to the Israel-Hamas war and distributing the HeadLace backdoor.

Researchers Unmask Sandman APT’s Hidden Link to China-Based Keyplug Backdoor

Sandman APT, Storm-0866/Red Dev 40, and LuaDream are China-based threat clusters that target telecommunication providers in the Middle East, Western Europe, and South Asia using the KEYPLUG backdoor and LuaDream implant, highlighting the complex nature of the Chinese threat landscape and the growing trend among threat actors to employ less common techniques to avoid detection.