Field notes from the edge.
What our engineers learned this week. Hands-on technical deep-dives, postmortems, and strategy frameworks.
AIOceanLotus Hits Vietnam Investors With SPECTRALVIPER in FireAnt Attack
The Vietnam-aligned threat actor OceanLotus has conducted two cyber espionage campaigns targeting Vietnamese infrastructure companies and stock investors using the SPECTRALVIPER backdoor. The attacks include a prolonged operation against a Vietnamese construction corporation spanning mid-2024 to February 2026, alongside a separate supply chain attack targeting investors.
AIVerdantBamboo Deploys BSD Variant of BRICKSTORM on Linux Appliances
China-linked cyber espionage group VerdantBamboo has been observed deploying a BSD variant of the BRICKSTORM backdoor along with PLENET (GRIMBOLT) and AGENTPSD malware to target Linux systems. Volexity attributes this activity to VerdantBamboo, which overlaps with Microsoft's Clay Typhoon threat group. This represents an expansion of the threat actor's capabilities to target BSD and Linux-based ap
AITropical Blend: Cyber & Politics Ramp Up Across Latin America
China-linked cyber espionage groups have conducted targeted attacks across at least twelve Latin American nations, focusing on critical infrastructure and strategic sectors. The campaigns have concentrated on gathering intelligence related to maritime shipping operations, oil production facilities, and other geopolitically significant assets in the region.
AIChina-Aligned Groups Ramp Up Attacks: Dragon Weave Hits Czech Republic & Taiwan
A cyber espionage campaign called Operation Dragon Weave, attributed to China-aligned threat actors, is targeting government, research, academic, technology, and financial services organizations in the Czech Republic and Taiwan. The campaign uses spear-phishing emails with ZIP attachments to deliver the AdaptixC2 agent, enabling remote access and surveillance capabilities.
