Field notes from the edge.
What our engineers learned this week. Hands-on technical deep-dives, postmortems, and strategy frameworks.
AIFake Microsoft Alerts Used to Deploy North Korean NarwhalRAT Malware
North Korean state-sponsored threat actor ScarCruft (APT37) is conducting spear-phishing campaigns that impersonate Microsoft Account security alerts to distribute NarwhalRAT malware. The social engineering tactic leverages fake security notifications to create urgency and trick recipients into executing malicious payloads. This campaign demonstrates continued evolution in APT37's tactics targetin
AIPakistan-Linked SideCopy Targets Afghanistan Finance Ministry with Xeno RAT
The Pakistan-aligned threat actor SideCopy has launched a targeted spear-phishing campaign against Afghanistan's Ministry of Finance, deploying the open-source Xeno RAT malware. The attack vector involves a ZIP archive containing a malicious LNK file with a Pashto-language filename designed to deceive targets into execution.
AIChina-Aligned Groups Ramp Up Attacks: Dragon Weave Hits Czech Republic & Taiwan
A cyber espionage campaign called Operation Dragon Weave, attributed to China-aligned threat actors, is targeting government, research, academic, technology, and financial services organizations in the Czech Republic and Taiwan. The campaign uses spear-phishing emails with ZIP attachments to deliver the AdaptixC2 agent, enabling remote access and surveillance capabilities.
