
A series of coordinated cyberattacks has been reported, targeting various entities across Europe, the United States, and Southeast Asia. These attacks have been attributed to Russian and China-linked hacker groups, employing sophisticated malware and phishing campaigns to breach the security of a wide range of targets including NGOs, research institutions, governments, and political parties. Notably, Russian hackers have been using upgraded 'AcidPour' malware against Ukrainian telecoms, deploying a never-before-seen data wiper against Ukrainian ISPs, and utilizing 'TinyTurla-NG' to breach European NGO's systems. Additionally, a China-linked threat group has aggressively exploited software flaws in ConnectWise ScreenConnect and F5 BIG-IP, impacting networks of research institutions, NGOs, and governments. In Germany, elite Russian hackers have targeted several political parties, employing tactics such as spearphishing campaigns and the use of 'WINELOADER' malware, with Google and US security firm Mandiant highlighting the serious nature of these intrusions. Other significant attacks include a new phishing campaign targeting US organizations with NetSupport RAT, Ivanti scrambling with 2 more vulnerabilities, critical exploitation of Fortinet’s FortiClient EMS flaw, and over 100 organizations hit by new StrelaStealer phishing attacks. The involvement of APT29 and Midnight Blizzard has been specifically noted in these operations.



















Russia's Cozy Bear caught phishing German politicos with phony dinner invites https://t.co/JvpXePTRaO
Russian Hackers Use 'WINELOADER' Malware to Target German Political Parties: https://t.co/Aql9U5fRAP by The Hacker News #infosec #cybersecurity #technology #news
Mandiant connects WINELOADER backdoor to Midnight Blizzard, a Russian SVR-linked hacking group. #Malware targeted German political parties with wine-tasting phishing scams. Read more: https://t.co/y02xtKGhDy #cybersecurity #hacking