Unit 42 details CL-STA-1114, a Russian-nexus cyberespionage campaign overlapping with Void Blizzard/LAUNDRY BEAR, exploiting CVE-2025-66376 in Zimbra webmail through zero-click phishing emails containing obfuscated HTML/SVG that decodes and executes a Base64-encoded JavaScript payload in the victim's browser. The payload exfiltrates CSRF tokens, credentials, 2FA scratch codes, and up to 90 days of email/search history to hardcoded C2 servers, with at least nine IPs and nine domains identified as rotating infrastructure averaging 35.4 days of activity.
Cyberespionage
10 posts
Russian Global Webmail Espionage One Target, Two Flags | Rival Espionage Actors Converge On Pakistani Law Enforcement SentinelLABS identified sustained cyberespionage activity by suspected China-nexus and India-nexus threat actors against Pakistani law enforcement organizations from February 2024 to April 2026, with both converging on Balochistan Police. Four C2 clusters (PlugX, ShadowPad, Cobalt Strike, Remcos) were mapped to compromised infrastructure. A China-nexus actor compromised the Balochistan Police Complaint Management System (CMS), deploying custom implants (cms_plugin.exe) disguised as portal updates that delivered AsyncRAT and staged payloads from attacker-controlled servers, targeting both police personnel and citizens. The implants share a development environment (D:\codedome PDB prefix) with Chinese-language indicators, attributing them to a Chinese-speaking developer.
Gamaredon in 2025: Leveraging tunnels, workers, dead drops, and new alliances Gamaredon, a Russia-aligned APT group attributed to the FSB, maintained high operational tempo throughout 2025 with 35 spearphishing campaigns exclusively targeting Ukrainian government and military institutions. The group introduced six new PowerShell tools, resurrected the PteroSetup VBScript weaponizer for lateral movement, and began abusing CVE-2025-8088 (WinRAR) for persistence via the Startup folder. A significant infrastructure evolution occurred: C&C servers are now hidden behind tunnel services (Cloudflare tunnels, Cloudflare workers, Microsoft devtunnels, Loophole) and dead-drop resolutions on legitimate platforms (Telegram, Telegra.ph, Rentry, GoFile, Dropbox, and others), while stolen data is exfiltrated to S3-compatible cloud storage (Wasabi, Tebi, Intercolo) rather than attacker-owned servers.
FSB’s matryoshka #3/3 – Gamaredon’s gifts that keeps unpacking – GammaSteel Gamaredon, an FSB-linked threat actor, has deployed a highly evasive, fileless stealer dubbed GammaSteel targeting Ukrainian entities. The malware leverages Windows DPAPI to encrypt and stage payloads within the registry, actively monitoring local, network, and USB drives for sensitive documents to exfiltrate via legitimate cloud services and dynamic C2 infrastructure.
FSB’s matryoshka #2/3 – Gamaredon’s gifts that keeps unpacking – GammaLoad Gamaredon, a Russia-nexus threat actor, utilizes a multi-stage VBScript loader framework named GammaLoad to establish persistent access and deploy subsequent payloads like GammaSteel. The infection chain leverages Dead Drop Resolvers on legitimate platforms, stores C2 configurations in the Windows Registry, and uses Alternate Data Streams (ADS) combined with Scheduled Tasks for stealthy execution.
FSB’s matryoshka #1/3 – Gamaredon’s gifts that keeps unpacking – GammaPhish and GammaWorm Gamaredon (FSB) is conducting an ongoing cyberespionage campaign against Ukrainian targets using a modular, fileless infection chain. The attack leverages HTML smuggling and archive path traversal (CVE-2025-8088) for initial access, followed by the deployment of GammaWorm, which utilizes NTFS Alternate Data Streams (ADS) and Dead Drop Resolvers (DDRs) on legitimate platforms for persistence, propagation, and C2 communication.
FrostyNeighbor: Fresh mischief and digital shenanigans FrostyNeighbor, a Belarus-aligned threat actor, has updated its toolset to target Ukrainian governmental organizations with a multi-stage compromise chain. The attack utilizes spearphishing with malicious PDFs that redirect to a RAR archive containing a JavaScript dropper, which ultimately deploys a Cobalt Strike beacon via the PicassoLoader malware following strict server-side and manual victim validation.
Inside Shadow-Earth-053: A China-Aligned Cyberespionage Campaign Against Government and Defense Sectors in Asia SHADOW-EARTH-053 is a China-aligned cyberespionage campaign exploiting legacy N-day vulnerabilities in Microsoft Exchange and IIS servers to target government and defense sectors primarily in Asia. The threat actors utilize GODZILLA web shells for persistence and deploy ShadowPad implants via DLL sideloading, sharing significant operational overlaps with another intrusion set tracked as SHADOW-EARTH-054.
Converging Interests: Analysis of Threat Clusters Targeting a Southeast Asian Government Unit 42 identified a coordinated cyberespionage campaign targeting a Southeast Asian government entity, involving three distinct China-aligned threat clusters. The attackers utilized a variety of tools including USB worms, custom loaders, and multiple remote access Trojans (PUBLOAD, Masol, Gorem, FluffyGh0st) to establish persistent access, evade detection via DLL sideloading, and exfiltrate sensitive data.
An Investigation Into Years of Undetected Operations Targeting High-Value Sectors Since 2020, a Chinese threat actor tracked as CL-UNK-1068 has targeted critical infrastructure in Asia for cyberespionage. The group utilizes a diverse, cross-platform toolkit including web shells, custom Go-based scanners, modified Fast Reverse Proxy (FRP) for tunneling, and legacy Python executables for DLL side-loading to maintain stealth, escalate privileges, and exfiltrate sensitive data.