Industrial-Scale Model Theft: NSA, CISA, and FBI Identify DeepSeek, Alibaba, Moonshot AI, MiniMax, StepFun, and Z.AI
The NSA, CISA, and FBI have issued a joint advisory identifying a coordinated, industrial-scale campaign by Chinese AI firms—specifically DeepSeek, Alibaba, Moonshot AI, MiniMax, StepFun, and Z.AI—to conduct large-scale model theft. The primary attack vector is knowledge distillation, where proprietary intelligence is systematically extracted from U.S. frontier LLMs via high-volume API exploitation. This process involves harvesting billions of tokens to train competitive models, such as Moonshot AI's Kimi-K2 and Kimi-K3, effectively bypassing the massive R&D and compute requirements of original model development.
Google Chrome and Microsoft Windows Zero-Day Chain via BlueMoon Exploit Kit
The "BlueMoon" exploit kit facilitates high-precision espionage by chaining a Google Chrome zero-day vulnerability for initial sandbox escape with a Microsoft Windows zero-day to achieve local privilege escalation (LPE). Attributed to China-aligned actor APT31, the kit enables kernel-level access to deploy modular surveillance backdoors across government and defense networks. The rapid emergence of the kit across four distinct threat clusters within a 12-day window indicates a highly coordinated distribution model or potential AI-driven exploit development. Effective defense necessitates immediate deployment of browser and OS security updates alongside aggressive hunting for associated C2 infrastructure and malicious file hashes.
Fire Ant: China-Nexus Threat Actor Hijacks Cisco Routers and Trusted Infrastructure
The China-nexus threat actor "Fire Ant" has shifted its operational focus toward "trusted infrastructure," specifically targeting Cisco routers, Linux-based management hosts, and authentication systems. By compromising the core network fabric, the actor establishes persistence below the endpoint visibility layer, enabling the interception of credentials and the manipulation of system logs to evade detection. This strategic pivot allows Fire Ant to leverage trusted network pathways to penetrate isolated, high-value environments for long-term intelligence collection and espionage, effectively bypassing standard EDR and endpoint security controls.
Russian APT28 Campaign Leveraging HOOKEDGE and webhook.site for European Espionage
Between September 2025 and April 2026, a Russian GRU-linked threat actor, identified as BlueDelta (overlapping with APT28), conducted a targeted espionage campaign against defense and diplomatic organizations in Romania, Spain, and Trkiye. The attackers deployed "HOOKEDGE," a lightweight Windows batch script backdoor designed for stealthy command-and-control (C2). The campaign utilizes the legitimate developer utility webhook.site for C2 infrastructure and employs traffic masking techniques to mimic standard Microsoft Edge browser activity. This approach effectively bypasses traditional network security monitoring by blending malicious telemetry with benign web traffic, facilitating long-term persistence and data exfiltration from high-value geopolitical targets.
Iranian APT Screening Serpens Expands Espionage Capabilities with Six New RAT Variants
Iranian-aligned threat actor Screening Serpens has escalated its espionage operations by deploying six distinct Remote Access Trojan (RAT) variants. The campaign utilizes sophisticated social engineering via fraudulent recruitment platforms and fake job sites to target high-value technology professionals in the United States, Israel, and the United Arab Emirates. The malware employs advanced obfuscation, diverse Command and Control (C2) infrastructures, and complex persistence mechanisms to facilitate long-term network presence. This evolution indicates a strategic shift toward highly targeted intelligence gathering, aiming to compromise sensitive intellectual property and national security interests through credential harvesting and lateral movement within critical governmental and corporate infrastructures.
Dark Caracal Deploys GoCaracal Malware with Ethereum-Based C2 Fallback
Dark Caracal, a Lebanon-linked espionage group, has transitioned from its legacy Bandook toolkit to GoCaracal, a Go-based malware framework targeting the Latin American communications sector, specifically within Venezuela. The malware utilizes SVG-based phishing for initial access and implements a high-resilience C2 architecture featuring an Ethereum smart contract fallback mechanism for backup address retrieval. Capabilities include remote shell access, keylogging, browser data exfiltration, and remote desktop control. This evolution significantly increases operational persistence by leveraging decentralized blockchain infrastructure to bypass traditional domain and IP-based takedown efforts.
QTYF Threat Group Utilizes qscan and qtrouter to Breach US Federal Agencies via IoT Botnets
The Chinese state-sponsored threat group QTYF conducted a sophisticated espionage campaign targeting the US Department of Justice, NASA, the Federal Reserve, and the US Senate. The actors deployed a global botnet of hijacked IoT devices—including routers and smart appliances—to mask their origins and provide a resilient C2 infrastructure. Using custom binaries qscan for network reconnaissance and qtrouter for traffic obfuscation and routing, QTYF successfully exfiltrated high-value national security and economic data. The operation was disrupted through FBI-led domain seizures and the neutralization of the core routing toolsets.
Espionage Campaign Exploiting ownCloud CVE-2023-49105 to Target Philippine Nuclear Research
A sophisticated espionage campaign, attributed to Chinese-speaking threat actors, successfully compromised the Philippine Nuclear Research Agency by exploiting CVE-2023-49105. This critical authentication bypass vulnerability in ownCloud, stemming from an empty signing secret, enabled unauthorized access to sensitive document repositories. Post-exploitation, the adversary employed Microsoft Teams-based vishing, deployed the GoGRPC backdoor, and utilized the Sliver C2 framework to maintain persistence. The breach resulted in the exfiltration of critical nuclear research and naval defense documentation, highlighting the extreme risks of misconfigured authentication secrets in centralized document management systems.