# Cyber-espionage

Published articles for Cyber-espionage.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## North Korean hackers target Rust maintainers through fake job interviews

DevFeed: [North Korean hackers target Rust maintainers through fake job interviews](<https://devfeed.tech/articles/north-korea-s-job-interview-scam-runs-both-ways-55812.md>)

Original publisher: [Read original article](<https://www.helpnetsecurity.com/2026/09/21/north-korean-hackers-contagious-interview-defenses/>)

Author: Zeljka Zorz

Published: 2026-09-21T12:27:05Z

Content type: news

Language: en

Sources: [Help Net Security](<https://devfeed.tech/sources/help-net-security.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [Rust](<https://devfeed.tech/topics/rust.md>), [Maintainers](<https://devfeed.tech/topics/maintainers.md>), [Malware](<https://devfeed.tech/topics/malware.md>), [Job](<https://devfeed.tech/topics/job.md>)

Tags: [account-hijacking](<https://devfeed.tech/tags/account-hijacking.md>), [cryptocurrency](<https://devfeed.tech/tags/cryptocurrency.md>), [cyber-espionage](<https://devfeed.tech/tags/cyber-espionage.md>), [developer](<https://devfeed.tech/tags/developer.md>), [don-t-miss](<https://devfeed.tech/tags/don-t-miss.md>), [enterprise](<https://devfeed.tech/tags/enterprise.md>), [government-backed-attacks](<https://devfeed.tech/tags/government-backed-attacks.md>), [hot-stuff](<https://devfeed.tech/tags/hot-stuff.md>), [job](<https://devfeed.tech/tags/job.md>), [maintainers](<https://devfeed.tech/tags/maintainers.md>), [malware](<https://devfeed.tech/tags/malware.md>), [news](<https://devfeed.tech/tags/news.md>), [north-korea](<https://devfeed.tech/tags/north-korea.md>), [remote-working](<https://devfeed.tech/tags/remote-working.md>), [requirements](<https://devfeed.tech/tags/requirements.md>), [rust](<https://devfeed.tech/tags/rust.md>), [scam](<https://devfeed.tech/tags/scam.md>), [scams](<https://devfeed.tech/tags/scams.md>), [security](<https://devfeed.tech/tags/security.md>), [social-engineering](<https://devfeed.tech/tags/social-engineering.md>), [software-development](<https://devfeed.tech/tags/software-development.md>), [tips](<https://devfeed.tech/tags/tips.md>)

### AI overview

The article reports that North Korean attackers are targeting Rust developers and package maintainers with fake job, contract, and collaboration opportunities. Victims are pressured to install software or run attacker-supplied commands, potentially enabling malware publication and account compromise.

### Source excerpt

Attackers are targeting members of the Rust Project and maintainers of widely used crates (Rust code libraries), dangling attractive opportunities to compromise their devices and accounts and, ultimately, publish malware. The warning came last week from the Rust Project's crates.io team and security response working group, and described a recurring pattern: a target is invited to a video call framed as a job, contract, or collaboration opportunity, then nudged into installing something or running an ... More -> The post North Korea's job interview scam runs both ways appeared first on Help Net Security.

## OpenAI's cyber defense letter gets the diagnosis right and the prescription wrong

DevFeed: [OpenAI's cyber defense letter gets the diagnosis right and the prescription wrong](<https://devfeed.tech/articles/openai-s-cyber-defense-letter-gets-the-diagnosis-right-and-the-prescription-wrong-55744.md>)

Original publisher: [Read original article](<https://www.infoworld.com/article/4223992/openais-cyber-defense-letter-gets-the-diagnosis-right-and-the-prescription-wrong.html>)

Author: Brad LaPorte

Published: 2026-09-21T09:00:00Z

Content type: opinion

Language: en

Sources: [InfoWorld](<https://devfeed.tech/sources/infoworld.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [OpenAI](<https://devfeed.tech/topics/openai.md>), [Threat Research](<https://devfeed.tech/topics/threat-research.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Endpoint Security & XDR](<https://devfeed.tech/topics/endpoint-security-xdr.md>), [Claude Code](<https://devfeed.tech/topics/claude-code.md>), [anthropic](<https://devfeed.tech/topics/anthropic.md>), [amazon](<https://devfeed.tech/topics/amazon.md>), [Google](<https://devfeed.tech/topics/google.md>), [Microsoft](<https://devfeed.tech/topics/microsoft.md>)

Tags: [amazon](<https://devfeed.tech/tags/amazon.md>), [anthropic](<https://devfeed.tech/tags/anthropic.md>), [artificial-intelligence](<https://devfeed.tech/tags/artificial-intelligence.md>), [artificial-intelligence-cyberattacks-cybercrime-data-and-information-security-generative-ai-sec](<https://devfeed.tech/tags/artificial-intelligence-cyberattacks-cybercrime-data-and-information-security-generative-ai-sec.md>), [claude-code](<https://devfeed.tech/tags/claude-code.md>), [cyber-espionage](<https://devfeed.tech/tags/cyber-espionage.md>), [cyberattacks](<https://devfeed.tech/tags/cyberattacks.md>), [cybercrime](<https://devfeed.tech/tags/cybercrime.md>), [data-and-information-security](<https://devfeed.tech/tags/data-and-information-security.md>), [generative-ai](<https://devfeed.tech/tags/generative-ai.md>), [google](<https://devfeed.tech/tags/google.md>), [microsoft](<https://devfeed.tech/tags/microsoft.md>), [openai](<https://devfeed.tech/tags/openai.md>), [security](<https://devfeed.tech/tags/security.md>), [threat-intelligence](<https://devfeed.tech/tags/threat-intelligence.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

An opinion article argues that OpenAI's cyber defense letter correctly identifies the growing sophistication of AI-enabled cyberattacks but offers recommendations that are too reactive and slow. It contrasts those measures with an Anthropic account of an AI-orchestrated espionage campaign involving Claude Code and argues that defenders must close response-time gaps.

### Source excerpt

On August 27, 2026, OpenAI published an open letter titled "A call for collective action on cyber defense." More than 100 organizations signed it (CNBC counted 116) including Anthropic, Microsoft, Google, Amazon, CrowdStrike, Palo Alto Networks, Mastercard, and Visa. The central message is blunt: In the coming months, AI-enabled cyberattacks will become far more widespread and sophisticated as models around the world become increasingly capable. They're right, and the letter is more honest than most industry documents of its kind. It concedes that current security practices are not sufficient. It names hospitals, water treatment plants, and power systems instead of hiding behind the word critical. It admits that the technical debt is real and that the teams are under-resourced. Then it reaches the recommendations, and the urgency drains out of the room. The asks describe a world where you still get to react The letter's four calls to action come down to threat intelligence sharing, coordination across levels of government, funding for under-resourced essential services, patching high-risk vulnerabilities, and giving defenders access to capable models during an incident. All of it is worth doing. All of it also happens either long before an attack, on a timeline you control, or after an attack has already started. Intelligence sharing assumes somebody saw it first. Coordination assumes there's time to convene. Funding assumes a budget cycle. Patching assumes a published CVE and a maintenance window you can actually get approved. That is a defense architecture built for an adversary who works business hours. Run the arithmetic on GTG-1002 On November 14, 2025, Anthropic disclosed what it called the first reported AI-orchestrated cyber espionage campaign. A Chinese state-linked group it tracks as GTG-1002 hit roughly 30 organizations and used Claude Code to execute 80% to 90% of the operation independently. Human operators contributed a maximum of about 20 minutes of w

## Chinese hackers use SparroWocky malware in govt espionage attacks

DevFeed: [Chinese hackers use SparroWocky malware in govt espionage attacks](<https://devfeed.tech/articles/chinese-hackers-use-sparrowocky-malware-in-govt-espionage-attacks-48097.md>)

Original publisher: [Read original article](<https://www.bleepingcomputer.com/news/security/chinese-hackers-use-sparrowocky-malware-in-govt-espionage-attacks/>)

Author: Bill Toulas

Published: 2026-09-17T09:00:00Z

Content type: news

Language: en

Sources: [BleepingComputer](<https://devfeed.tech/sources/bleepingcomputer.md>)

Topics: [ransomware](<https://devfeed.tech/topics/ransomware.md>), [backdoor](<https://devfeed.tech/topics/backdoor.md>), [Security](<https://devfeed.tech/topics/security.md>), [C++](<https://devfeed.tech/topics/c-plus-plus.md>), [Windows](<https://devfeed.tech/topics/windows.md>), [Persistence](<https://devfeed.tech/topics/persistence.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [Process](<https://devfeed.tech/topics/process.md>), [Network](<https://devfeed.tech/topics/network.md>)

Tags: [attacks](<https://devfeed.tech/tags/attacks.md>), [backdoor](<https://devfeed.tech/tags/backdoor.md>), [c-plus-plus](<https://devfeed.tech/tags/c-plus-plus.md>), [china](<https://devfeed.tech/tags/china.md>), [computer-help](<https://devfeed.tech/tags/computer-help.md>), [computer-security](<https://devfeed.tech/tags/computer-security.md>), [computers](<https://devfeed.tech/tags/computers.md>), [cyber-espionage](<https://devfeed.tech/tags/cyber-espionage.md>), [famoussparrow](<https://devfeed.tech/tags/famoussparrow.md>), [government](<https://devfeed.tech/tags/government.md>), [infosec](<https://devfeed.tech/tags/infosec.md>), [infosec-computer-security](<https://devfeed.tech/tags/infosec-computer-security.md>), [linux](<https://devfeed.tech/tags/linux.md>), [mac](<https://devfeed.tech/tags/mac.md>), [malware](<https://devfeed.tech/tags/malware.md>), [malware-removal](<https://devfeed.tech/tags/malware-removal.md>), [network](<https://devfeed.tech/tags/network.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [persistence](<https://devfeed.tech/tags/persistence.md>), [process](<https://devfeed.tech/tags/process.md>), [processes](<https://devfeed.tech/tags/processes.md>), [security](<https://devfeed.tech/tags/security.md>), [sparrowocky](<https://devfeed.tech/tags/sparrowocky.md>), [spyware](<https://devfeed.tech/tags/spyware.md>), [support](<https://devfeed.tech/tags/support.md>), [tech-support](<https://devfeed.tech/tags/tech-support.md>), [technical-support](<https://devfeed.tech/tags/technical-support.md>), [virus](<https://devfeed.tech/tags/virus.md>), [virus-removal](<https://devfeed.tech/tags/virus-removal.md>), [windows](<https://devfeed.tech/tags/windows.md>)

### AI overview

ESET researchers identified SparroWocky, a modular C++ backdoor used by the China-linked FamousSparrow espionage group against government organizations across Latin America. The malware supports command execution, data collection, file operations, screenshots, TCP proxying, and persistence while using multiple evasion techniques.

### Source excerpt

The China-linked espionage group FamousSparrow has been using a new backdoor named SparroWocky in attacks on government organizations in Latin America. [...]

## US officials revise claims that government agencies were hacked by Chinese, now say they were targets

DevFeed: [US officials revise claims that government agencies were hacked by Chinese, now say they were targets](<https://devfeed.tech/articles/us-officials-revise-claims-that-government-agencies-were-hacked-by-chinese-now-say-they-were-targets-56592.md>)

Original publisher: [Read original article](<https://indianexpress.com/article/technology/tech-news-technology/us-officials-revise-claims-that-government-agencies-were-hacked-by-chinese-now-say-they-were-targets-10856307/>)

Author: Reuters

Published: 2026-08-31T01:01:37Z

Content type: news

Language: en

Sources: [Technology | The Indian Express](<https://devfeed.tech/sources/technology-the-indian-express.md>)

Topics: [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [Hacking](<https://devfeed.tech/topics/hacking.md>), [Threat Research](<https://devfeed.tech/topics/threat-research.md>), [national security](<https://devfeed.tech/topics/national-security.md>), [cybersecurity and infrastructure security agency](<https://devfeed.tech/topics/cybersecurity-and-infrastructure-security-agency.md>)

Tags: [chinese-state-cyber-attacks-us-senate-nasa](<https://devfeed.tech/tags/chinese-state-cyber-attacks-us-senate-nasa.md>), [cyber-espionage](<https://devfeed.tech/tags/cyber-espionage.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [department-of-justice](<https://devfeed.tech/tags/department-of-justice.md>), [doj-revises-china-hack-statement](<https://devfeed.tech/tags/doj-revises-china-hack-statement.md>), [espionage](<https://devfeed.tech/tags/espionage.md>), [fbi-chinese-cyber-espionage-campaign](<https://devfeed.tech/tags/fbi-chinese-cyber-espionage-campaign.md>), [government](<https://devfeed.tech/tags/government.md>), [hacking](<https://devfeed.tech/tags/hacking.md>), [nanjing-xinjiuwei-network-technology](<https://devfeed.tech/tags/nanjing-xinjiuwei-network-technology.md>), [nasa](<https://devfeed.tech/tags/nasa.md>), [patching](<https://devfeed.tech/tags/patching.md>), [qscan-qtrouter-domain-seizure](<https://devfeed.tech/tags/qscan-qtrouter-domain-seizure.md>), [qtfy-chinese-state-sponsored-hackers](<https://devfeed.tech/tags/qtfy-chinese-state-sponsored-hackers.md>), [tech](<https://devfeed.tech/tags/tech.md>), [technology](<https://devfeed.tech/tags/technology.md>), [technology-tech](<https://devfeed.tech/tags/technology-tech.md>), [us](<https://devfeed.tech/tags/us.md>), [us-agencies-targeted-not-compromised](<https://devfeed.tech/tags/us-agencies-targeted-not-compromised.md>)

### AI overview

U.S. officials corrected earlier claims that several government agencies had been hacked by a Chinese state-sponsored group, clarifying that the agencies were targets and that only some were compromised. The correction narrows the scope of confirmed breaches in a broader cyber-espionage campaign.

### Source excerpt

The distinction matters because it narrows the scope of confirmed breaches in what the DOJ described as a years-long Chinese cyber-espionage campaign against U.S. government agencies, defense contractors and other sensitive targets.

## Armored Likho expands its cyber-espionage toolkit

DevFeed: [Armored Likho expands its cyber-espionage toolkit](<https://devfeed.tech/articles/armored-likho-expands-its-cyber-espionage-toolkit-48824.md>)

Original publisher: [Read original article](<https://securelist.com/armored-likho-still-toolkit/121033/>)

Author: Konstantin Isakov

Published: 2026-08-13T08:00:15Z

Content type: article

Language: en

Sources: [Securelist](<https://devfeed.tech/sources/securelist.md>)

Topics: [infection chain](<https://devfeed.tech/topics/infection-chain.md>), [C2](<https://devfeed.tech/topics/c2.md>), [API](<https://devfeed.tech/topics/api.md>), [kaspersky](<https://devfeed.tech/topics/kaspersky.md>), [Rust](<https://devfeed.tech/topics/rust.md>), [Tauri](<https://devfeed.tech/topics/tauri.md>), [App](<https://devfeed.tech/topics/app.md>), [Framework](<https://devfeed.tech/topics/framework.md>), [data](<https://devfeed.tech/topics/data.md>), [Server](<https://devfeed.tech/topics/server.md>)

Tags: [api](<https://devfeed.tech/tags/api.md>), [app](<https://devfeed.tech/tags/app.md>), [apt](<https://devfeed.tech/tags/apt.md>), [apt-reports](<https://devfeed.tech/tags/apt-reports.md>), [armored-likho](<https://devfeed.tech/tags/armored-likho.md>), [audio-surveillance](<https://devfeed.tech/tags/audio-surveillance.md>), [command-and-control](<https://devfeed.tech/tags/command-and-control.md>), [cyber](<https://devfeed.tech/tags/cyber.md>), [cyber-espionage](<https://devfeed.tech/tags/cyber-espionage.md>), [dropper](<https://devfeed.tech/tags/dropper.md>), [eavesdropping](<https://devfeed.tech/tags/eavesdropping.md>), [espionage](<https://devfeed.tech/tags/espionage.md>), [files](<https://devfeed.tech/tags/files.md>), [framework](<https://devfeed.tech/tags/framework.md>), [full](<https://devfeed.tech/tags/full.md>), [great-research](<https://devfeed.tech/tags/great-research.md>), [infection-chain](<https://devfeed.tech/tags/infection-chain.md>), [kaspersky](<https://devfeed.tech/tags/kaspersky.md>), [large](<https://devfeed.tech/tags/large.md>), [logs](<https://devfeed.tech/tags/logs.md>), [malware](<https://devfeed.tech/tags/malware.md>), [malware-descriptions](<https://devfeed.tech/tags/malware-descriptions.md>), [malware-technologies](<https://devfeed.tech/tags/malware-technologies.md>), [medium](<https://devfeed.tech/tags/medium.md>), [rust](<https://devfeed.tech/tags/rust.md>), [spyware](<https://devfeed.tech/tags/spyware.md>), [still-toolkit](<https://devfeed.tech/tags/still-toolkit.md>), [targeted-attacks](<https://devfeed.tech/tags/targeted-attacks.md>), [tauri](<https://devfeed.tech/tags/tauri.md>), [telegram](<https://devfeed.tech/tags/telegram.md>), [thumbnail](<https://devfeed.tech/tags/thumbnail.md>), [trojan](<https://devfeed.tech/tags/trojan.md>), [trojan-stealer](<https://devfeed.tech/tags/trojan-stealer.md>)

### AI overview

Kaspersky researchers describe an Armored Likho cyber-espionage campaign that uses a fake donation app to deliver the Rust-based Still Toolkit. Its components steal Telegram session data and conduct covert audio surveillance.

### Source excerpt

Kaspersky experts break down a new Armored Likho campaign that poses as a fundraising efforts and delivers a new Still Toolkit aimed at stealing Telegram data and eavesdropping on victims.