Latest updates for Apt37

Fresh curated links around APT37 are collected here so marketers can spot useful updates and turn timely ideas into posts faster.

Recent items include:

  • Proofpoint: TA4922 Deploys New RAT and Loader Arsenal
  • Chinese-Speaking APT Deploys New TinyRCT Backdoor in Southeast Asia Campaign
  • Suspected China-Nexus Hackers Use Fake Indian Tax Filing Utility to Deploy DcRAT

Post angles to try

Share the most useful takeaway for your audience.
Turn one article into a quick practical checklist.
Ask your audience how this shift affects their work.
Turn angles into scheduled posts

Fresh articles and ideas

Recent curated links from global sources. Generate one free draft from any story, then use SocialBu to schedule and refine your content calendar.

gbhackers.com /1 month ago

Proofpoint: TA4922 Deploys New RAT and Loader Arsenal

A rapidly evolving threat cluster tracked as TA4922, a Chinese-speaking cybercriminal actor deploying a diverse and expanding malware arsenal that now includes Atlas RAT, RomulusLo...

Read source
thehackernews.com /1 month ago

Chinese-Speaking APT Deploys New TinyRCT Backdoor in Southeast Asia Campaign

A Chinese-speaking advanced persistent threat (APT) actor has been linked to a new custom backdoor called TinyRCT as part of cyber attacks aimed at government entities and critical...

Read source
thehackernews.com /2 weeks ago

Suspected China-Nexus Hackers Use Fake Indian Tax Filing Utility to Deploy DcRAT

A suspected China-nexus threat activity cluster has been observed targeting Indian taxpayers, tax professionals, and corporate finance teams to deliver a remote access trojan desig...

Read source
thehackernews.com /1 month ago

China-Linked TA4922 Expands Phishing Attacks to U.K., Germany, Italy, and South Africa

A new China-linked cybercrime group known as TA4922 has expanded its targeting focus to target European organizations in the U.K., Germany, Italy, and South Africa. These efforts...

Read source
hackread.com /1 month ago

China-Linked TA4922 Hackers Target UK, Europe With New SilentRunLoader Malware

Proofpoint says TA4922, a suspected China aligned cybercrime group, is targeting UK and European organisations with tax, payroll and benefits themed malware campaigns.

Read source
thehackernews.com /2 weeks ago

China-Linked UAT-7810 Expands ORB Network With New LONGLEASH Malware

A Chinese threat actor tracked as UAT-7810 is actively refining its bespoke malware to expand its Operational Relay Box (ORB) network by breaking into internet-facing networking de...

Read source
cybersecuritynews.com /1 month ago

CL-STA-1062 Hackers Use TinyRCT Backdoor to Target Southeast Asian Governments

A Chinese-speaking threat group known as CL-STA-1062 has been running a quiet but aggressive campaign against government agencies and critical energy infrastructure across Southeas...

Read source
thehackernews.com /2 weeks ago

New MODBEACON RAT Uses gRPC Streaming for Encrypted C2 Traffic

The China-linked cybercrime group known as Silver Fox has been attributed to a new Rust-based remote access trojan (RAR) called MODBEACON. Chinese cybersecurity company QiAnXin sa...

Read source
gbhackers.com /1 month ago

Chinese-Speaking Hackers Deploy TinyRCT Backdoor Against Critical Energy Infrastructure

A Chinese-speaking threat cluster tracked as CL-STA-1062 has deployed a newly discovered .NET backdoor, TinyRCT, in targeted campaigns against government and critical energy infras...

Read source
gbhackers.com /1 month ago

China-Linked Espionage Cluster Deploys Custom ASPX/ASHX Shells on IIS

A previously disclosed China-linked threat cluster, tracked as OP-512, has been observed deploying a purpose-built web shell framework to compromise Internet Information Services (...

Read source
thehackernews.com /1 month ago

WinRAR Flaw Exploited by Russia-Aligned Groups to Deploy Stealers in Ukraine

Two Russia-aligned cyber attack campaigns have continued to exploit a security flaw in WinRAR to target Ukrainian organisations, almost a year after patches for the vulnerability w...

Read source
thehackernews.com /2 days ago

Fake Notepad++ Plugin Delivers MATCHBOIL.V2 in UAC-0099 Attacks

The Computer Emergency Response Team of Ukraine (CERT-UA) has warned of a new campaign that involves the use of a malicious program that's dressed up as a Notepad++ plugin to compr...

Read source
thehackernews.com /1 month ago

UNC3753 Used Vishing and Physical Intrusions in U.S. Data Theft Extortion Campaign

Cybersecurity researchers have disclosed details of a financially motivated data theft extortion campaign that has targeted dozens of organizations across professional, legal, and...

Read source
thehackernews.com /3 days ago

China-Nexus JadeProx Uses New TriBack Loader in Government and Healthcare Attacks

An exposed Alibaba Cloud server has revealed a China-nexus operation that Group-IB tracks as JadeProx. The cluster has targeted government, healthcare, and education organizations...

Read source
gbhackers.com /3 weeks ago

ValleyRAT Uses RC4 Encryption, Donut Shellcode, and rundll32 Injection for Stealth

A recent surge in ValleyRAT activity that combines RC4-encrypted payloads, Donut-generated shellcode, and in-memory execution via suspended rundll32 processes to evade detection. F...

Read source
thehackernews.com /1 month ago

Fake Microsoft Alerts Used to Deploy North Korean NarwhalRAT Malware

The North Korean state-sponsored hacking group known as ScarCruft (aka APT37) has been observed using spear-phishing messages impersonating Microsoft Account security notifications...

Read source
gbhackers.com /3 days ago

New TriBack Loader Evades EDR Using Signed Binaries and Win32 Callback APIs

A new shellcode loader, dubbed “TriBack Loader,” to a China-nexus intrusion cluster tracked as JadeProx, with the malware explicitly engineered to evade modern EDR by abusing signe...

Read source
cybersecuritynews.com /1 month ago

New GIFTEDCROOK Chain Abuses WinRAR ADS and Reflective Loading to Steal Browser Data

A newly documented attack chain tied to threat actor group UAC-0226 is putting Windows users at serious risk. The campaign uses booby-trapped WinRAR archives, hidden file streams,...

Read source
thehackernews.com /1 month ago

China-Aligned Groups Ramp Up Attacks: Dragon Weave Hits Czech Republic & Taiwan

A new cyber espionage campaign codenamed Operation Dragon Weave has been observed targeting officials and citizens in the Czech Republic and Taiwan to deliver an AdaptixC2 agent....

Read source
cybersecuritynews.com /1 month ago

UNC3753 Attacking US Law Firms Using Vishing and RMM Tools to Exfiltrate Data

A sophisticated cybercriminal group known as UNC3753 has been running an aggressive campaign against US law firms since early 2026, using phone calls, screen-sharing tricks, and re...

Read source
infosecurity-magazine.com /2 weeks ago

China-Linked APT Expands Proxy Network With New Malware

Cisco Talos said China-linked APT UAT-7810 is growing its proxy relay network with new malware

Read source
cybersecuritynews.com /1 month ago

SHEETCREEP C# RAT Abuses Google Sheets API as C2 to Target Diplomatic Organizations

A newly identified remote access trojan named SHEETCREEP is making headlines for its clever use of Google Sheets as a hidden communication channel between attackers and infected ma...

Read source
cybersecuritynews.com /1 month ago

New China-Linked Threat Cluster OP-512 Targets IIS Servers With Cryptographically Unique Web Shell Framework

A newly identified threat cluster with suspected ties to China has been caught targeting Internet Information Services (IIS) web servers using a purpose-built web shell framework....

Read source
thehackernews.com /1 month ago

New Threat Cluster OP-512 Targets Microsoft IIS Servers with Custom Web Shell Framework

Cybersecurity researchers have discovered a previously unreported threat cluster dubbed OP-512 (where "OP" stands for "opponent") that has been observed targeting Microsoft Interne...

Read source

Turn fresh research into a full content calendar

Use SocialBu to discover ideas, generate post drafts, and schedule them across your social channels.

Sources covering Apt37

cybersecuritynews.com

Recent coverage from public sources
Public source

feeds.feedburner.com

Recent coverage from public sources
Public source

gbhackers.com

Recent coverage from public sources
Public source

hackread.com

Recent coverage from public sources
Public source

infosecurity-magazine.com

Recent coverage from public sources
Public source