Latest updates for Apt37

Fresh curated links around APT37 are collected here so marketers can spot useful updates and turn timely ideas into posts faster.

Recent items include:

  • Chinese-Speaking APT Deploys New TinyRCT Backdoor in Southeast Asia Campaign
  • Suspected China-Nexus Hackers Use Fake Indian Tax Filing Utility to Deploy DcRAT
  • China-Linked UAT-7810 Expands ORB Network With New LONGLEASH Malware

Post angles to try

Share the most useful takeaway for your audience.
Turn one article into a quick practical checklist.
Ask your audience how this shift affects their work.
Turn angles into scheduled posts

Fresh articles and ideas

Recent curated links from global sources. Generate one free draft from any story, then use SocialBu to schedule and refine your content calendar.

thehackernews.com /1 month ago

Chinese-Speaking APT Deploys New TinyRCT Backdoor in Southeast Asia Campaign

A Chinese-speaking advanced persistent threat (APT) actor has been linked to a new custom backdoor called TinyRCT as part of cyber attacks aimed at government entities and critical...

Read source
thehackernews.com /1 month ago

Suspected China-Nexus Hackers Use Fake Indian Tax Filing Utility to Deploy DcRAT

A suspected China-nexus threat activity cluster has been observed targeting Indian taxpayers, tax professionals, and corporate finance teams to deliver a remote access trojan desig...

Read source
thehackernews.com /1 month ago

China-Linked UAT-7810 Expands ORB Network With New LONGLEASH Malware

A Chinese threat actor tracked as UAT-7810 is actively refining its bespoke malware to expand its Operational Relay Box (ORB) network by breaking into internet-facing networking de...

Read source
thehackernews.com /1 week ago

SilverFox Targets Japanese Manufacturer with 3-Driver BYOVD Chain and ValleyRAT

The Chinese cybercrime group known as Silver Fox has been observed using new drivers as part of bring your own vulnerable driver (BYOVD) attacks targeting a Japanese organization i...

Read source
cybersecuritynews.com /1 month ago

CL-STA-1062 Hackers Use TinyRCT Backdoor to Target Southeast Asian Governments

A Chinese-speaking threat group known as CL-STA-1062 has been running a quiet but aggressive campaign against government agencies and critical energy infrastructure across Southeas...

Read source
thehackernews.com /1 month ago

New MODBEACON RAT Uses gRPC Streaming for Encrypted C2 Traffic

The China-linked cybercrime group known as Silver Fox has been attributed to a new Rust-based remote access trojan (RAR) called MODBEACON. Chinese cybersecurity company QiAnXin sa...

Read source
gbhackers.com /1 month ago

Chinese-Speaking Hackers Deploy TinyRCT Backdoor Against Critical Energy Infrastructure

A Chinese-speaking threat cluster tracked as CL-STA-1062 has deployed a newly discovered .NET backdoor, TinyRCT, in targeted campaigns against government and critical energy infras...

Read source
thehackernews.com /6 days ago

QuickFox Supply Chain Attack Delivers FDMTP Backdoor via Trojanized Windows Installer

Cybersecurity researchers have disclosed what has been described as a "long-standing supply chain attack" on QuickFox, a virtual private network (VPN) and network acceleration tool...

Read source
thehackernews.com /2 weeks ago

Fake Notepad++ Plugin Delivers MATCHBOIL.V2 in UAC-0099 Attacks

The Computer Emergency Response Team of Ukraine (CERT-UA) has warned of a new campaign that involves the use of a malicious program that's dressed up as a Notepad++ plugin to compr...

Read source
thehackernews.com /2 weeks ago

China-Nexus JadeProx Uses New TriBack Loader in Government and Healthcare Attacks

An exposed Alibaba Cloud server has revealed a China-nexus operation that Group-IB tracks as JadeProx. The cluster has targeted government, healthcare, and education organizations...

Read source
thehackernews.com /1 week ago

Chinese Hacker Commands DeepSeek via Telegram to Launch Autonomous Attacks

Palo Alto Networks' Unit 42 says a Chinese-speaking threat actor used DeepSeek through the open-source Hermes Agent framework to launch attacks autonomously. After an initial Tele...

Read source
gbhackers.com /1 month ago

ValleyRAT Uses RC4 Encryption, Donut Shellcode, and rundll32 Injection for Stealth

A recent surge in ValleyRAT activity that combines RC4-encrypted payloads, Donut-generated shellcode, and in-memory execution via suspended rundll32 processes to evade detection. F...

Read source
thehackernews.com /1 month ago

Fake Microsoft Alerts Used to Deploy North Korean NarwhalRAT Malware

The North Korean state-sponsored hacking group known as ScarCruft (aka APT37) has been observed using spear-phishing messages impersonating Microsoft Account security notifications...

Read source
gbhackers.com /2 weeks ago

New TriBack Loader Evades EDR Using Signed Binaries and Win32 Callback APIs

A new shellcode loader, dubbed “TriBack Loader,” to a China-nexus intrusion cluster tracked as JadeProx, with the malware explicitly engineered to evade modern EDR by abusing signe...

Read source
cybersecuritynews.com /1 month ago

New GIFTEDCROOK Chain Abuses WinRAR ADS and Reflective Loading to Steal Browser Data

A newly documented attack chain tied to threat actor group UAC-0226 is putting Windows users at serious risk. The campaign uses booby-trapped WinRAR archives, hidden file streams,...

Read source
thehackernews.com /2 weeks ago

Cruciferra Crypter Uses BYOVD and Process Ghosting to Hide Windows Malware

The China-linked cybercrime group behind the use of income tax-related phishing lures targeting Indian taxpayers, tax professionals, and corporate finance teams has been observed u...

Read source
thehackernews.com /1 week ago

Flying Eagle Android RAT Traces Found on 170 Servers as Source Code Circulates

Source code for the Flying Eagle Android remote access trojan (RAT) framework is circulating through criminal Telegram channels. Hunt.io and independent researcher NetAskari traced...

Read source
cofense.com /1 week ago

The Evolution of Remote Access Tool Abuse: From Single Payloads to Multi-Stage Campaigns

Threat actors are increasingly abusing legitimate remote access tools (RATs) such as ConnectWise, GoTo, Datto RMM, and SimpleHelp in multi-stage phishing campaigns, using one trust...

Read source
infosecurity-magazine.com /1 month ago

China-Linked APT Expands Proxy Network With New Malware

Cisco Talos said China-linked APT UAT-7810 is growing its proxy relay network with new malware

Read source
thehackernews.com /1 day ago

China-Linked Hackers Deploy New StormEncryptor Ransomware, Likely via N-central Flaw

Microsoft has disclosed that Storm-1175, a financially motivated threat actor linked to China, has deployed a previously undocumented ransomware strain called StormEncryptor. The...

Read source
gbhackers.com /2 weeks ago

Chinese Hackers Use RedRelay Multi-Hop Network to Conceal Global Cyber Operations

Chinese state-linked hackers are increasingly relying on a covert multi-hop infrastructure dubbed RedRelay (also known as ORBWEAVER) to mask the origins of global cyber operations,...

Read source
infosecurity-magazine.com /1 week ago

Russian-Alligned TA488 Returns With Persistent Outlook Web Access Attack

TA488 returned with OWA half-click exploit deploying OWAReaper implant that survived re-imaging

Read source
thehackernews.com /3 weeks ago

ACR Stealer Uses ClickFix Lures to Steal Browser Tokens and Microsoft 365 Files

ACR Stealer, an infostealer in circulation since 2024, is walking out of enterprise networks with saved browser passwords, live session tokens, PDFs, Microsoft 365 documents, and f...

Read source
gbhackers.com /1 month ago

Fancy Bear Uses LSB Steganography and Reflective Loading to Run C# Remote-Control Trojan

A new intrusion campaign attributed to APT‑C‑20 (aka Fancy Bear, APT28) demonstrates the group’s continued refinement of stealthy, fileless techniques: weaponized Office documents...

Read source

Turn fresh research into a full content calendar

Use SocialBu to discover ideas, generate post drafts, and schedule them across your social channels.

Sources covering Apt37

cofense.com

Recent coverage from public sources
Public source

cybersecuritynews.com

Recent coverage from public sources
Public source

feeds.feedburner.com

Recent coverage from public sources
Public source

gbhackers.com

Recent coverage from public sources
Public source

infosecurity-magazine.com

Recent coverage from public sources
Public source