Skip to content

Topic

State-Sponsored Cyber Espionage

Campaigns attributed to nation-state actors targeting technology, finance, chemical and government organisations for intelligence collection.

Current stories

securityConfirmed6 publishers

US offers $10 million for Hafnium suspect Zhang Yu after his alleged partner's extradition

State Department offers $10 million for information on the whereabouts of Zhang Yu, a Shanghai company director charged in the Hafnium hacking campaign. The bounty keeps the US case against two named men moving years after June 2021, when the indictment says the charged intrusions ended.

Perspective Coverage

6 publishers
Builder
Builder 14%
Operator
Operator 81%
Investor
Investor 5%

Reality

Evidence72
Adoption
Insufficient
Hype gap+15
Incentives55
Confidence70
securityOne report1 publisher

Unit 42 ties fake coding challenges from Dubai Airports to an Iranian campaign in Iraq

Palo Alto's Unit 42 says an Iranian state-aligned actor it tracks as CL-STA-1178 posed as the Dubai Airports IT department to deliver trojanized coding challenges to high-value targets. Its report ties attacks other vendors reported one at a time into one campaign that hit Iraqi critical infrastructure in March 2026.

Reality

Evidence50
Adoption
Insufficient
Hype gap+15
Incentives60
Confidence45
securityConfirmed3 publishers

China-nexus UAT-11587 runs its Antino backdoor through Outlook and OneDrive

Cisco Talos links China-nexus UAT-11587 to 16 affected or targeted institutions in eight Asian countries, via a backdoor run through Microsoft 365. Its commands move through Outlook and OneDrive via Microsoft Graph, so defenders have no command server to block.

Perspective Coverage

3 publishers
Builder
Builder 32%
Operator
Operator 63%
Investor
Investor 5%

Reality

Evidence62
Adoption30
Hype gap+8
Incentives
Insufficient
Confidence65
securityConfirmed7 publishers

Mabna Institute case re-upped with 17 defendants, this time during a war with Iran

Prosecutors added eight names to a 2018 indictment over 31.5 terabytes of stolen academic work. The target set has not changed: professors' mailboxes and university libraries.

Perspective Coverage

7 publishers
Builder
Builder 13%
Operator
Operator 69%
Investor
Investor 18%

Reality

Evidence70
Adoption
Insufficient
Hype gap+15
Incentives40
Confidence70
securityConfirmed3 publishers

Insikt Group traces six months of Word macro lures on three governments to GRU's BlueDelta

The new backdoor, HOOKEDGE, is a Windows batch script that beacons to a free webhook.site endpoint. Insikt Group calls the BlueDelta attribution moderate confidence, resting on overlap with the older HEADLACE implant.

Perspective Coverage

3 publishers
Builder
Builder 27%
Operator
Operator 68%
Investor
Investor 5%

Reality

Evidence60
Adoption
Insufficient
Hype gap+15
Incentives35
Confidence60
securityConfirmed5 publishers

DPRK operators compiled their backdoor into the victim's own HAProxy build

Rapid7 says the ted backdoor is built into the victim's existing HAProxy 2.8.12 and hooks its filter API, so the load balancer keeps balancing normally while it logs cookies and injects scripts for selected clients.

Perspective Coverage

5 publishers
Builder
Builder 42%
Operator
Operator 53%
Investor
Investor 5%

Reality

Evidence70
Adoption10
Hype gap+20
Incentives35
Confidence66
securityOne report1 publisher

Salt Typhoon logged into telecom network gear with stolen credentials in all but one case Talos examined

Salt Typhoon used legitimate stolen credentials to reach Cisco devices in every telecom intrusion Cisco Talos investigated but one. It then pulled more logins from weakly encrypted router configs and captured TACACS and RADIUS keys, so credentials stored on network gear are the first exposure for defenders to close.

Reality

Evidence62
Adoption
Insufficient
Hype gap−5
Incentives55
Confidence60