Find notable cyber news and cases, enriched with sources, timelines, and signals.

Suspected China-linked Nezha-to-Gh0st RAT campaign

Campaign
First reported
Last updated
Happening score
H score 37
1 unique sources, 1 articles

Summary

Hide ▲

A China-linked intrusion campaign abused Nezha to deliver Gh0st RAT, giving the operators remote control over more than 100 victim machines across multiple countries. The activity was observed in August 2025 and used a multi-step chain that began with exposed web infrastructure. The scale and repeatable delivery flow make the operation a broad campaign, not a one-off compromise.

Related Happenings

GreyVibe AI-assisted cyberespionage campaign targeting Ukraine-linked organizations

Campaign
H score39 First: 29.05.2026 01:24 Last: 29.05.2026 01:24 Sources 1

About this happening: GreyVibe is running an AI-assisted cyberespionage campaign against Ukrainian and Ukraine-related organizations, expanding the threat to military, government, civilian,...

Glassworm botnet command-and-control disruption

Malware Activity
H score10 First: 27.05.2026 17:00 Last: 27.05.2026 17:00 Sources 1

About this happening: The Glassworm botnet had all four command-and-control channels disrupted, cutting operators off from infected machines and blocking new payload delivery. The infrastructur...

Webworm multi-country targeting campaign against government and enterprise victims

Campaign
H score38 First: 20.05.2026 15:51 Last: 20.05.2026 15:51 Sources 1

About this happening: Webworm is running a multi-country targeting campaign against government agencies and enterprises, expanding the risk of persistent access across several regions. The...

Webworm expanded European government and South Africa university espionage campaign

Campaign
H score24 First: 20.05.2026 14:30 Last: 20.05.2026 14:30 Sources 1

About this happening: Webworm expanded its 2025 espionage campaign into European government organizations and a university in South Africa, widening the cross-region targeting risk. The ope...

FamousSparrow Azerbaijanian oil-and-gas targeting campaign

Campaign
H score32 First: 13.05.2026 16:00 Last: 13.05.2026 16:00 Sources 1

About this happening: The China-linked FamousSparrow group ran a targeted cyberespionage campaign against an Azerbaijanian oil-and-gas company in the South Caucasus, highlighting a new...

Timeline

  1. 08.10.2025 16:56 2 articles · 9mo ago

    Suspected China-linked Nezha-to-Gh0st RAT campaign

    Initial Disclosure

    The intrusion began with log poisoning against a vulnerable phpMyAdmin panel, which let the operators drop a web shell. That foothold enabled server control through ANTSWORD before the wider malware chain was deployed.

    Show sources