Earth Lusca Operation FishMedley espionage campaign
Campaign
Summary
Hide ▲
Show ▼
A multi-country espionage campaign tied to Earth Lusca / FishMonger is now linked to Operation FishMedley, a January–October 2022 effort that reached seven organizations across Taiwan, Hungary, Turkey, Thailand, France, and the U.S. The campaign matters because it shows coordinated targeting across multiple countries rather than a single isolated intrusion. The operation also reinforces the group's repeatable access and follow-on activity against government and organizational targets.
Related Happenings
Russian FSB Center 16 router intrusion campaign
Campaign
H score40
First: 13.07.2026 12:32
Last: 13.07.2026 12:32
Sources 1
About this happening:
A Russian FSB Center 16 campaign is targeting vulnerable and poorly configured routers to infiltrate critical infrastructure networks, raising the risk of device takeo...
Russian FSB Center 16 router intrusion campaign
CampaignAbout this happening: A Russian FSB Center 16 campaign is targeting vulnerable and poorly configured routers to infiltrate critical infrastructure networks, raising the risk of device takeo...
Scattered Spider reclassified as a decentralized collective of independent clusters
Threat Actor Meta
H score26
First: 07.07.2026 17:00
Last: 07.07.2026 17:00
Sources 1
About this happening:
Scattered Spider has been reclassified as a decentralized cybercrime collective, changing how its persistence and resilience are understood. The shift suggests independe...
Scattered Spider reclassified as a decentralized collective of independent clusters
Threat Actor MetaAbout this happening: Scattered Spider has been reclassified as a decentralized cybercrime collective, changing how its persistence and resilience are understood. The shift suggests independe...
Operation Escaneo Latin America intrusion campaign targeting government and finance
Campaign
H score57
First: 18.06.2026 14:30
Last: 18.06.2026 14:30
Sources 1
About this happening:
The Operation Escaneo campaign exposed a coordinated intrusion effort against government and financial targets across Latin America, with confirmed victim access and d...
Operation Escaneo Latin America intrusion campaign targeting government and finance
CampaignAbout this happening: The Operation Escaneo campaign exposed a coordinated intrusion effort against government and financial targets across Latin America, with confirmed victim access and d...
FishMonger multi-country government espionage campaign
Campaign
H score33
First: 16.06.2026 17:30
Last: 16.06.2026 17:30
Sources 1
About this happening:
FishMonger ran a multi-country espionage campaign against government bodies in Honduras, Taiwan, Thailand and Pakistan across 2023 and 2024. The activity point...
FishMonger multi-country government espionage campaign
CampaignAbout this happening: FishMonger ran a multi-country espionage campaign against government bodies in Honduras, Taiwan, Thailand and Pakistan across 2023 and 2024. The activity point...
SprySOCKS Windows backdoor activity against government organizations
Malware Activity
H score23
First: 16.06.2026 12:00
Last: 16.06.2026 12:00
Sources 1
How related:
Cybersecurity researchers have flagged two previously undocumented Windows variants of what was believed to be a Linux-only backdoor called SprySOCKS.
About this happening:
SprySOCKS now has documented Windows variants, WIN_DRV and WIN_PLUS, expanding a toolset first known as a Linux-only backdoor. The activity is tied to govern...
SprySOCKS Windows backdoor activity against government organizations
Malware ActivityHow related: Cybersecurity researchers have flagged two previously undocumented Windows variants of what was believed to be a Linux-only backdoor called SprySOCKS.
About this happening: SprySOCKS now has documented Windows variants, WIN_DRV and WIN_PLUS, expanding a toolset first known as a Linux-only backdoor. The activity is tied to govern...
Timeline
-
16.06.2026 12:44 2 articles · 29d ago
Earth Lusca Operation FishMedley espionage campaign
Initial DisclosureOperation FishMedley is the earliest named multi-country campaign thread tied to Earth Lusca / FishMonger in this event set. Its first documented phase runs from January to October 2022 and covers seven organizations across Asia, Europe, and the U.S.
Show sources
- China-Linked SprySOCKS Backdoor Expands to Windows with Driver-Based Stealth — thehackernews.com — 16.06.2026 12:44
- China-Linked SprySOCKS Backdoor Expands to Windows with Driver-Based Stealth — thehackernews.com — 16.06.2026 12:44