Friday 26 June 2026 10:22:10 GMT+02:00

Netcrook

HomeManifesto
News
Techcrook
Geocrook
WikicrookTeamAppContact
EnglishItalianoArabic

#UNC1549


The Recruiter Trap Behind a Familiar Espionage Name

Published: 02 June 2026 10:23Category: Cyber Warfare & Nation-State OperationsAuthor: AGONY

A fake hiring site linked to Nimbus Manticore shows how job lures, impersonation, and cloud-friendly tradecraft can turn a simple message into a national-security risk.

Recruitment Became the Trap Door: Fake Job Lures Meet Malware Sideloading

Published: 02 June 2026 08:10Category: Cyber Warfare & Nation-State OperationsGeo: Middle East / IranAuthor: AGONY

A campaign tied to the Nimbus Manticore label shows how hiring themes can be turned into an execution path, using deception first and Windows loader abuse second.

When the Loader Betrays the App: A .NET Trick That Can Hide in Plain Sight

Published: 01 June 2026 16:28Category: Cyber Warfare & Nation-State OperationsGeo: Middle East / IranAuthor: AGONY

A campaign tied to Screening Serpens shows how AppDomainManager abuse can turn a trusted .NET startup path into an early-stage hiding place for malware.

Search Results Became the Bait in a New Software-Download Ambush

Published: 25 May 2026 12:23Category: Malware & BotnetsGeo: North America / USAAuthor: IRONQUERY

A lure built around SQL Developer shows how a threat cluster can turn user search intent into a delivery channel for malware, without relying on email at all.

Search Results as a Delivery Pipe: The Fake SQL Developer Lure Behind a New Poisoned-SEO Campaign

Published: 25 May 2026 10:24Category: Cyber Warfare & Nation-State OperationsGeo: Middle East / IranAuthor: AGONY

A suspected nation-state-linked operation used search manipulation and a fake developer tool as the bait, showing how software discovery can become the first step in compromise.

MiniUpdate, Big Message: How Cloud Hostnames Became Cover for a Spyware Run

Published: 25 May 2026 10:19Category: Cyber Warfare & Nation-State OperationsGeo: North America / USAAuthor: AGONY

Researchers linked a MiniUpdate RAT campaign to Azure-hosted command channels, showing how attackers can abuse cloud infrastructure to support espionage operations.