APT31 Russian IT sector cloud-services and phishing campaign
Campaign
Summary
Hide ▲
Show ▼
The APT31 campaign targeted the Russian IT sector from 2024 to 2025, using cloud services and phishing to evade detection and sustain espionage. The operation focused on contractors and integrators for government agencies and used legitimate services such as Yandex Cloud and Microsoft OneDrive for command and control and exfiltration. It also relied on CloudyLoader, social-media staging, and weekend or holiday timing to stay hidden for long periods.
Related Happenings
HeartlessSoul phishing and malvertising espionage campaign targeting aerospace firms and drone operators
Campaign
H score29
First: 11.05.2026 15:00
Last: 11.05.2026 15:00
Sources 1
About this happening:
The HeartlessSoul operation is using phishing and malvertising to target aerospace firms and drone operators, raising the risk of geospatial data theft from co...
HeartlessSoul phishing and malvertising espionage campaign targeting aerospace firms and drone operators
CampaignAbout this happening: The HeartlessSoul operation is using phishing and malvertising to target aerospace firms and drone operators, raising the risk of geospatial data theft from co...
UnsolicitedBooker Central Asian telecom phishing campaign
Campaign
H score31
First: 24.02.2026 11:54
Last: 24.02.2026 11:54
Sources 1
About this happening:
The UnsolicitedBooker cluster shifted its phishing operation to telecommunications companies in Kyrgyzstan and Tajikistan, extending a multi-month campaign that matters be...
UnsolicitedBooker Central Asian telecom phishing campaign
CampaignAbout this happening: The UnsolicitedBooker cluster shifted its phishing operation to telecommunications companies in Kyrgyzstan and Tajikistan, extending a multi-month campaign that matters be...
LongNosedGoblin cyber-espionage campaign targeting government entities in Southeast Asia and Japan
Campaign
H score33
First: 18.12.2025 19:34
Last: 18.12.2025 19:34
Sources 1
About this happening:
A LongNosedGoblin campaign is targeting governmental entities in Southeast Asia and Japan, creating a sustained risk of cyber espionage and file exfiltration insid...
LongNosedGoblin cyber-espionage campaign targeting government entities in Southeast Asia and Japan
CampaignAbout this happening: A LongNosedGoblin campaign is targeting governmental entities in Southeast Asia and Japan, creating a sustained risk of cyber espionage and file exfiltration insid...
APT24 BadAudio multi-delivery espionage campaign
Campaign
H score54
First: 21.11.2025 00:12
Last: 21.11.2025 00:12
Sources 1
About this happening:
APT24 is running a three-year espionage campaign with BadAudio that has expanded into multiple delivery methods, increasing the operation's reach and stealth. Since ...
APT24 BadAudio multi-delivery espionage campaign
CampaignAbout this happening: APT24 is running a three-year espionage campaign with BadAudio that has expanded into multiple delivery methods, increasing the operation's reach and stealth. Since ...
UNC1549 Middle East aerospace and defense intrusion campaign
Campaign
H score22
First: 18.11.2025 14:54
Last: 18.11.2025 14:54
Sources 1
About this happening:
UNC1549 is running a late 2023 through 2025 intrusion campaign against aerospace, aviation, and defense organizations in the Middle East, using third-party relations...
UNC1549 Middle East aerospace and defense intrusion campaign
CampaignAbout this happening: UNC1549 is running a late 2023 through 2025 intrusion campaign against aerospace, aviation, and defense organizations in the Middle East, using third-party relations...
Timeline
-
22.11.2025 17:19 2 articles · 7mo ago
APT31 Russian IT sector cloud-services and phishing campaign
Initial DisclosureThe first visible phase used legitimate cloud services such as Yandex Cloud to blend command-and-control and exfiltration traffic into ordinary activity. The operators also hid encrypted payloads in social media profiles and used weekend and holiday timing to reduce detection.
Show sources
- China-Linked APT31 Launches Stealthy Cyberattacks on Russian IT Using Cloud Services — thehackernews.com — 22.11.2025 17:19
- China-Linked APT31 Launches Stealthy Cyberattacks on Russian IT Using Cloud Services — thehackernews.com — 22.11.2025 17:19