daily cyber × ai intelligence

index

tagged

[bitter-apt]

2 editions · 2 items

June 27, 2026

  • Bitter APT (APT-C-08) is hitting maritime and government officials with a .accdr file disguised as a PDF: AutoExec VBA fires on open, decodes payloads in memory via MSXML2, side-loads a DLL through signed fsquirt.exe, and plants a 17-minute scheduled task masquerading as a Chrome updater that pipes C2 responses straight into cmd.exe. The DLL runs TLS-callback anti-analysis and WMI/BIOS VM checks before fetching stage two. Nextron Research · Threat Activity

in Amazon Q Coding Assistant Hijacked Through Malicious MCP Configs as Washington Starts Gating Frontier Models Customer-by-Customer