Curated cybersecurity briefings on active threats, vulnerabilities, and emerging risks
Daily Cybersecurity Briefing (19 December 2025)
Published: Loading…
At a Glance
- North Korean cyber operations dominated the day, with Chainalysis attributing $2.02 billion in 2025 cryptocurrency thefts to DPRK-linked groups including Lazarus and Kimsuky.
- China-aligned actors drove parallel risk, as LongNosedGoblin targeted Southeast Asian and Japanese governments while exploiting Windows Group Policy and a Cisco AsyncOS zero-day.
- Actively exploited vulnerabilities expanded, including React2Shell (CVE-2025-55182), SonicWall SMA 1000 zero-days, and HPE OneView CVE-2025-37164 enabling unauthenticated RCE.
- Credential abuse and modern phishing surged through OAuth device code attacks against Microsoft 365 and password spraying on Cisco and Palo Alto VPNs.
- Supply-chain and third-party exposure persisted, with ASUS Live Update backdoored (CVE-2025-59374) and Mixpanel-linked breaches impacting PornHub and SoundCloud.
Summary
North Korean-linked activity remained a dominant theme, spanning both financial crime and espionage. Lazarus Group and Kimsuky were tied to record cryptocurrency thefts totalling $2.02 billion in 2025, alongside new BeaverTail and Android DocSwap malware campaigns. Amazon also confirmed blocking 1,800 suspected DPRK operatives attempting to secure remote tech jobs to generate overseas revenue.
China-aligned espionage activity intensified through exploitation and stealthy persistence. The newly identified LongNosedGoblin group targeted government networks in Southeast Asia and Japan using Group Policy abuse and custom malware, while a China-linked actor actively exploited a Cisco AsyncOS zero-day affecting Secure Email Gateway appliances. These campaigns showed sustained focus on governmental and communications infrastructure.
Exploited vulnerabilities and rapid weaponisation featured heavily across enterprise environments. React2Shell (CVE-2025-55182) was compromised within 48 hours and later used in ransomware delivery, while SonicWall SMA 1000 zero-days were chained for root-level access. HPE OneView CVE-2025-37164, rated CVSS 10.0, exposed infrastructure management systems to unauthenticated remote code execution.
Credential-based intrusions increasingly bypassed traditional controls through modern authentication abuse. Large-scale OAuth device code phishing campaigns targeted Microsoft 365 users, enabling account takeover without password theft, while automated password spraying hit Cisco SSL VPN and Palo Alto GlobalProtect gateways. ClickFix-style lures also delivered StealC infostealers and Qilin ransomware.
Supply-chain and third-party compromise continued to drive broad impact. ASUS Live Update was added to CISA’s KEV list after confirmation of an embedded backdoor (CVE-2025-59374), and third-party analytics provider Mixpanel exposure affected PornHub and SoundCloud users. Additional breaches struck healthcare and education sectors, including NHS supplier DXS and the University of Sydney.
Today’s selected highlights expand on DPRK infrastructure mapping, LongNosedGoblin espionage activity, Kimsuky QR-code malware, Mixpanel-linked breaches at PornHub and SoundCloud, Stealka infostealer distribution, OAuth device phishing, and GhostPairing WhatsApp account hijacking.
Highlights of the Day
Research Maps Active North Korean Cyber Infrastructure
Joint research by Acronis TRU and Hunt.io has uncovered previously unlinked infrastructure used by North Korean state-backed groups Lazarus and Kimsuky across multiple global campaigns. The investigation found consistent reuse of open directories, credential-theft toolkits, tunnelling infrastructure, and digital certificates, revealing stable operational patterns despite changing malware. These overlaps highlight how different DPRK-linked groups continue to share tools and infrastructure across espionage and financially motivated operations.
Third-Party Breach Exposes Data at PornHub and SoundCloud
PornHub and SoundCloud disclosed data breaches linked to unauthorised access via third-party and ancillary service platforms, exposing limited user information. PornHub said analytics data was accessed through Mixpanel without affecting payment systems, while SoundCloud reported that roughly 20% of its users had email addresses and public profile data accessed. The incidents underline how security failures at connected services can impact large consumer platforms simultaneously.
Kimsuky Spreads Android Malware Through QR Code Lures
Researchers have identified a Kimsuky-linked campaign distributing malicious Android apps via phishing sites that redirect victims using QR codes. The malware, an updated variant of the DOCSWAP family, installs a hidden remote access trojan capable of surveillance, credential theft, and persistent control. Analysis found shared infrastructure, Korean-language artefacts, and overlapping phishing techniques tying the activity to the North Korean threat group.
New China-Linked APT Targets Governments in Asia
ESET researchers have identified a previously unknown China-aligned threat group, dubbed LongNosedGoblin, conducting cyberespionage against government entities in Southeast Asia and Japan. Active since at least 2023, the group uses custom .NET malware and abuses Windows Group Policy for deployment and lateral movement, while relying on cloud services such as OneDrive and Google Drive for command and control. The findings suggest tool sharing among China-linked actors and highlight continued focus on regional governmental networks.
Finance Sector Hit by Cloud and Edge Attacks
A Darktrace report finds financial institutions facing intensified cyber activity targeting cloud platforms, edge infrastructure, and legacy systems, with phishing, credential theft, and VPN exploitation remaining common entry points. Researchers observed increased use of adversary-in-the-middle and QR code phishing techniques to bypass multi-factor authentication, alongside ransomware and supply chain attacks linked to groups such as Cl0p and Lazarus. The analysis also highlights growing exposure from rapid AI adoption and persistent risks tied to third-party software.
VPN Extensions Secretly Collect and Sell AI Chats
Research from Koi Security reveals that several widely used browser extensions, including Urban VPN Proxy, silently captured and monetised users’ conversations with AI platforms such as ChatGPT, Claude, and Gemini. The data collection, enabled by default since mid-2025, intercepted full prompts and responses and shared them with affiliated data brokers despite privacy-focused branding and “featured” marketplace status. More than eight million users across Chrome and Edge extensions were affected.
Stealka Malware Hides Inside Game Cheats and Software Cracks
Kaspersky researchers have identified a new Windows infostealer, dubbed Stealka, distributed through fake game mods, cheats, and pirated software hosted on legitimate platforms such as GitHub and SourceForge. The malware steals browser data, credentials, and cryptocurrency wallet information, and can also deploy crypto-mining components on infected systems. Analysis shows Stealka targets a wide range of browsers, applications, and extensions, expanding its reach beyond gaming-focused victims.
GhostPairing Scam Hijacks WhatsApp Accounts Without Password Theft
Gen researchers have uncovered a WhatsApp account takeover campaign, dubbed GhostPairing, that tricks users into linking an attacker-controlled device through WhatsApp’s legitimate pairing feature. Victims are lured via messages from compromised contacts to fake pages imitating Facebook, where they are prompted to approve a device using a QR or numeric code. The technique grants attackers persistent access to messages and media without stealing passwords, SIMs, or authentication tokens.
Riot Vanguard Closes Pre-Boot Security Blind Spot
Riot Games has detailed updates to its Vanguard anti-cheat system aimed at addressing attacks that operate before the operating system loads. The changes focus on strengthening trust in early boot stages, including tighter validation of motherboard firmware and boot processes. Riot says the update targets sophisticated cheats that previously evaded detection by running below the OS level.
Daily Coverage