CyberSecBrief

Curated cybersecurity briefings on active threats, vulnerabilities, and emerging risks


Daily Cybersecurity Briefing (19 December 2025)

Published: Loading…

At a Glance

  • North Korean cyber operations dominated the day, with Chainalysis attributing $2.02 billion in 2025 cryptocurrency thefts to DPRK-linked groups including Lazarus and Kimsuky.
  • China-aligned actors drove parallel risk, as LongNosedGoblin targeted Southeast Asian and Japanese governments while exploiting Windows Group Policy and a Cisco AsyncOS zero-day.
  • Actively exploited vulnerabilities expanded, including React2Shell (CVE-2025-55182), SonicWall SMA 1000 zero-days, and HPE OneView CVE-2025-37164 enabling unauthenticated RCE.
  • Credential abuse and modern phishing surged through OAuth device code attacks against Microsoft 365 and password spraying on Cisco and Palo Alto VPNs.
  • Supply-chain and third-party exposure persisted, with ASUS Live Update backdoored (CVE-2025-59374) and Mixpanel-linked breaches impacting PornHub and SoundCloud.

Summary

North Korean-linked activity remained a dominant theme, spanning both financial crime and espionage. Lazarus Group and Kimsuky were tied to record cryptocurrency thefts totalling $2.02 billion in 2025, alongside new BeaverTail and Android DocSwap malware campaigns. Amazon also confirmed blocking 1,800 suspected DPRK operatives attempting to secure remote tech jobs to generate overseas revenue.

China-aligned espionage activity intensified through exploitation and stealthy persistence. The newly identified LongNosedGoblin group targeted government networks in Southeast Asia and Japan using Group Policy abuse and custom malware, while a China-linked actor actively exploited a Cisco AsyncOS zero-day affecting Secure Email Gateway appliances. These campaigns showed sustained focus on governmental and communications infrastructure.

Exploited vulnerabilities and rapid weaponisation featured heavily across enterprise environments. React2Shell (CVE-2025-55182) was compromised within 48 hours and later used in ransomware delivery, while SonicWall SMA 1000 zero-days were chained for root-level access. HPE OneView CVE-2025-37164, rated CVSS 10.0, exposed infrastructure management systems to unauthenticated remote code execution.

Credential-based intrusions increasingly bypassed traditional controls through modern authentication abuse. Large-scale OAuth device code phishing campaigns targeted Microsoft 365 users, enabling account takeover without password theft, while automated password spraying hit Cisco SSL VPN and Palo Alto GlobalProtect gateways. ClickFix-style lures also delivered StealC infostealers and Qilin ransomware.

Supply-chain and third-party compromise continued to drive broad impact. ASUS Live Update was added to CISA’s KEV list after confirmation of an embedded backdoor (CVE-2025-59374), and third-party analytics provider Mixpanel exposure affected PornHub and SoundCloud users. Additional breaches struck healthcare and education sectors, including NHS supplier DXS and the University of Sydney.

Today’s selected highlights expand on DPRK infrastructure mapping, LongNosedGoblin espionage activity, Kimsuky QR-code malware, Mixpanel-linked breaches at PornHub and SoundCloud, Stealka infostealer distribution, OAuth device phishing, and GhostPairing WhatsApp account hijacking.

Highlights of the Day

Research Maps Active North Korean Cyber Infrastructure

Joint research by Acronis TRU and Hunt.io has uncovered previously unlinked infrastructure used by North Korean state-backed groups Lazarus and Kimsuky across multiple global campaigns. The investigation found consistent reuse of open directories, credential-theft toolkits, tunnelling infrastructure, and digital certificates, revealing stable operational patterns despite changing malware. These overlaps highlight how different DPRK-linked groups continue to share tools and infrastructure across espionage and financially motivated operations.

Third-Party Breach Exposes Data at PornHub and SoundCloud

PornHub and SoundCloud disclosed data breaches linked to unauthorised access via third-party and ancillary service platforms, exposing limited user information. PornHub said analytics data was accessed through Mixpanel without affecting payment systems, while SoundCloud reported that roughly 20% of its users had email addresses and public profile data accessed. The incidents underline how security failures at connected services can impact large consumer platforms simultaneously.

Kimsuky Spreads Android Malware Through QR Code Lures

Researchers have identified a Kimsuky-linked campaign distributing malicious Android apps via phishing sites that redirect victims using QR codes. The malware, an updated variant of the DOCSWAP family, installs a hidden remote access trojan capable of surveillance, credential theft, and persistent control. Analysis found shared infrastructure, Korean-language artefacts, and overlapping phishing techniques tying the activity to the North Korean threat group.

New China-Linked APT Targets Governments in Asia

ESET researchers have identified a previously unknown China-aligned threat group, dubbed LongNosedGoblin, conducting cyberespionage against government entities in Southeast Asia and Japan. Active since at least 2023, the group uses custom .NET malware and abuses Windows Group Policy for deployment and lateral movement, while relying on cloud services such as OneDrive and Google Drive for command and control. The findings suggest tool sharing among China-linked actors and highlight continued focus on regional governmental networks.

Finance Sector Hit by Cloud and Edge Attacks

A Darktrace report finds financial institutions facing intensified cyber activity targeting cloud platforms, edge infrastructure, and legacy systems, with phishing, credential theft, and VPN exploitation remaining common entry points. Researchers observed increased use of adversary-in-the-middle and QR code phishing techniques to bypass multi-factor authentication, alongside ransomware and supply chain attacks linked to groups such as Cl0p and Lazarus. The analysis also highlights growing exposure from rapid AI adoption and persistent risks tied to third-party software.

VPN Extensions Secretly Collect and Sell AI Chats

Research from Koi Security reveals that several widely used browser extensions, including Urban VPN Proxy, silently captured and monetised users’ conversations with AI platforms such as ChatGPT, Claude, and Gemini. The data collection, enabled by default since mid-2025, intercepted full prompts and responses and shared them with affiliated data brokers despite privacy-focused branding and “featured” marketplace status. More than eight million users across Chrome and Edge extensions were affected.

Stealka Malware Hides Inside Game Cheats and Software Cracks

Kaspersky researchers have identified a new Windows infostealer, dubbed Stealka, distributed through fake game mods, cheats, and pirated software hosted on legitimate platforms such as GitHub and SourceForge. The malware steals browser data, credentials, and cryptocurrency wallet information, and can also deploy crypto-mining components on infected systems. Analysis shows Stealka targets a wide range of browsers, applications, and extensions, expanding its reach beyond gaming-focused victims.

Source: Kaspersky

GhostPairing Scam Hijacks WhatsApp Accounts Without Password Theft

Gen researchers have uncovered a WhatsApp account takeover campaign, dubbed GhostPairing, that tricks users into linking an attacker-controlled device through WhatsApp’s legitimate pairing feature. Victims are lured via messages from compromised contacts to fake pages imitating Facebook, where they are prompted to approve a device using a QR or numeric code. The technique grants attackers persistent access to messages and media without stealing passwords, SIMs, or authentication tokens.

Riot Vanguard Closes Pre-Boot Security Blind Spot

Riot Games has detailed updates to its Vanguard anti-cheat system aimed at addressing attacks that operate before the operating system loads. The changes focus on strengthening trust in early boot stages, including tighter validation of motherboard firmware and boot processes. Riot says the update targets sophisticated cheats that previously evaded detection by running below the OS level.

Source: Riot Games

Daily Coverage

Developments
Dprk Crypto Theft SurgeReact2Shell ExploitationCisco Asyncos Zero-DaySonicwall Sma Attacks
Vulnerabilities
CVE-2025-14733Fireware Os 11.10.2 (Critical)CVE-2025-20393Cisco Is Aware Of A Potential Vulnerability.&Nbsp; Cisco Is Currently Investigating And&Nbsp;Will Update These Details As Appropriate&Nbsp;As More Information Becomes Available.CVE-2025-59374"Unsupported When Assigned" Certain Versions Of The Asus Live Update Client Were Distributed With Unauthorized Modifications Introduced Through A Supply Chain Compromise. The Modified Builds Could Cause Devices Meeting Specific Targeting Conditions To Perform Unintended Actions. Only Devices That Met These Conditions And Installed The Compromised Versions Were Affected. The Live Update Client Has Already Reached End-Of-Support (Eos) In October 2021, And No Currently Supported Devices Or Products…CVE-2025-37164Hpe Oneview (Critical)CVE-2025-55182A Pre-Authentication Remote Code Execution Vulnerability Exists In React Server Components Versions 19.0.0, 19.1.0, 19.1.1, And 19.2.0 Including The Following Packages: React-Server-Dom-Parcel, React-Server-Dom-Turbopack, And React-Server-Dom-Webpack. The Vulnerable Code Unsafely Deserializes Payloads From Http Requests To Server Function Endpoints.CVE-2025-68161The Socket Appender In Apache Log4J Core Versions 2.0-Beta9 Through 2.25.2 Does Not Perform Tls Hostname Verification Of The Peer Certificate, Even When The Verifyhostname Https://Logging.apache.org/Log4J/2.X/Manual/Appenders/Network.html#Sslconfiguration-Attr-Verifyhostname Configuration Attribute Or The Log4J2.Sslverifyhostname Https://Logging.apache.org/Log4J/2.X/Manual/Systemproperties.html#Log4J2.Sslverifyhostname System Property Is Set To True. This Issue May Allow A Man-In-The-Middle…CVE-2025-14492Superantispyware 10.0.1276 Free Edition (High)CVE-2025-14496Superantispyware 10.0.1276 Free Edition (High)CVE-2025-14493Superantispyware 10.0.1276 Free Edition (High)CVE-2025-14495Superantispyware 10.0.1276 Free Edition (High)
Threat Groups
KimsukyKimsuky is a North Koreabased cyber espionage group that has been active since at least 2012. The group initially targeted South Korean government agencies, think tanks, and subjectmatter experts in various fields. Its operations expanded to include the United Nations and organizations in the government, education, business services, and manufacturing sectors across the United States, Japan, Russia, and Europe. Kimsuky has focused collection on foreign policy and national security issues tied to the Korean Peninsula, nuclear policy, and sanctions. Its operations have overlapped with other DPRK actors, likely due to ad hoc collaboration or limited resource sharing. Because of overlapping operations, some researchers group a wide range of North Korean statesponsored cyber activity under the broader Lazarus Group umbrella rather than tracking separate subgroup or cluster distinctions. Kimsuky was assessed to be responsible for the 2014 Korea Hydro & Nuclear Power Co. compromise; other notable campaigns include Operation STOLEN PENCIL (2018), Operation Kabar Cobra (2019), and Operation Smoke Screen (2019). In 2023, Kimsuky was observed using commercial large language models to assist with vulnerability research, scripting, social engineering and reconnaissance.Lazarus GroupLazarus Group is a North Korean statesponsored cyber threat group attributed to the Reconnaissance General Bureau (RGB). Lazarus Group has been active since at least 2009 and is reportedly responsible for the November 2014 destructive wiper attack on Sony Pictures Entertainment, identified by Novetta as part of Operation Blockbuster. Malware used by Lazarus Group correlates to other reported campaigns, including Operation Flame, Operation 1Mission, Operation Troy, DarkSeoul, and Ten Days of Rain. North Korea’s cyber operations have shown a consistent pattern of adaptation, forming and reorganizing units as national priorities shift. These units frequently share personnel, infrastructure, malware, and tradecraft, making it difficult to attribute specific operations with high confidence. Public reporting often uses “Lazarus Group” as an umbrella term for multiple North Korean cyber operators conducting espionage, destructive attacks, and financially motivated campaigns.