Cyware Weekly Threat Intelligence, April 14–18, 2025

Weekly Threat Briefing • April 18, 2025
Weekly Threat Briefing • April 18, 2025
The U.S. is drawing a hard line on data outflows. The DOJ’s new Data Security Program aims to block foreign adversaries, specifically nations like China and Russia, from acquiring sensitive American data through commercial channels. SSL certificates are about to expire a lot faster. In a move to tighten digital trust, the CA/Browser Forum has approved a gradual reduction in certificate lifespans - from the current 398 days to just 47 by 2029.
One email, three stages, and no files to catch. Agent Tesla is being deployed through spam campaigns that use archive attachments with embedded JavaScript. They look like browser helpers, but they act like spyware. A set of 57 Chrome extensions have been found snooping on users. XorDDoS is now compromising Docker servers and deploying new features tied to a “VIP” variant. Most of the recent activity is hitting U.S. infrastructure.
UNC5174 is keeping a low profile, but its targets aren’t. Active since late 2024, the Chinese state-linked group has been compromising Linux systems using a malicious bash script that drops SNOWLIGHT malware and a fileless VShell RAT. A wine-tasting invite with a side of malware. APT29, the Russian state-aligned group, is targeting European diplomatic networks with phishing lures disguised as event announcements.