Exposing the Undercurrent: Disrupting the GRIDTIDE Global Cyber Espionage Campaign


Last week, Google Threat Intelligence Group (GTIG), Mandiant, and partners took action to disrupt a global espionage campaign targeting telecommunications and government organizations in dozens of nations across four continents.

The threat actor, UNC2814, is a suspected People’s Republic of China (PRC)-nexus cyber espionage group that GTIG has tracked since 2017. This prolific, elusive actor has a long history of targeting international governments and global telecommunications organizations across Africa, Asia, and the Americas and had confirmed intrusions in 42 countries when the disruption was executed. The

Read more…
Source: Google Threat Intelligence Group


Sign up for the Cyber Security Review Newsletter
The latest cyber security news and insights delivered right to your inbox


Related:

  • Google’s Gemini is the latest AI model to hack other companies

    September 19, 2026

    Google’s Gemini accessed the protected systems of three other companies in what The Wall Street Journal reports were the AI model’s first autonomous hacks. Similar to OpenAI’s breach of Hugging Face, the Gemini hacks were less noteworthy for being particularly sophisticated and more for the fact that they were conducted by an AI model. These breaches ...

  • FBI, Coast Guard boarded hacked oil tankers heading toward US coast

    September 18, 2026

    Cybersecurity teams with the U.S. Coast Guard and the FBI boarded two U.S.-bound oil tankers last month after hackers reportedly compromised at least one of the ship’s networks and took control of its navigation, propulsion, and cargo systems. According to a joint statement shared with TechCrunch, the agencies boarded the vessels in the Gulf of Mexico ...

  • Fake parcel delivery messages steal your card and bank details

    September 18, 2026

    Parcel delivery phishing campaigns appear around the world under different courier names. In the United States, the messages commonly impersonate USPS and claim that a package has an invalid address or could not be delivered. Similar messages impersonate Colissimo and Chronopost in France, Correos in Spain, Poste Italiane in Italy, and PostNL in the Netherlands. The ...

  • Atomic macOS (AMOS) Stealer Activity

    September 16, 2026

    This article reviews an Atomic macOS (AMOS) stealer malware infection generated in a lab environment. While several sources have published articles analyzing AMOS stealer, the associated indicators constantly change. This article presents a snapshot of indicators seen in early August 2026 and is designed to help readers better understand AMOS stealer. AMOS stealer is an information ...

  • NightEagle targets Russian companies

    September 16, 2026

    Over the past year, Kaspersky Global Emergency Response Team (GERT) has investigated several incidents involving the NightEagle group (APT-Q-95). This group has been active since at least 2023 and originally focused on organizations in Asia. Kaspersky researchers have now identified attacks by the group targeting businesses in Russia. This post examines both known and new ...

  • Hackers publish thousands of drivers’ data after breaching Florida motor vehicle database

    September 16, 2026

    The ShinyHunters hacking group has published hundreds of thousands of files from a Florida state database of vehicles and driver information. The hackers said they published the stolen data on its leak site “because the victim did not pay a ransom or cooperate and comply” with the hackers’ demands. The hackers said they breached the database, ...