{"id":438,"date":"2018-05-11T08:10:21","date_gmt":"2018-05-11T08:10:21","guid":{"rendered":"https:\/\/packetstormsecurity.com\/news\/view\/28945\/Vigilante-Hacks-Government-Linked-Cyber-Espionage-Group.html"},"modified":"2018-05-11T08:10:21","modified_gmt":"2018-05-11T08:10:21","slug":"vigilante-hacks-government-linked-cyber-espionage-group","status":"publish","type":"post","link":"https:\/\/www.threatshub.org\/blog\/vigilante-hacks-government-linked-cyber-espionage-group\/","title":{"rendered":"Vigilante Hacks Government Linked Cyber Espionage Group"},"content":{"rendered":"<p>Somewhere, government-linked hackers might be panicking. A digital vigilante has struck back against what researchers believe is a cyberespionage group connected to a nation state. The hacker has allegedly stolen, rather ironically, a cache of data that the government-linked hackers lifted from their own victims across the Middle East.<\/p>\n<p>The news provides a rare instance of someone targeting a so-called advanced persistent threat, or APT, as well as an opportunity for a behind-the-scenes look at a government hacking campaign.<\/p>\n<p>\u201c10 minutes of effort; intel on Iranian APTs,\u201d the anonymous hacker told Motherboard in an online chat, saying which nation they believe may be linked to the hacking group. Some cybersecurity experts tentatively agreed. But Kaspersky, which originally reported on the hacking group it <a href=\"https:\/\/usa.kaspersky.com\/about\/press-releases\/2018_zoopark-new-android-based-malware\" target=\"_blank\">dubbed \u201cZooPark<\/a>\u201d earlier this month, told Motherboard it could not currently link the outfit to a known actor.<\/p>\n<p>The stolen data the hacker provided to Motherboard though is noteworthy. It includes text messages, emails, and GPS locations seemingly swept up by ZooPark\u2019s tools; audio recordings apparently captured by the malware of people speaking; and the hacker said they found another related server hosted in Tehran, Iran during their spree.<\/p>\n<p class=\"article__blockquote\"><strong><em>Got a tip? You can contact this reporter securely on Signal on +44 20 8133 5190, OTR chat on jfcox@jabber.ccc.de, or email joseph.cox@vice.com.<\/em><\/strong><\/p>\n<p>The hacker broke into a specific ZooPark server that was listed in Kaspersky\u2019s research\u2014the hacker then pasted their own message on to the ZooPark server, explaining how they allegedly carried out the hack, and <a href=\"https:\/\/web.archive.org\/web\/20180508063705\/http:\/\/5.61.27.157\/\" target=\"_blank\">pushed a copy to the Internet Archive<\/a> as proof.<\/p>\n<p>To corroborate the hacker\u2019s claim that the data was taken from a ZooPark server, Motherboard cross-referenced the stolen material with details in Kaspersky\u2019s recent report. Kaspersky\u2019s report said ZooPark had victims in Egypt, Jordan, Morocco, Lebanon, and Iran. Motherboard dug through the GPS coordinates provided by the hacker and found a heavy concentration of infected devices in Egypt and others in Iran. The report added that this was an Android hacking campaign; the data obtained by Motherboard includes sections naming the model of phones, and all appear to be different types of Android devices. Kaspersky\u2019s report said this particular version of ZooPark\u2019s malware was created in 2016; the earliest timestamp of an infected device in the data is from that same year, and stretches up to this month.<\/p>\n<div class=\"article__media\" readability=\"7\"><img decoding=\"async\" src=\"https:\/\/vice-web-statics-cdn.vice.com\/images\/blank.png\" alt=\"\" class=\"col-12-xs\" data-src=\"https:\/\/video-images.vice.com\/_uncategorized\/1525975480552-4626_ZooPark_infographic.png\"\/><\/p>\n<p>Caption: A Kaspersky infographic on the ZooPark group. Image: Kaspersky Lab.<\/p>\n<\/div>\n<p>Kaspersky\u2019s press release said ZooPark potentially targeted members of the United Nations Relief and Works Agency, based on the news topics that the group used to trick victims into installing the malware. And the report adds that one of the group\u2019s pieces of malware was delivered as a fake voting app in the independence referendum in Kurdistan. Notably, one infected device included in the data obtained by Motherboard visited Islamic State-related websites, but the context of why this person browsed those websites is unclear.<\/p>\n<p>Some of the intercepted text messages include verification codes for Instagram and Telegram accounts.<\/p>\n<p><strong>THE BREACH<\/strong><\/p>\n<p><a href=\"https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2018\/05\/03114450\/ZooPark_for_public_final_edit.pdf\" target=\"_blank\">Kaspersky\u2019s report<\/a> said ZooPark has used several different pieces of malware over the past few years. The third version of ZooPark\u2019s malware is based on Spymaster Pro, a piece of spyware that the ordinary consumer can purchase, perhaps for spying on their children, employees, or spouses, according to the report. ZooPark\u2019s version of Spymaster Pro lets an attacker record phone calls, monitor a phone\u2019s internet browsing, and steal photos too.<\/p>\n<p>Alexey Firsh, the security expert at Kaspersky Lab who authored the ZooPark report, said this version of the malware was delivered through so-called watering hole attacks; meaning the malware is pushed to a target once they visit a particular malicious website. Firsh said the malware came from <a href=\"http:\/\/alnaharegypt.com\/\" target=\"_blank\">alnaharegypt.com<\/a> and <a href=\"http:\/\/alhayatnews.com\/\" target=\"_blank\">alhayatnews.com<\/a>, two Arabic language sites, and although he didn\u2019t go into detail, said this particular strain of the malware was used to target \u201cemployers of international organizations.\u201d<\/p>\n<div class=\"article__media\" readability=\"7\"><img decoding=\"async\" src=\"https:\/\/vice-web-statics-cdn.vice.com\/images\/blank.png\" alt=\"\" class=\"col-12-xs\" data-src=\"https:\/\/video-images.vice.com\/_uncategorized\/1525975777511-message.png\"\/><\/p>\n<p>Caption: A section of the hacker&#8217;s message left on the ZooPark server. Image: Screenshot<\/p>\n<\/div>\n<p>In February, a hacker targeted Spymaster Pro and <a href=\"https:\/\/motherboard.vice.com\/en_us\/article\/7x77ex\/hacker-strikes-stalkerware-companies-stealing-alleged-texts-and-gps-locations-of-customers\" target=\"_blank\">provided the stolen data to Motherboard<\/a>. After seeing the Spymaster Pro connection to the Kaspersky research, that same hacker decided to probe ZooPark\u2019s infrastructure, the hacker told Motherboard in an online chat. The hacker claims they breached a ZooPark server listed in the report by uploading a malicious file, obtaining the server\u2019s administrator credentials, and then moving throughout the system.<\/p>\n<p>\u201cHacking back should be legalized so Kaspersky could of done this themselves,\u201d the hacker wrote in their message on the ZooPark server.<\/p>\n<p>In its press release, Kaspersky described ZooPark as a \u201csophisticated cyberespionage campaign.\u201d Although ZooPark did start using more sophisticated malware with its fourth version, the hacker who claims to have breached ZooPark suggests the APT is anything but advanced.<\/p>\n<p>\u201cI don\u2019t think these guys are APTs at all; LamePTs,\u201d the hacker said. \u201cCode reuse kills everyone in the end, if you want to be an APT dont be a fucking skid.\u201d<\/p>\n<p>READ MORE <a href=\"https:\/\/packetstormsecurity.com\/news\/view\/28945\/Vigilante-Hacks-Government-Linked-Cyber-Espionage-Group.html\">HERE<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>READ MORE HERE&#8230;<\/p>\n","protected":false},"author":2,"featured_media":439,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"colormag_page_layout":"default_layout","footnotes":""},"categories":[60],"tags":[320],"class_list":["post-438","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-packet-storm","tag-headlinehackergovernmentcyberwar"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.1 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Vigilante Hacks Government Linked Cyber Espionage Group 2026 | ThreatsHub Cybersecurity News<\/title>\n<meta name=\"description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.threatshub.org\/blog\/vigilante-hacks-government-linked-cyber-espionage-group\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Vigilante Hacks Government Linked Cyber Espionage Group 2026 | ThreatsHub Cybersecurity News\" \/>\n<meta property=\"og:description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.threatshub.org\/blog\/vigilante-hacks-government-linked-cyber-espionage-group\/\" \/>\n<meta property=\"og:site_name\" content=\"ThreatsHub Cybersecurity News\" \/>\n<meta property=\"article:published_time\" content=\"2018-05-11T08:10:21+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2018\/05\/vigilante-hacks-government-linked-cyber-espionage-group.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"16\" \/>\n\t<meta property=\"og:image:height\" content=\"9\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"TH Author\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@threatshub\" \/>\n<meta name=\"twitter:site\" content=\"@threatshub\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"TH Author\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"4 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/vigilante-hacks-government-linked-cyber-espionage-group\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/vigilante-hacks-government-linked-cyber-espionage-group\\\/\"},\"author\":{\"name\":\"TH Author\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\"},\"headline\":\"Vigilante Hacks Government Linked Cyber Espionage Group\",\"datePublished\":\"2018-05-11T08:10:21+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/vigilante-hacks-government-linked-cyber-espionage-group\\\/\"},\"wordCount\":849,\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/vigilante-hacks-government-linked-cyber-espionage-group\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2018\\\/05\\\/vigilante-hacks-government-linked-cyber-espionage-group.jpg\",\"keywords\":[\"headline,hacker,government,cyberwar\"],\"articleSection\":[\"Packet Storm\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/vigilante-hacks-government-linked-cyber-espionage-group\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/vigilante-hacks-government-linked-cyber-espionage-group\\\/\",\"name\":\"Vigilante Hacks Government Linked Cyber Espionage Group 2026 | ThreatsHub Cybersecurity News\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/vigilante-hacks-government-linked-cyber-espionage-group\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/vigilante-hacks-government-linked-cyber-espionage-group\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2018\\\/05\\\/vigilante-hacks-government-linked-cyber-espionage-group.jpg\",\"datePublished\":\"2018-05-11T08:10:21+00:00\",\"description\":\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/vigilante-hacks-government-linked-cyber-espionage-group\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/vigilante-hacks-government-linked-cyber-espionage-group\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/vigilante-hacks-government-linked-cyber-espionage-group\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2018\\\/05\\\/vigilante-hacks-government-linked-cyber-espionage-group.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2018\\\/05\\\/vigilante-hacks-government-linked-cyber-espionage-group.jpg\",\"width\":16,\"height\":9},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/vigilante-hacks-government-linked-cyber-espionage-group\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"headline,hacker,government,cyberwar\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/tag\\\/headlinehackergovernmentcyberwar\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"Vigilante Hacks Government Linked Cyber Espionage Group\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"name\":\"ThreatsHub Cybersecurity News\",\"description\":\"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"alternateName\":\"Threatshub.org\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\",\"name\":\"ThreatsHub.org\",\"alternateName\":\"Threatshub.org\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"width\":432,\"height\":435,\"caption\":\"ThreatsHub.org\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/threatshub\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\",\"name\":\"TH Author\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"caption\":\"TH Author\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Vigilante Hacks Government Linked Cyber Espionage Group 2026 | ThreatsHub Cybersecurity News","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.threatshub.org\/blog\/vigilante-hacks-government-linked-cyber-espionage-group\/","og_locale":"en_US","og_type":"article","og_title":"Vigilante Hacks Government Linked Cyber Espionage Group 2026 | ThreatsHub Cybersecurity News","og_description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","og_url":"https:\/\/www.threatshub.org\/blog\/vigilante-hacks-government-linked-cyber-espionage-group\/","og_site_name":"ThreatsHub Cybersecurity News","article_published_time":"2018-05-11T08:10:21+00:00","og_image":[{"width":16,"height":9,"url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2018\/05\/vigilante-hacks-government-linked-cyber-espionage-group.jpg","type":"image\/jpeg"}],"author":"TH Author","twitter_card":"summary_large_image","twitter_creator":"@threatshub","twitter_site":"@threatshub","twitter_misc":{"Written by":"TH Author","Est. reading time":"4 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.threatshub.org\/blog\/vigilante-hacks-government-linked-cyber-espionage-group\/#article","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/vigilante-hacks-government-linked-cyber-espionage-group\/"},"author":{"name":"TH Author","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476"},"headline":"Vigilante Hacks Government Linked Cyber Espionage Group","datePublished":"2018-05-11T08:10:21+00:00","mainEntityOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/vigilante-hacks-government-linked-cyber-espionage-group\/"},"wordCount":849,"publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/vigilante-hacks-government-linked-cyber-espionage-group\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2018\/05\/vigilante-hacks-government-linked-cyber-espionage-group.jpg","keywords":["headline,hacker,government,cyberwar"],"articleSection":["Packet Storm"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.threatshub.org\/blog\/vigilante-hacks-government-linked-cyber-espionage-group\/","url":"https:\/\/www.threatshub.org\/blog\/vigilante-hacks-government-linked-cyber-espionage-group\/","name":"Vigilante Hacks Government Linked Cyber Espionage Group 2026 | ThreatsHub Cybersecurity News","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/vigilante-hacks-government-linked-cyber-espionage-group\/#primaryimage"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/vigilante-hacks-government-linked-cyber-espionage-group\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2018\/05\/vigilante-hacks-government-linked-cyber-espionage-group.jpg","datePublished":"2018-05-11T08:10:21+00:00","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","breadcrumb":{"@id":"https:\/\/www.threatshub.org\/blog\/vigilante-hacks-government-linked-cyber-espionage-group\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.threatshub.org\/blog\/vigilante-hacks-government-linked-cyber-espionage-group\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/vigilante-hacks-government-linked-cyber-espionage-group\/#primaryimage","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2018\/05\/vigilante-hacks-government-linked-cyber-espionage-group.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2018\/05\/vigilante-hacks-government-linked-cyber-espionage-group.jpg","width":16,"height":9},{"@type":"BreadcrumbList","@id":"https:\/\/www.threatshub.org\/blog\/vigilante-hacks-government-linked-cyber-espionage-group\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.threatshub.org\/blog\/"},{"@type":"ListItem","position":2,"name":"headline,hacker,government,cyberwar","item":"https:\/\/www.threatshub.org\/blog\/tag\/headlinehackergovernmentcyberwar\/"},{"@type":"ListItem","position":3,"name":"Vigilante Hacks Government Linked Cyber Espionage Group"}]},{"@type":"WebSite","@id":"https:\/\/www.threatshub.org\/blog\/#website","url":"https:\/\/www.threatshub.org\/blog\/","name":"ThreatsHub Cybersecurity News","description":"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform","publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"alternateName":"Threatshub.org","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.threatshub.org\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.threatshub.org\/blog\/#organization","name":"ThreatsHub.org","alternateName":"Threatshub.org","url":"https:\/\/www.threatshub.org\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","width":432,"height":435,"caption":"ThreatsHub.org"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/threatshub"]},{"@type":"Person","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476","name":"TH Author","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","caption":"TH Author"}}]}},"_links":{"self":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/438","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/comments?post=438"}],"version-history":[{"count":0,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/438\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media\/439"}],"wp:attachment":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media?parent=438"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/categories?post=438"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/tags?post=438"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}