this post was submitted on 26 Feb 2026
126 points (95.0% liked)

Technology

81933 readers
3264 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related news or articles.
  3. Be excellent to each other!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, this includes using AI responses and summaries. To ask if your bot can be added please contact a mod.
  9. Check for duplicates before posting, duplicates may be removed
  10. Accounts 7 days and younger will have their posts automatically removed.

Approved Bots


founded 2 years ago
MODERATORS
 
  • The Chocolate Factory announced the Google Threat Intelligence Group-led actions on Wednesday and said that, in partnership with other teams, it terminated all Google Cloud Projects that had been controlled by UNC2814, a group that GTIG has tracked since 2017. They also disabled all known UNC2814 infrastructure and accounts, and revoked access to the Google Sheets API calls used by the Chinese snoops for command-and-control (C2) purposes.
  • "As of Feb. 18, GTIG's investigation confirmed that UNC2814 has impacted 53 victims in 42 countries across four continents, and identified suspected infections in at least 20 more countries," the threat hunters said in the report.
  • The security sleuths uncovered this campaign during a Mandiant investigation into suspicious activity in a customer's environment. Specifically, this binary, "/var/tmp/xapt," initiated a shell with root privileges, and then executed a command to retrieve the system’s user and group identifiers to confirm it had successfully escalated to root.
  • Google suspects the payload was named xapt, after the command-line tool in Debian and Ubuntu systems, to make it easier to hide in the victim's environment and look like a legitimate tool.
  • The intruders also used a novel backdoor, Gridtide, that abuses legitimate Google Sheets API functionality to disguise its command-and-control (C2) traffic. Mandiant has linked Gridtide to UNC2814.
  • The intruders also used a novel backdoor, Gridtide, that abuses legitimate Google Sheets API functionality to disguise its command-and-control (C2) traffic. Mandiant has linked Gridtide to UNC2814.
  • After breaking in, the spies moved laterally via SSH, performed reconnaissance, escalated privileges, and then deployed the Gridtide backdoor using a command, "nohup ./xapt," that allows it to run even after the user closes the session.
  • "Subsequently, SoftEther VPN Bridge was deployed to establish an outbound encrypted connection to an external IP address," the threat intel team wrote. "VPN configuration metadata suggests UNC2814 has been leveraging this specific infrastructure since July 2018."
  • The C-based backdoor uses Google Sheets as its C2 platform, can execute shell commands, and can upload and download files. In this case, the attacker deployed Gridtide on an endpoint containing personal information - likely to identify and track persons of interest - including full name, phone number, date and place of birth, voter ID and national ID numbers.
you are viewing a single comment's thread
view the rest of the comments
[–] XLE@piefed.social 0 points 1 day ago (1 children)

This is how you can "tell"... its never about the conversation never about the point, just about winning some invisible game they're playing?

Literally what game are you playing right now? Never mind the point of this post, apparently you've devolved beyond that. What's your point?

[–] arnitbier@sh.itjust.works 0 points 1 day ago* (last edited 1 day ago) (1 children)

That your a intentionally placed comment farmer playing to whatever side pays you the most or an ideological comment farmer who works for a government likely highly supportive of the USA 👍

[–] XLE@piefed.social 0 points 1 day ago (1 children)

Using your metric: when you and your friend jumped into this thread to talk about a completely different topic, what should I assume about you?

[–] arnitbier@sh.itjust.works 0 points 1 day ago (1 children)

My friend? Oh right the innocent person you were psychologically abusing

[–] XLE@piefed.social 0 points 1 day ago (1 children)

According to your metrics, how abusive are you being?

I'm not DMing with you, buddy

[–] arnitbier@sh.itjust.works 0 points 1 day ago (1 children)

2 down votes in a few minutes buddy. There ain't no one reading this post that are that opinionated in the 2 minutes that took. So I threw some shade 😎

[–] XLE@piefed.social 0 points 1 day ago (1 children)

Ah I see. Disagreement is harassment, unless it involves calling someone nonhuman, then it's fine

And the upvotes are right, unless they're for the wrong person, and then they're fake.

Get well soon friend.

[–] arnitbier@sh.itjust.works 1 points 1 day ago* (last edited 19 hours ago)

No harassment is harassment, saying that they did shit they didn't do and said shit they didnt say is called gas-lighting and is defined as psychological abuse.

https://www.medicalnewstoday.com/articles/gaslighting

Also bot votes don't matter so I was pointing to that idea

"State-sponsored comment farms, often referred to as "troll farms," are organized groups that create and disseminate online comments and content to influence public opinion and manipulate discussions, typically in favor of government narratives. These operations are often linked to specific countries, such as Russia, where they employ paid commentators to spread disinformation across social media and forums."

https://spideraf.com/articles/the-rise-of-click-farms-and-their-impact-on-digital-advertising-and-online-engagement