Alexis Rapin

@alexis-rapin.bsky.social

Strategic Cyber Threat Intelligence Analyst @esetresearch.bsky.social // Research Fellow at Chaire Raoul-Dandurand en études stratégiques et diplomatiques (UQAM) // At the confluence of cyber & geopolitics

I’ll say it again: Russia hacked Poland’s energy infrastructure in the dead of winter. And NATO’s answer (6 months later) has been a joint attribution and a bunch of sanctioned individuals. Highly unusual attack, awfully normal answer. They’ll keep probing, because they don’t see any pushback.

Alexander Martin@alexmartin.bsky.social · 4d ago

Poland’s cybersecurity authorities have revealed that a previously unknown cyberattack disrupted systems at a combined heat and power plant during last winter’s cold snap, threatening to leave tens of thousands of people exposed to freezing weather.

Des groupes de hackers affiliés à l’Iran ont visé des stations de traitement des eaux dans 7 États 🇺🇸 dans les derniers jours (une trentaine juste au Minnesota…). Teheran veut montrer qu’ils peuvent, eux aussi, toucher le sol américain à leur manière. www.wired.com/story/securi...

7 States’ Water Systems Hit by Cyberattacks Likely Tied to Iran

Plus: The FBI eyes AI-powered tech to detect future crimes, Russia charges Telegram’s founder, xAI sues to stop a state’s “nudification” ban, and the Democrats learn a lesson about getting scammed.

wired.com

Sur le cas Xenia Fedorova: je saisis cette belle occasion pour republier ce bijou d’enquête *publié en 2019*. Tout était déjà exposé on ne peut plus clairement. Encore une fois: n’ont pas vu que ceux qui ne voulaient pas voir. www.vanityfair.fr/pouvoir/medi...

Enquête sur RT, la chaîne russe qui bouscule les médias français

À la faveur de la crise des Gilets jaunes, une mystérieuse chaîne russe s'est imposée parmi les premiers médias de France sur Internet. Sa recette ? Montrer que tout va pour le pire en Occident.

vanityfair.fr

And cyberespionage plays a significant role in it. Every month or so, our APT research team sees China-aligned hackers groups target organizations active in the semiconductor industry (especially in Taiwan 🇹🇼). And you can tell it is a persistent, well-targeted, cross-group effort.

The Wall Street Journal@wsj.com · 3w ago

Behind closed doors, China is directing a feverish campaign to catch up to U.S. chips and win the AI war. www.wsj.com/world/china/...

I am 6 again, and Fantasia’s Mickey Mouse loses control of the enchanted brooms he tasked with carrying water. Except this time, Mickey has lobbyists all across D.C. to make sure no one keeps the sorcerer’s apprentice in check. 🧙‍♂️🧹🪣 www.bbc.com/news/article...

OpenAI says its AI went rogue and launched 'unprecedented' cyber-attack

It is one of the first publicly disclosed cyber-attacks carried out by AI without direct human involvement.

bbc.com

What people need to understand is that 🇨🇳 is way past trying to influence who becomes president. They’re interested in congressional & state-level races. They’re interested in candidates of Chinese descent, etc. It’s about cultivating influence from the ground up. www.usatoday.com/story/news/p...

Trump Chinese election meddling statement faces skepticism. Here's why

President Donald Trump made many allegations in his address on election integrity. Experts, former U.S. intelligence officials are skeptical.

usatoday.com

What people need to understand is that 🇨🇳 is way past trying to influence who becomes president. They’re interested in congressional & state-level races. They’re interested in candidates of Chinese descent, etc. It’s about cultivating influence from the ground up. www.usatoday.com/story/news/p...

Trump Chinese election meddling statement faces skepticism. Here's why

President Donald Trump made many allegations in his address on election integrity. Experts, former U.S. intelligence officials are skeptical.

usatoday.com

Bottomline: after a 6 months wait, a joint attribution and a bunch of sanctioned individuals. That’s an awfully normal response to a worryingly unusual attack, if you ask me. What message do we think that sends? What Stringer Bell would call « a 40-degree day ». therecord.media/russia-blame...

Russia's FSB blamed for Poland grid attack as UK and EU impose first joint cyber sanctions

The allies blamed Center 16, the FSB’s signals intelligence arm, for acts of attempted cyber sabotage targeting Poland’s energy sector and water treatment facilities, alongside “a wide range of malici...

therecord.media

« An investigation by Dutch intelligence services revealed that the Russian operation targeted cameras on doorbells installed along military transport routes, in order to determine which weapons were being delivered to Kyiv ». unn.ua/en/amp/russi...

Russia spied on NATO military bases through doorbell cameras in search of weapons for Ukraine - Dutch intelligence | УНН

УНН War in Ukraine ✎ Russian hackers gained access to doorbell cameras to monitor the transportation of military equipment to Ukraine.

unn.ua

« An investigation by Dutch intelligence services revealed that the Russian operation targeted cameras on doorbells installed along military transport routes, in order to determine which weapons were being delivered to Kyiv ». unn.ua/en/amp/russi...

Russia spied on NATO military bases through doorbell cameras in search of weapons for Ukraine - Dutch intelligence | УНН

УНН War in Ukraine ✎ Russian hackers gained access to doorbell cameras to monitor the transportation of military equipment to Ukraine.

unn.ua

Le groupe hacktiviste pro-🇷🇺 NoName057(16), connu pour ses nombreux DDoS, a vu un 3e de ses membres être arrêté – en Espagne. Il était aussi membre de Cyber Army of Russia Reborn (CARR). Les 2 groupes ont été formellement associés au GRU par la justice US fin 2025. www.theregister.com/security/202...

Spain collars alleged pro-Russia hacktivist after FBI tip-off

Palencia man suspected of links to CARR, Z-Pentest, and NoName057(16), plus helping a Ukrainian hacker flee to Russia

theregister.com

Et ça s’étend très largement au cyber-espace: notre équipe observe très fréquemment les groupes de hackers affiliés au renseignement biélorusse cibler des organisations de la diaspora en Pologne. La répression transnationale ne vient pas que de la Chine et de l’Iran. www.la-croix.com/internationa...

En Pologne, les espions étrangers sèment la terreur parmi les communautés biélorusse et ukrainienne du pays

Une recrudescence des activités d’espionnage a conduit les autorités polonaises à arrêter toute une série de suspects ces derniers jours. Le 15 juin 2026, un caricaturiste russe a même été assassiné e...

la-croix.com

An Iranian hacker affiliated with the IRGC has been arrested in Montenegro and now faces extradition to the 🇺🇸. Not the 1st time this would happen, but still quite notable. A reminder that state-sponsored hackers must choose their holiday destination carefully… www.reuters.com/world/monten...

Montenegro police, FBI arrest Iranian wanted by US for hacking

Montenegrin police and the U.S. Federal Bureau of Investigation arrested an Iranian national suspected ​of hacking attacks that damaged U.S. infrastructure to ‌the tune of $3.4 billion, Montenegrin po...

reuters.com

Il y a 2 ans, discussion avec un ami qui affirme (à regret) que « la Russie ne peut pas être battue ». Je rétorque que si l’🇺🇦 reçoit 1000 Storm Shadow par mois et tape les raffineries chaque nuit, dans la durée, Moscou va finir par flancher. On y est pas (encore), mais on voit la logique à l’œuvre…

NOELREPORTS@noelreports.com · 2mo ago

Fuel supply disruptions are spreading across Russia, with shortages reported in Moscow, Tyumen, Buryatia and multiple other regions. Russia is quickly turning into a big parking lot. #Russia

If one APT group has adopted « move fast and break things » as their motto, that’s Gamaredon: we documented 35 distinct phishing campaigns of the group in 2025, *all targeting Ukraine 🇺🇦 *. A new ESET Research blog about our old friends from FSB Center 18. www.welivesecurity.com/en/eset-rese...

Gamaredon in 2025: Leveraging tunnels, workers, dead drops, and new alliances

ESET Research analyzes Gamaredon’s new toolset and the group’s growing reliance on legitimate online services to hide its C&C infrastructure and exfiltrate stolen data.

welivesecurity.com

Is the idea of APT groups as unitary, monolithic entities (a PLA unit, an MSS bureau) still viable? When it comes to China, maybe not so much. Cool paper discussing the new ecosystem of 🇨🇳 cyber operations and its complex mesh of contractors, fronts, quartermaster etc. bindinghook.com/understandin...

Understanding modern Chinese cyber operations means shifting from ‘APT’ to composite responsibility

Cyber operations today can include anything from PLA units to companies acting independently, and often include a mix of actors, complicating attribution and response

bindinghook.com

The (in)famous Vietnamese APT group OceanLotus is back, with a campaign that targeted stock buyers via a compromised investment app. We suspect this operation was part of the 🇻🇳 government’s ongoing crusade against corruption and financial crime.

ESET Research@esetresearch.bsky.social · 2mo ago

#ESETresearch has discovered a supply-chain attack targeting stock investors in Vietnam, distributing SPECTRALVIPER through the update mechanism of the FireAnt Metakit stock investment platform. www.welivesecurity.com/en/eset-rese... 1/4

Considérant que le renseignement 🇩🇪 a mis en garde contre le recrutement chinois via LinkedIn dès 2017, les 🇺🇸 et la 🇫🇷 dès 2018, je serai curieux de savoir ce qui précipite ce communiqué conjoint maintenant… (Spoiler: je soupçonne qu’un des 5 Eyes s’en est fait passer une)

The Washington Post@washingtonpost.com · 2mo ago

Breaking news: The U.S. and other nations in the Five Eyes intelligence partnership — the U.K., Canada, Australia and New Zealand — jointly warned that China is using LinkedIn and other platforms to pry secret information from security professionals.

Back in 2022, I participated in a research project where (among other things) we warned about the potential use of sexually explicit deepfakes for foreign interference purposes. Back then, some readers felt our scenario was a bit far-fetched. 4 years later… 👇🏼 www.newsweek.com/for-exposing...

Women who expose China's repression are targeted by deepfake AI porn

Many female activists who take on China are targeted by deepfake porn campaigns. Some are pushing back by publicizing the images.

newsweek.com

Our new APT Activity Report is out, highlighting some cyber espionage campaigns we’ve observed in recent months. Among the interesting stories: - FamousSparrow (🇨🇳-aligned) targeting the Venezuelan gov. just after US raid - Andariel (🇰🇵) targeting an engineering company involved in the nuclear sector

ESET Research@esetresearch.bsky.social · 3mo ago

#ESETresearch released its latest APT Activity Report (Oct 2025–Mar 2026): 🇨🇳China-aligned groups focused on Venezuela, Gulf states, and AI & robotics industry in 🇰🇷South Korea, while 🇰🇵North Korea-aligned APTs targeted the nuclear sector. Full report: web-assets.esetstatic.com/wls/en/paper...

Entirely possible, but on the other hand, few people realize how much the baddies hack their supposed friends on a regular basis. China hacks 🇷🇺, Russia hacks all central Asia, North Korea hacks 🇨🇳… Ideological alignment rarely means mutual trust for these guys. www.theguardian.com/politics/202...

Nigel Farage’s Russian hack claim ‘without any merit’, former NCSC chief says

Ciaran Martin says Reform UK leader’s allegation over Guardian report on £5m gift ‘entirely unsubstantiated’

theguardian.com