Skip to main content

Google has dismantled infrastructure linked to a cyber group associated with attacks on dozens of organizations worldwide.

According to findings shared by the company’s threat intelligence team, the group targeted entities across multiple sectors in over 40 countries.

The attackers reportedly used cloud-based tools to blend malicious activity with routine network traffic, allowing them to conduct surveillance and data collection operations.

In response, Google worked with partners to shut down projects, disable accounts and block related infrastructure connected to the activity.

The operation highlights ongoing challenges in global cybersecurity and the evolving methods used in large-scale digital espionage campaigns.