Cyber Command Armed Forces of the Philippines

Cyber Command Armed Forces of the Philippines One Cyber. One Command.

CYBER ALERT: FAKE ADOBE & ZOOM UPDATESCybersecurity researchers have uncovered an active campaign dubbed SMOKE , where a...
20/08/2026

CYBER ALERT: FAKE ADOBE & ZOOM UPDATES

Cybersecurity researchers have uncovered an active campaign dubbed SMOKE , where attackers use fake Adobe and Zoom updates, business documents, and other software-related lures to trick users into executing malicious files. The campaign ultimately installs ConnectWise ScreenConnect, a legitimate remote-management tool that is abused by attackers to establish persistent remote access to compromised computers.

This campaign demonstrates how cyber threats can hide behind familiar software, trusted cloud platforms, and seemingly routine workplace activities. A legitimate application can become a security risk when attackers manipulate users into installing or running it without authorization.

KEY FACTS
• The campaign is identified as SMOKE .
• Attackers use fake Adobe and Zoom update notifications as phishing lures.
• Business-related documents and system-maintenance themes are also used to deceive users.
• The attack chain can involve VBScript droppers, batch scripts, .NET executables, PowerShell, and malicious MSI files.
• Attackers abuse trusted services, including Dropbox and Cloudflare, to deliver or stage malicious content.
• Successful infections lead to the installation of ScreenConnect, allowing attackers to establish persistent remote access.
• Attackers may attempt to weaken security protections such as AMSI, SmartScreen, and Windows Defender.

MALICIOUS SOFTWARE AND TOOLS IDENTIFIED
• ScreenConnect – legitimate remote-management software abused to maintain persistent remote access to compromised systems.
• VBScript droppers – used to initiate the infection and download additional payloads.
• PowerShell payloads – used to retrieve and execute malicious code.
• Malicious .NET loaders/executables – used to stage and execute the next phase of the attack.
• Malicious MSI installers – used to install the ScreenConnect client.
• Batch scripts – used to modify security settings and facilitate ex*****on.
• cloudflared.exe – a legitimate Cloudflare utility observed being used as part of the attackers' infrastructure and tunneling activity.

WARNING SIGNS
• Unexpected Adobe, Zoom, or software-update notifications received through email or web pages.
• Links directing users to download updates from unfamiliar websites or file-sharing services.
• Unexpected MSI, EXE, BAT, VBScript, or other executable files attached to emails or documents.
• Requests to disable antivirus, SmartScreen, or other security controls.
• Unexpected User Access Control (UAC) administrator prompts during supposedly routine software updates.
• Appearance of an unfamiliar remote-management or remote-access application on a workstation.
• Suspicious PowerShell or cmd.exe activity following the opening of an email attachment or downloaded file.

RECOMMENDATIONS
• Never install software updates from unsolicited email links or attachments.
• Download updates only from the software vendor's official website or approved organizational repositories.
• Verify unexpected update requests with your IT or cybersecurity personnel.
• Restrict the ex*****on of untrusted MSI, EXE, BAT, and script files.
• Monitor and audit the authorized use of Remote Monitoring and Management (RMM) tools such as ScreenConnect.
• Monitor suspicious PowerShell and command-line activity.
• Maintain endpoint security controls and investigate attempts to disable or tamper with security protections.
• Enforce appropriate UAC and application-control policies to prevent unauthorized administrative actions.
Cyber attackers do not always use obviously malicious software or suspicious websites; they can disguise their activities as routine software updates and legitimate business processes. Think before you click, verify before you install, and report suspicious activity immediately, because one seemingly harmless update can provide attackers with persistent access to your system.













CYBER ALERT | TinyRCT Backdoor Powering Cyber Espionage in Southeast AsiaCybersecurity researchers have uncovered a soph...
12/08/2026

CYBER ALERT | TinyRCT Backdoor Powering Cyber Espionage in Southeast Asia

Cybersecurity researchers have uncovered a sophisticated cyber espionage campaign involving a Chinese-speaking Advanced Persistent Threat (APT) group deploying a newly discovered backdoor called TinyRCT against government and state-owned energy organizations in Southeast Asia. The malware enables attackers to remotely control compromised systems, steal sensitive files, capture screenshots, and maintain long-term access while avoiding detection. The campaign highlights the persistent threat posed by nation-state actors targeting critical infrastructure and emphasizes the importance of proactive cyber defense.

Key Facts
• Researchers attributed the activity to a Chinese-speaking threat cluster tracked as CL-STA-1062.
• The campaign primarily targets government agencies and state-owned energy organizations in Southeast Asia.
• Attackers utilize a newly identified custom backdoor named TinyRCT.
• TinyRCT enables remote command ex*****on, file theft, screenshot capture, and persistent remote access.
• The operation demonstrates characteristics commonly associated with long-term cyber espionage campaigns designed to gather intelligence while remaining hidden.

Red Flags to Watch For
• Unusual outbound connections to unfamiliar external servers.
• Unexpected remote command ex*****on or unauthorized administrative activities.
• Unknown processes running persistently in the background.
• Sudden creation or modification of scheduled tasks or startup entries.
• Suspicious file access or unexplained screenshot and data collection activities.
• Security tools generating repeated alerts for abnormal network behavior.

Recommendations
• Keep operating systems and applications fully patched and updated.
• Implement Endpoint Detection and Response (EDR) solutions to identify malicious activity.
• Continuously monitor network traffic for unusual outbound communications.
• Apply the principle of least privilege to reduce unauthorized access.
• Conduct regular threat hunting and log analysis to detect indicators of compromise.
• Strengthen multi-factor authentication (MFA) and network segmentation for critical systems.
• Educate personnel on cybersecurity best practices and reporting suspicious activity promptly.

Advanced Persistent Threats continue to evolve by deploying custom malware specifically designed to evade traditional security measures and maintain long-term access to targeted networks. Organizations must remain vigilant through layered security, continuous monitoring, and timely incident response to protect critical information and national infrastructure from emerging cyber threats.








07/08/2026

CYBER ALERT | ClickLock: A New macOS Malware That Tricks You Into Giving Away Your Password

A newly discovered macOS malware called ClickLock is targeting Apple users through deceptive social engineering techniques rather than exploiting software vulnerabilities.

Victims are lured into copying and pasting malicious commands into the Terminal through fake verification pages, after which the malware disables system functions, displays convincing fake password prompts, and pressures users into revealing their macOS login credentials.

Once successful, it can steal browser data, password manager information, cryptocurrency wallets, and even install a persistent backdoor for remote access.

Key Facts

• Threat Name: ClickLock Stealer

• Targets macOS devices.

• Relies on social engineering, not software exploits.

• Often begins with a fake Cloudflare verification or ClickFix webpage.

• Tricks users into copying and running malicious commands in Terminal.

• Displays a fake macOS login prompt to steal the user's password.

• Can steal:
o Browser credentials and cookies
o Password manager data
o Cryptocurrency wallet information
o Autofill and session data
o Basic system information

• Installs a persistent backdoor that allows attackers to regain access to the device.

Red Flags

• A website asks you to copy and paste commands into Terminal.

• Fake CAPTCHA or Cloudflare verification pages requesting Terminal access.

• Unexpected macOS password prompts appearing after running Terminal commands.

• Finder, Dock, Terminal, or other applications suddenly close repeatedly.

• Your Mac becomes difficult to use while repeatedly asking for your login password.

Recommendations

• Never copy and execute Terminal commands from unfamiliar websites.

• Verify that software downloads come only from trusted or official sources.

• Be suspicious of websites requiring Terminal commands as part of "verification."

• Keep macOS and security software updated.

If your Mac suddenly locks up with persistent password
prompts, do not enter your password. Force a shutdown by holding the power button, then restart in Safe Mode and inspect the system for compromise.

Cybercriminals continue to rely on human deception instead of technical exploits. ClickLock demonstrates that even secure operating systems can be compromised when users are persuaded to perform unsafe actions. Practicing good cyber hygiene, questioning unusual requests, and avoiding unknown Terminal commands remain your strongest defenses against modern cyber threats.








CYBER ALERT | ClickLock: A New macOS Malware That Tricks You Into Giving Away Your PasswordA newly discovered macOS malw...
31/07/2026

CYBER ALERT | ClickLock: A New macOS Malware That Tricks You Into Giving Away Your Password

A newly discovered macOS malware called ClickLock is targeting Apple users through deceptive social engineering techniques rather than exploiting software vulnerabilities. Victims are lured into copying and pasting malicious commands into the Terminal through fake verification pages, after which the malware disables system functions, displays convincing fake password prompts, and pressures users into revealing their macOS login credentials. Once successful, it can steal browser data, password manager information, cryptocurrency wallets, and even install a persistent backdoor for remote access.

Key Facts
•Threat Name: ClickLock Stealer
•Targets macOS devices.
•Relies on social engineering, not software exploits.
•Often begins with a fake Cloudflare verification or ClickFix webpage.
•Tricks users into copying and running malicious commands in Terminal.
•Displays a fake macOS login prompt to steal the user's password.
•Can steal:
‣Browser credentials and cookies
‣Password manager data
‣Cryptocurrency wallet information
‣Autofill and session data
‣Basic system information
•Installs a persistent backdoor that allows attackers to regain access to the device.

Red Flags
•A website asks you to copy and paste commands into Terminal.
•Fake CAPTCHA or Cloudflare verification pages requesting Terminal access.
•Unexpected macOS password prompts appearing after running Terminal commands.
•Finder, Dock, Terminal, or other applications suddenly close repeatedly.
•Your Mac becomes difficult to use while repeatedly asking for your login password.

Recommendations
•Never copy and execute Terminal commands from unfamiliar websites.
•Verify that software downloads come only from trusted or official sources.
•Be suspicious of websites requiring Terminal commands as part of "verification."
•Keep macOS and security software updated.
•If your Mac suddenly locks up with persistent password prompts, do not enter your password. Force a shutdown by holding the power button, then restart in Safe Mode and inspect the system for compromise.

Cybercriminals continue to rely on human deception instead of technical exploits. ClickLock demonstrates that even secure operating systems can be compromised when users are persuaded to perform unsafe actions. Practicing good cyber hygiene, questioning unusual requests, and avoiding unknown Terminal commands remain your strongest defenses against modern cyber threats.








Fostering Interoperability: Joint Operational Visit to the 950th CEWWThe Commander of Cyber Command, AFP, BGEN JOEY T FO...
28/07/2026

Fostering Interoperability: Joint Operational Visit to the 950th CEWW

The Commander of Cyber Command, AFP, BGEN JOEY T FONTIVEROS PA, together with the Acting Commander of Air Logistics Support Command, BGEN EDMON B GUPIT PAF, conducted a Joint Operational Visit to the 950th Cyberspace and Electronic Warfare Wing (950 CEWW) on 22 July 2026 at the Headquarters, 950 CEWW, CJVAB, Pasay City. The delegation was warmly received by the Wing Commander, BGEN FERNANDO G VENTURA PAF, who welcomed the visiting commanders and provided an overview of the unit's operational capabilities and ongoing initiatives.

Strengthening inter-service collaboration and advancing unified cyber and electronic warfare capabilities, the visit served as an opportunity to reinforce coordination between Cyber Command, the Air Logistics Support Command, and the 950 CEWW in support of the Armed Forces of the Philippines' mission to enhance cyberspace operations and electronic warfare readiness. Discussions focused on operational synchronization, capability development, and fostering greater interoperability to effectively address emerging threats in the increasingly complex cyber and electromagnetic domains.

The engagement reaffirmed the commitment of the participating commands to work closely in building a more resilient, adaptive, and mission-ready force. Through sustained collaboration and shared expertise, Cyber Command, the Air Logistics Support Command, and the 950th Cyberspace and Electronic Warfare Wing continue to reinforce the AFP's ability to safeguard national security and maintain operational excellence across the cyber and electronic warfare battlespace.







27/07/2026

CYBER ALERT | Cyber Hygiene: Your First Line of Defense in the Digital World

Just as washing your hands helps prevent illness, practicing good cyber hygiene helps protect your devices, accounts, and personal information from cyber threats. In the Philippines, where millions rely on online banking, e-wallets, social media, and digital government services every day, poor cyber hygiene can lead to identity theft, financial loss, and compromised personal data. Developing safe online habits is one of the simplest yet most effective ways to stay secure in today's connected world.

✅ Things to Do (Good Cyber Hygiene Practices):
1. Use strong and unique passwords for every account instead of reusing the same password.
2. Enable Multi-Factor Authentication (MFA) whenever it is available.
3. Keep your phone, laptop, and applications updated to receive the latest security patches.
4. Install trusted antivirus or endpoint protection software and keep it updated.
5. Verify emails, text messages, and links before clicking or downloading attachments.
6. Regularly back up important files to an external drive or secure cloud storage.
7. Connect only to trusted Wi-Fi networks or use a VPN when accessing sensitive information.
8. Download applications only from official app stores such as Google Play Store and Apple App Store.
9. Log out of accounts when using shared or public computers.
10. Regularly review account activity for unfamiliar logins or transactions.

Red Flags That Your Cyber Hygiene Needs Improvement:
⚠️ You use the same password for multiple accounts.
⚠️ You ignore software or operating system update notifications.
⚠️ You click links without checking who sent them.
⚠️ You frequently connect to free public Wi-Fi without protection.
⚠️ You install apps from unofficial websites or unknown sources.
⚠️ You receive unexpected login alerts or One-Time Password (OTP) requests.
⚠️ Your device suddenly becomes slow, overheats, or displays excessive pop-up advertisements.
⚠️ You notice unauthorized purchases or suspicious transactions in your online banking or e-wallet accounts.
⚠️ Friends tell you they received strange messages from your social media account.
⚠️ Your antivirus or device security has been disabled without your knowledge.

Recommendations:
✔️ Make cyber hygiene part of your daily routine—not just something you do after a cyber incident.
✔️ Change passwords immediately if you suspect an account has been compromised.
✔️ Turn on automatic updates for your devices and applications whenever possible.
✔️ Learn to recognize phishing attempts through emails, SMS, messaging apps, and social media.
✔️ Verify requests involving money, passwords, or sensitive information through official communication channels.
✔️ Review your privacy and security settings on your social media and online accounts regularly.
✔️ Report suspicious online activities, scams, or cyber incidents to the appropriate authorities or your organization's cybersecurity team.
✔️ Share cyber hygiene best practices with your family, friends, and colleagues to help build a more cyber-aware community.
Remember:

Cybersecurity starts with everyday habits. Every strong password created, every software update installed, and every suspicious link avoided helps create a safer digital environment for all Filipinos.

Strengthening Cyber Capability Through Allied Partnership | Train-the-Trainers on CybersecurityCyber Command, AFP succes...
27/07/2026

Strengthening Cyber Capability Through Allied Partnership | Train-the-Trainers on Cybersecurity

Cyber Command, AFP successfully concluded the Train-the-Trainers on Cybersecurity on 17 July 2026, following a two-week program conducted from 06 to 17 July 2026 in collaboration with the Australian Defence Force (ADF) through the Joint Australian Training Team-Philippines (JATT-P). Held at the IMCITE Room, C4ISTAR Training Center, CEISSAFP Compound, Camp Aguinaldo, Quezon City, the training reaffirmed the enduring partnership between the Philippines and Australia in advancing cybersecurity capability, professional military education, and interoperability.

As part of Australia's continuing commitment to supporting the Armed Forces of the Philippines, the Joint Australian Training Team-Philippines (JATT-P) offered a Mobile Training Team (MTT) to deliver the Cybersecurity Train-the-Trainer Program. The initiative aims to strengthen the AFP's institutional cybersecurity maturity through a sustainable train-the-trainer model, focusing on cybersecurity policy, governance, and risk management, while equipping participants with effective instructional design, training delivery techniques, and strategies for institutional implementation. The program was conducted in two iterations, reflecting Australia's sustained support in enhancing the AFP's operational capabilities while responding to the capability development priorities of the AFP and the Department of National Defense (DND).

The first phase of the training was facilitated by highly experienced instructors from the Australian Defence Force, who guided participants through comprehensive discussions and practical exercises on cybersecurity fundamentals, emerging cyber threats, defensive strategies, governance, risk management, and instructional methodologies. Through collaborative learning and the exchange of international best practices, participants enhanced both their technical competencies and their capacity to become future cybersecurity instructors within the AFP.

Building on the knowledge and skills acquired during the first iteration, the succeeding phase of the program reinforced key learning outcomes while providing participants with opportunities to apply and demonstrate effective instructional techniques. This approach ensured that participants were not only proficient in cybersecurity concepts but were also prepared to cascade the knowledge throughout their respective units, contributing to the AFP's long-term cyber capability development.

The successful completion of the Cybersecurity Train-the-Trainers Program marks another milestone in the growing defense cooperation between the Philippines and Australia. More importantly, it underscores the shared commitment of both nations to developing a resilient, adaptive, and highly capable cyber workforce prepared to safeguard the nation's digital battlespace against evolving cyber threats through continuous learning, collaboration, and institutional excellence.










The Cyber Command, Armed Forces of the Philippines extends its warmest congratulations to General Antonio G Nafarrete PA...
23/07/2026

The Cyber Command, Armed Forces of the Philippines extends its warmest congratulations to General Antonio G Nafarrete PA on his appointment as the 61st Chief of Staff of the Armed Forces of the Philippines.

In his words: "We shall build on the accomplishments and lessons of those who came before us."

We are confident that under your leadership, the Armed Forces of the Philippines will continue to grow stronger, more capable, and more united in fulfilling its mandate to protect the nation and serve the Filipino people.

The Cyber Command stands firmly committed to supporting your vision and advancing our shared mission of safeguarding the country across all domains, including cyberspace.

Congratulations, Sir, and may your leadership be guided with wisdom, courage, and unwavering dedication to service.


The Cyber Command, Armed Forces of the Philippines extends its deepest gratitude and warmest congratulations to General ...
23/07/2026

The Cyber Command, Armed Forces of the Philippines extends its deepest gratitude and warmest congratulations to General Romeo S Brawner Jr PA as he concludes his distinguished service as the 60th Chief of Staff of the Armed Forces of the Philippines.

As he aptly said: "Throughout my military career, I have learned that leadership is never about one person—it is about bringing good people together around a common purpose. It is about earning trust, taking care of your people, making difficult decisions when necessary, and always remembering that the privilege to lead is, first and foremost, a responsibility to serve."

Your vision, commitment, and steadfast leadership have inspired the Armed Forces and strengthened our mission in safeguarding the nation.

Thank you for your dedicated service, Sir.

The Cyber Command wishes you continued success, good health, and fulfillment in your future endeavors.

Congratulations on your well-earned retirement, and may God bless you always.


Address

Camp General Emilio Aguinaldo
Quezon City
1110

Alerts

Be the first to know and let us send you an email when Cyber Command Armed Forces of the Philippines posts news and promotions. Your email address will not be used for any other purpose, and you can unsubscribe at any time.

Shortcuts

Share

Category