logo

Hackers deployed new malware against university in Taiwan

ID: 4b37e330-c015-5e5b-ade8-cec5d5203162

STIX ID: report--4b37e330-c015-5e5b-ade8-cec5d5203162

Feed Name: The Record from Recorded Future News

Threat Score
65/100

Date Published: 2024-08-20

Date Updated: 2026-05-01

...
...

Researchers discovered a new backdoor named Msupedge used in an attack on a Taiwanese university that likely exploited CVE-2024-4577 in PHP to achieve remote code execution; the malware uses DNS tunneling for stealthy command-and-control, and multiple actors have been observed scanning for the vulnerability. The report also references contemporaneous campaigns attributed to suspected Chinese state-sponsored groups (RedJuliett, APT41) and highlights the challenge of detecting DNS-based C2 traffic.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.