logo

Suspected Chinese gov’t hackers used ransomware as cover in attacks on Brazil presidency, Indian health org

ID: 96092cbf-08f9-5e51-8aff-85e93cba26a9

STIX ID: report--96092cbf-08f9-5e51-8aff-85e93cba26a9

Feed Name: The Record from Recorded Future News

Threat Score
85/100

Date Published: 2024-06-27

Date Updated: 2026-05-01

...
...

Researchers from SentinelOne, Recorded Future and TeamT5 report that suspected Chinese APT group ChamelGang has increasingly used ransomware (including CatB) against high-value targets — such as Brazil’s presidency and India’s AIIMS healthcare platform — to cause disruption, obscure espionage activity, and destroy evidence; the report also notes other clusters using BestCrypt/BitLocker and highlights deception and misattribution risks between law enforcement and intelligence communities.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.