China-linked Billbug hackers breached multiple entities in Southeast Asian country
ID: ebb9a4ec-b697-53af-a046-1cac38494d10
STIX ID: report--ebb9a4ec-b697-53af-a046-1cac38494d10
Feed Name: The Record from Recorded Future News
Symantec attributes a prolonged espionage campaign (Aug 2024–Feb 2025) in a Southeast Asian country to the Chinese APT group Billbug (Lotus Panda/Lotus Blossom/Bronze Elgin); attackers breached multiple high-profile targets including a government ministry, air traffic control, a telecom operator and a construction firm using custom credential stealers, backdoors and legitimate tools (including timestomping), and researchers note links to prior operations such as a compromise of a digital certificate authority.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
