Chinese APT Hackers Using Proxy and VPN Service to Anonymize Infrastructure
ID: a96adc90-b4e0-5531-a35c-99aa449b0c41
STIX ID: report--a96adc90-b4e0-5531-a35c-99aa449b0c41
Feed Name: cybersecurityNews.com
Threat Score
**Executive Summary:** Researchers report a sustained Chinese APT campaign that weaponized a zero-day Office RCE (CVE-2025-1234) to deploy a Go-based Trojan proxy which tunnels C2 and exfiltration through WgetCloud VPN exit nodes, leveraging wildcard TLS certificates (*.appletls.com) on ports 4000–4099 to evade detection and steal intellectual property from targets in South Korea and Taiwan.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
