China-linked cyber-spies infect Russian govt, IT sector
ID: 00307599-8057-50f3-bf92-23859dbef792
STIX ID: report--00307599-8057-50f3-bf92-23859dbef792
Feed Name: The Register (Security)
Kaspersky describes an ongoing targeted campaign named "EastWind," attributed to China-linked actors (APT27/APT31), that has infected dozens of Russian government agencies and IT providers since late July. Attackers gain initial access via phishing RAR attachments and deploy malicious libraries that use DLL sideloading to load backdoors which use cloud services (GitHub, Dropbox, Quora, LiveJournal, Yandex.Disk) as command-and-control; observed payloads include GrewApacha, CloudSorcerer and a newly observed implant dubbed PlugY, with similarities to the DRBControl backdoor.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
