logo

China-linked cyber-spies infect Russian govt, IT sector

ID: 00307599-8057-50f3-bf92-23859dbef792

STIX ID: report--00307599-8057-50f3-bf92-23859dbef792

Feed Name: The Register (Security)

Threat Score
85/100

Date Published: 2024-08-15

Date Updated: 2026-04-26

Author: Jessica Lyons

...
...

Kaspersky describes an ongoing targeted campaign named "EastWind," attributed to China-linked actors (APT27/APT31), that has infected dozens of Russian government agencies and IT providers since late July. Attackers gain initial access via phishing RAR attachments and deploy malicious libraries that use DLL sideloading to load backdoors which use cloud services (GitHub, Dropbox, Quora, LiveJournal, Yandex.Disk) as command-and-control; observed payloads include GrewApacha, CloudSorcerer and a newly observed implant dubbed PlugY, with similarities to the DRBControl backdoor.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.