Chinese spies suspected of 'moonlighting' as tawdry ransomware crooks
ID: 65c5e53b-df0e-531b-ade4-306d09323146
STIX ID: report--65c5e53b-df0e-531b-ade4-306d09323146
Feed Name: The Register (Security)
Threat Score
Symantec researchers observed a China-linked espionage group (Mustang Panda/Mustang Panda aliases) exploit a Palo Alto Networks authentication bypass (CVE-2024-0012) in late November to steal admin credentials and Veeam-held AWS S3 credentials, exfiltrate sensitive data, and deploy RA World ransomware demanding $2M; the intruders used a custom PlugX backdoor tied to prior Mustang Panda operations and later resumed espionage targeting government ministries.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
