logo

Novel attack on Windows spotted in phishing campaign run from and targeting China

ID: 7b511d39-1949-52ee-8dd7-2d3ebd551419

STIX ID: report--7b511d39-1949-52ee-8dd7-2d3ebd551419

Feed Name: The Register (Security)

Threat Score
78/100

Date Published: 2024-09-02

Date Updated: 2026-04-26

Author: Simon Sharwood

...
...

Securonix researchers uncovered a covert phishing campaign called SLOW#TEMPEST targeting Chinese-speaking entities; attackers used zip attachments containing a malicious LNK that executed a renamed LicensingUI.exe to sideload a malicious dui70.dll (Cobalt Strike implant). The intruders deployed multiple post-exploitation tools for scanning, port forwarding, AD enumeration, credential theft, shellcode loading and exfiltration, maintained persistence and lateral movement for over two weeks, and used IPs hosted on Tencent cloud; no firm attribution was established.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.