logo

'China-aligned' spyware slingers operating since 2018 unmasked at last

ID: 8688210f-8fb8-5294-9b3a-20409c1f79a5

STIX ID: report--8688210f-8fb8-5294-9b3a-20409c1f79a5

Feed Name: The Register (Security)

Threat Score
85/100

Date Published: 2024-05-23

Date Updated: 2026-04-26

Author: Matthew Connatser

...
...

Bitdefender uncovered a long-running targeted campaign by a group dubbed Unfading Sea Haze, likely linked to Chinese interests, which used spear-phishing (ZIP attachments with LNK files) to deploy data-stealing malware (Gh0st RAT family, Ps2dllLoader) against at least eight government and military organizations since 2018; the actors evolved to in-memory execution via PowerShell and MSBuild, used scheduled tasks to load malicious DLLs for credential and browser data theft, and exfiltrated data over FTP (curl) — the report includes technical indicators and mitigation guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.