'China-aligned' spyware slingers operating since 2018 unmasked at last
ID: 8688210f-8fb8-5294-9b3a-20409c1f79a5
STIX ID: report--8688210f-8fb8-5294-9b3a-20409c1f79a5
Feed Name: The Register (Security)
Bitdefender uncovered a long-running targeted campaign by a group dubbed Unfading Sea Haze, likely linked to Chinese interests, which used spear-phishing (ZIP attachments with LNK files) to deploy data-stealing malware (Gh0st RAT family, Ps2dllLoader) against at least eight government and military organizations since 2018; the actors evolved to in-memory execution via PowerShell and MSBuild, used scheduled tasks to load malicious DLLs for credential and browser data theft, and exfiltrated data over FTP (curl) — the report includes technical indicators and mitigation guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
