logo

Google issued ‘State-backed attack in progress’ warnings after spotting web hijack scheme

ID: 9f076ce7-6cb1-57d7-b8e9-2f64824887e1

STIX ID: report--9f076ce7-6cb1-57d7-b8e9-2f64824887e1

Feed Name: The Register (Security)

Threat Score
88/100

Date Published: 2025-08-27

Date Updated: 2026-04-26

Author: Simon Sharwood

...
...

Google Threat Intelligence observed a targeted, likely state-backed campaign (attributed to UNC6384 / TEMP.Hex) that hijacked captive portals on compromised edge devices to serve a malicious, code-signed installer (AdobePlugins.exe) which retrieves an MSI and installs CANONSTAGER and the SOGU.SEC backdoor; victims included diplomats in Southeast Asia and other global entities, and Google released indicators and mitigation guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.