Chinese spies used Maduro's capture as a lure to phish US govt agencies
ID: d24bbfbf-02f4-5fd3-bae3-cd853ab4d7e3
STIX ID: report--d24bbfbf-02f4-5fd3-bae3-cd853ab4d7e3
Feed Name: The Register (Security)
Threat Score
Acronis Threat Research Unit uncovered a targeted phishing campaign, attributed with moderate confidence to Beijing-backed Mustang Panda, that used a geopolitical lure about US plans for Venezuela to deliver a DLL-sideloaded backdoor named Lotuslite hidden alongside a renamed legitimate Kugou launcher; the C++ implant establishes persistence, beaconing to hard-coded IP-based C2 and enables data theft from infected systems.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
