logo

Microsoft: Another Chinese cyberspy crew targeting US critical orgs 'as of yesterday'

ID: d90680d8-1ecd-542a-bf76-d41dbb1387df

STIX ID: report--d90680d8-1ecd-542a-bf76-d41dbb1387df

Feed Name: The Register (Security)

Threat Score
85/100

Date Published: 2024-12-06

Date Updated: 2026-04-26

Author: Jessica Lyons

...
...

Microsoft reports that China-linked espionage group Storm-2077 is actively targeting US government agencies and critical sectors (defense, aviation, telecoms, finance, legal, NGOs). The group gains initial access via public-facing web vulnerabilities and spearphishing, deploys the open-source SparkRAT for persistent remote access, and steals cloud credentials (including Microsoft 365/eDiscovery) to exfiltrate email and sensitive files for intelligence gathering.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.