Chinese hackers are increasingly deploying ransomware, researchers say
ID: afa00169-bb84-5927-ae3b-971ec57ac0ec
STIX ID: report--afa00169-bb84-5927-ae3b-971ec57ac0ec
Feed Name: CyberScoop
Researchers from SentinelLabs and Recorded Future report that Chinese-linked cyberespionage groups are increasingly deploying ransomware as a final stage to mask state-sponsored operations, create deniability, distract responders, or destroy forensic evidence; the report attributes suspected 2022 incidents (including attacks on the Brazilian presidency and AIIMS in India) to a cluster tracked as ChamelGang/CamoFei, cites precedent from APT41 and GRU disruptive operations, and describes a separate cluster using off-the-shelf tools against manufacturers across the Americas and Europe.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
