APT32 Hacker Group Attacking Cybersecurity Professionals Poisoning GitHub
ID: f83d980b-4d63-54d0-8184-aa440dd21d44
STIX ID: report--f83d980b-4d63-54d0-8184-aa440dd21d44
Feed Name: GBHackers
Threat Score
ThreatBook attributes a targeted supply-chain campaign to OceanLotus (APT32) in which a backdoored Cobalt Strike plugin and a malicious Visual Studio project (.suo) were published on GitHub to compromise Chinese cybersecurity professionals; the malware uses DLL hollowing, base64 encoding, and Notion for C2, exfiltrates data/identities, and ThreatBook published IOCs and detection guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
