logo

RST TI Report Digest: 17 Nov 2025

ID: 9f32b1e9-5b0f-5f73-94cd-f71db1473c58

STIX ID: report--9f32b1e9-5b0f-5f73-94cd-f71db1473c58

Feed Name: RST Cloud Blog

Threat Score
75/100

Date Published: 2025-11-17

Date Updated: 2026-04-29

Author: RST Cloud

...
...

**Executive Summary:** In 2025 Unit42 describes two large-scale impersonation campaigns (Trio and Chorus) targeting Chinese-speaking users by creating thousands of spoofed domains and delivering variants of the Gh0st RAT via MSI-based installers, intermediary domains and public cloud storage; the attackers used embedded VBScript and DLL side-loading to evade detection and the report provides numerous IOCs (IPs, domains, URLs, SHA-256 hashes).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.