RST TI Report Digest: 17 Nov 2025
ID: 9f32b1e9-5b0f-5f73-94cd-f71db1473c58
STIX ID: report--9f32b1e9-5b0f-5f73-94cd-f71db1473c58
Feed Name: RST Cloud Blog
Threat Score
**Executive Summary:** In 2025 Unit42 describes two large-scale impersonation campaigns (Trio and Chorus) targeting Chinese-speaking users by creating thousands of spoofed domains and delivering variants of the Gh0st RAT via MSI-based installers, intermediary domains and public cloud storage; the attackers used embedded VBScript and DLL side-loading to evade detection and the report provides numerous IOCs (IPs, domains, URLs, SHA-256 hashes).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
