China's APT41 Targets Taiwan Research Institute for Cyber Espionage
ID: 02c3d557-7116-54e7-ac99-b2744db5b625
STIX ID: report--02c3d557-7116-54e7-ac99-b2744db5b625
Feed Name: Dark Reading
Threat Score
China-linked APT41 compromised a Taiwanese government-affiliated advanced computing research institute beginning in July 2023, deploying ShadowPad and Cobalt Strike via a custom loader that leveraged a 2018 Windows RCE (CVE-2018-0824). The actors used credential-harvesting tools (Mimikatz, WebBrowserPassView), steganographic beacon delivery in images, and in-memory execution to map the network and exfiltrate research documents.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
