Chinese APTs Hacking Asian Orgs With High-End Malware
ID: 093ff9b4-b016-5f6e-be25-0291aa384731
STIX ID: report--093ff9b4-b016-5f6e-be25-0291aa384731
Feed Name: Dark Reading
Trend Micro reports that China-linked APTs are using a flexible JScript-based C2 framework called PeckBirdy to conduct watering-hole and targeted espionage campaigns across the Asia-Pacific region: malicious scripts on compromised Chinese gambling sites delivered fake Chrome updates that install modular backdoors (Holodonut, MKDoor) and other payloads, while operators exploited a Chrome vulnerability (CVE-2020-16040) and leveraged living-off-the-land binaries (Mshta, ScriptControl, WScript, NodeJS, ASP) to evade detection and adapt to different environments, affecting both financially motivated and espionage-focused actors (tracked as Shadow-Void-044, Shadow-Earth-045 and others).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
