logo

Chinese Nexus Actors Shift Focus to Qatar Amid Iranian Conflict

ID: 185f54a1-e478-5b50-8eaa-9519a54e81a9

STIX ID: report--185f54a1-e478-5b50-8eaa-9519a54e81a9

Feed Name: Dark Reading

Threat Score
80/100

Date Published: 2026-03-11

Date Updated: 2026-04-21

Author: Elizabeth Montalbano

...
...

Check Point observed China-aligned APT activity rapidly pivoting to target Qatari organizations after the US-Israeli strike on Iran: one campaign by 'Camaro Dragon' used a malicious archive and LNK to chain into a DLL-hijack of a Baidu NetDisk binary to deploy the PlugX backdoor, while a separate campaign used a password-protected archive and a Rust-based loader abusing nvdaHelperRemote.dll to deploy Cobalt Strike; both used Iran-conflict themed lures and Check Point published IoCs and mitigation recommendations (EDR, MFA, etc.).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.