Chinese Nexus Actors Shift Focus to Qatar Amid Iranian Conflict
ID: 185f54a1-e478-5b50-8eaa-9519a54e81a9
STIX ID: report--185f54a1-e478-5b50-8eaa-9519a54e81a9
Feed Name: Dark Reading
Check Point observed China-aligned APT activity rapidly pivoting to target Qatari organizations after the US-Israeli strike on Iran: one campaign by 'Camaro Dragon' used a malicious archive and LNK to chain into a DLL-hijack of a Baidu NetDisk binary to deploy the PlugX backdoor, while a separate campaign used a password-protected archive and a Rust-based loader abusing nvdaHelperRemote.dll to deploy Cobalt Strike; both used Iran-conflict themed lures and Check Point published IoCs and mitigation recommendations (EDR, MFA, etc.).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
