With Friends Like These: China Spies on Russian IT Orgs
ID: 3a040a79-8f18-54a8-92b9-18cc5ef025b1
STIX ID: report--3a040a79-8f18-54a8-92b9-18cc5ef025b1
Feed Name: Dark Reading
Positive Technologies disclosed a multi-year espionage campaign by China-aligned APT31 (Judgment Panda) against Russia's IT sector and government contractors observed from late 2022 with major activity in 2024–2025; attackers used targeted phishing with DLL sideloading, custom Windows and Linux backdoors (OneDriveDoor, CloudSorcerer, YaLeak, VtChatter), credential-stealers and local-file scraping, and abused legitimate cloud services (OneDrive, Dropbox, Yandex, VirusTotal) as covert C2 and exfiltration channels, suggesting sophisticated, state-level intelligence collection and IP theft.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
