China's APT41 Targets Global Logistics, Utilities Companies
ID: 6e07d31e-e428-5cdc-8392-33eacd393699
STIX ID: report--6e07d31e-e428-5cdc-8392-33eacd393699
Feed Name: Dark Reading
Mandiant (in collaboration with Google TAG) reports that APT41 has conducted a sustained espionage campaign since early 2023 against organizations in shipping/logistics, media/entertainment, technology, and automotive sectors across countries including the UK, Italy, Spain, Taiwan, Thailand, and Turkey. The actor employed custom web shells (AntsWord, BlueBeam), a dropper (DustPan), a multi-stage in-memory plugin framework (DustTrap), specialized exfiltration tools (PineGrove, SQLULDR2) and Beacon to maintain prolonged access and exfiltrate sensitive data, with evidence of broad geographic targeting and sophisticated post-compromise tooling.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
