'EastWind' Cyber-Spy Campaign Combines Various Chinese APT Tools
ID: 8b9c99ac-6dd0-5900-b72b-fcb70a7133ae
STIX ID: report--8b9c99ac-6dd0-5900-b72b-fcb70a7133ae
Feed Name: Dark Reading
Kaspersky identified an espionage campaign named "EastWind" targeting Russian government entities where a China-nexus actor used phishing with malicious shortcut attachments to deploy malware that communicates with C2 servers hosted on popular cloud services (Dropbox, GitHub, Quora, Yandex). The attackers dropped tools and implants associated with APT31 and APT27 (including GrewApacha, CloudSorcerer, and PlugY) to perform broad reconnaissance and data-collection tasks such as file manipulation, shell execution, keystroke logging, and screen/clipboard monitoring.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
