logo

'EastWind' Cyber-Spy Campaign Combines Various Chinese APT Tools

ID: 8b9c99ac-6dd0-5900-b72b-fcb70a7133ae

STIX ID: report--8b9c99ac-6dd0-5900-b72b-fcb70a7133ae

Feed Name: Dark Reading

Threat Score
85/100

Date Published: 2024-08-14

Date Updated: 2026-04-21

Author: Jai Vijayan, Contributing Writer

...
...

Kaspersky identified an espionage campaign named "EastWind" targeting Russian government entities where a China-nexus actor used phishing with malicious shortcut attachments to deploy malware that communicates with C2 servers hosted on popular cloud services (Dropbox, GitHub, Quora, Yandex). The attackers dropped tools and implants associated with APT31 and APT27 (including GrewApacha, CloudSorcerer, and PlugY) to perform broad reconnaissance and data-collection tasks such as file manipulation, shell execution, keystroke logging, and screen/clipboard monitoring.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.