Chinese APT 'Emperor Dragonfly' Moonlights With Ransomware
ID: 9fd1ef42-85f7-5237-b17c-d1b702bfa717
STIX ID: report--9fd1ef42-85f7-5237-b17c-d1b702bfa717
Feed Name: Dark Reading
Date Published: 2025-02-13
Date Updated: 2026-04-21
Author: Kristina Beek, Associate Editor, Dark Reading
Symantec reported a late‑2024 intrusion in which attackers used a legitimate Toshiba executable (toshdpdb.exe) that loaded a malicious DLL to deploy a PlugX backdoor and ultimately install RA World ransomware against an unnamed Asian software/services company; the actors allegedly exploited Palo Alto PAN‑OS CVE‑2024‑0012, stole administrative and Veeam/Amazon S3 credentials to exfiltrate data, and demanded $2 million. Researchers observed the tool set has prior use in espionage intrusions against governments and telecoms and linked the activity to China‑associated Emperor Dragonfly (aka Bronze Starlight), noting the unusual overlap of espionage toolsets with ransomware activity.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
