logo

Chinese APT 'Emperor Dragonfly' Moonlights With Ransomware

ID: 9fd1ef42-85f7-5237-b17c-d1b702bfa717

STIX ID: report--9fd1ef42-85f7-5237-b17c-d1b702bfa717

Feed Name: Dark Reading

Threat Score
80/100

Date Published: 2025-02-13

Date Updated: 2026-04-21

Author: Kristina Beek, Associate Editor, Dark Reading

...
...

Symantec reported a late‑2024 intrusion in which attackers used a legitimate Toshiba executable (toshdpdb.exe) that loaded a malicious DLL to deploy a PlugX backdoor and ultimately install RA World ransomware against an unnamed Asian software/services company; the actors allegedly exploited Palo Alto PAN‑OS CVE‑2024‑0012, stole administrative and Veeam/Amazon S3 credentials to exfiltrate data, and demanded $2 million. Researchers observed the tool set has prior use in espionage intrusions against governments and telecoms and linked the activity to China‑associated Emperor Dragonfly (aka Bronze Starlight), noting the unusual overlap of espionage toolsets with ransomware activity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.