logo

Chinese Hacker Group Tracked Back to iSoon APT Operation

ID: a3d2f818-305b-5786-b9b8-fb71e8203d8a

STIX ID: report--a3d2f818-305b-5786-b9b8-fb71e8203d8a

Feed Name: Dark Reading

Threat Score
88/100

Date Published: 2025-03-24

Date Updated: 2026-04-21

Author: Becky Bracken, Senior Editor, Dark Reading

...
...

ESET researchers expose "FishMedley," a global espionage campaign by the FishMonger/Aquatic Panda group—allegedly a paid hacking contractor (iSoon) for Chinese state agencies—that targets NGOs, think tanks, and governments using public backdoors and loaders (ShadowPad, Spyder, SodaMaster, RPipeCommander) to maintain long-term privileged access and exfiltrate confidential information.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.