Chinese Cyber Threat Lurks In Critical Asian Sectors for Years
ID: b6c120aa-52a8-5d36-88bc-5c572f90c63e
STIX ID: report--b6c120aa-52a8-5d36-88bc-5c572f90c63e
Feed Name: Dark Reading
Unit 42 reports that a Chinese-speaking threat cluster tracked as CL-UNK-1068 has conducted cross-platform cyber-espionage against critical infrastructure and government-related sectors across Asia since at least 2020, using web-server exploitation and web shells for initial access, credential-dumping tools (e.g., Mimikatz, LsaRecorder), custom scanners (ScanPortPlus), persistence techniques such as DLL sideloading via legitimate Python binaries, tunneling tools (modified FRP), and Linux backdoors (Xnote); the report includes IoCs and defensive guidance to detect and mitigate these activities.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
