logo

Chinese Cyber Threat Lurks In Critical Asian Sectors for Years

ID: b6c120aa-52a8-5d36-88bc-5c572f90c63e

STIX ID: report--b6c120aa-52a8-5d36-88bc-5c572f90c63e

Feed Name: Dark Reading

Threat Score
88/100

Date Published: 2026-03-09

Date Updated: 2026-04-21

Author: Elizabeth Montalbano

...
...

Unit 42 reports that a Chinese-speaking threat cluster tracked as CL-UNK-1068 has conducted cross-platform cyber-espionage against critical infrastructure and government-related sectors across Asia since at least 2020, using web-server exploitation and web shells for initial access, credential-dumping tools (e.g., Mimikatz, LsaRecorder), custom scanners (ScanPortPlus), persistence techniques such as DLL sideloading via legitimate Python binaries, tunneling tools (modified FRP), and Linux backdoors (Xnote); the report includes IoCs and defensive guidance to detect and mitigate these activities.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.