logo

China-Linked Threat Actor Taps 'Peculiar' Malware to Evade Detection

ID: c7500029-0fab-584f-aa2b-8fde6e6e10c8

STIX ID: report--c7500029-0fab-584f-aa2b-8fde6e6e10c8

Feed Name: Dark Reading

Threat Score
85/100

Date Published: 2024-04-02

Date Updated: 2026-04-21

Author: Jai Vijayan, Contributing Writer

...
...

Trend Micro researchers observed Earth Freybug (linked to APT41) deploying a new DLL malware called UNAPIMON that unhooks Windows API functions to prevent sandboxing and antivirus tools from monitoring child processes; the attack chain included code injection into vmstools.exe, creation of scheduled tasks running batch scripts, and DLL side-loading via the SessionEnv service to drop and execute the payload for stealthy persistence and defense evasion.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.