China Hijacks Captive Portals to Spy on Asian Diplomats
ID: e1b8a28a-d7c5-5b7b-8ae0-d374d360e8d6
STIX ID: report--e1b8a28a-d7c5-5b7b-8ae0-d374d360e8d6
Feed Name: Dark Reading
Google researchers attribute a campaign to Chinese state-linked APT Mustang Panda (UNC6384/TA416) that hijacked browser captive-portal checks via compromised edge devices to redirect victims to malicious, HTTPS-served pages. Victims—reported primarily as Southeast Asian diplomats—were tricked into running a signed downloader (STATICPLUGIN) that launched CANONSTAGER, which used API hashing and TLS arrays to load an encrypted PlugX variant (SOGU.SEC). The report highlights high sophistication (DLL sideloading, code-signing abuse) and observed compromise of roughly two dozen victims, indicating targeted espionage activity.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
