logo

China Hijacks Captive Portals to Spy on Asian Diplomats

ID: e1b8a28a-d7c5-5b7b-8ae0-d374d360e8d6

STIX ID: report--e1b8a28a-d7c5-5b7b-8ae0-d374d360e8d6

Feed Name: Dark Reading

Threat Score
86/100

Date Published: 2025-08-27

Date Updated: 2026-05-05

Author: Nate Nelson, Contributing Writer

...
...

Google researchers attribute a campaign to Chinese state-linked APT Mustang Panda (UNC6384/TA416) that hijacked browser captive-portal checks via compromised edge devices to redirect victims to malicious, HTTPS-served pages. Victims—reported primarily as Southeast Asian diplomats—were tricked into running a signed downloader (STATICPLUGIN) that launched CANONSTAGER, which used API hashing and TLS arrays to load an encrypted PlugX variant (SOGU.SEC). The report highlights high sophistication (DLL sideloading, code-signing abuse) and observed compromise of roughly two dozen victims, indicating targeted espionage activity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.