logo

'ChamelGang' APT Disguises Espionage Activities With Ransomware

ID: f1c36bb0-aea8-5f9b-9584-50f800f2a684

STIX ID: report--f1c36bb0-aea8-5f9b-9584-50f800f2a684

Feed Name: Dark Reading

Threat Score
88/100

Date Published: 2024-06-26

Date Updated: 2026-04-21

...
...

**Executive Summary:** SentinelOne and other researchers attribute a China-linked APT known as ChamelGang (CamoFei) with multi-year cyber-espionage campaigns against government, critical infrastructure, healthcare (including AIIMS), and other sectors across Asia, the Americas and elsewhere, noting the group's use of tools like Cobalt Strike and CatB ransomware—often deployed late in intrusions—to mask data theft and destroy forensic evidence, complicating attribution and incident response.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.