logo

China-Linked Hackers Hit Qatar with Backdoor Disguised as War News

ID: c61d3c51-366c-5645-8cd2-6eb077b3067c

STIX ID: report--c61d3c51-366c-5645-8cd2-6eb077b3067c

Feed Name: HackRead

Threat Score
85/100

Date Published: 2026-03-10

Date Updated: 2026-04-22

Author: Deeba Ahmed

...
...

**Executive summary:** Check Point Research observed a China-linked APT campaign (attributed to Camaro Dragon) using Middle East conflict-themed lures to target Qatar's energy and military sectors; attackers employed social-engineered files that initiate an infection chain, perform DLL hijacking of Baidu NetDisk to deploy the PlugX backdoor, and used a Rust-based loader hidden in NVDA to deliver Cobalt Strike. The campaign (active from 1 March 2026) includes a reused decryption key "20260301@@@" and demonstrates rapid pivoting and sophisticated TTPs aimed at espionage against critical infrastructure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.