China-Linked Hackers Hit Qatar with Backdoor Disguised as War News
ID: c61d3c51-366c-5645-8cd2-6eb077b3067c
STIX ID: report--c61d3c51-366c-5645-8cd2-6eb077b3067c
Feed Name: HackRead
**Executive summary:** Check Point Research observed a China-linked APT campaign (attributed to Camaro Dragon) using Middle East conflict-themed lures to target Qatar's energy and military sectors; attackers employed social-engineered files that initiate an infection chain, perform DLL hijacking of Baidu NetDisk to deploy the PlugX backdoor, and used a Rust-based loader hidden in NVDA to deliver Cobalt Strike. The campaign (active from 1 March 2026) includes a reused decryption key "20260301@@@" and demonstrates rapid pivoting and sophisticated TTPs aimed at espionage against critical infrastructure.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
