logo

Chinese espionage tools deployed in RA World ransomware attack

ID: 30deda8d-d583-58ed-b23e-f6dc4adbc106

STIX ID: report--30deda8d-d583-58ed-b23e-f6dc4adbc106

Feed Name: Bleeping Computer

Threat Score
80/100

Date Published: 2025-02-13

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

A China-linked actor (Emperor Dragonfly / Bronze Starlight) used espionage tools—Korplug/PlugX via Toshiba DLL sideloading, NPS proxy, and RC4-encrypted payloads—after exploiting PAN-OS CVE-2024-0012 to deploy RA World ransomware against an Asian software and services company in late 2024; Symantec observed overlap between state-linked espionage tooling and financially motivated ransomware activity and published IoCs to help defenders.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.