Chinese hackers use new data theft malware in govt attacks
ID: 5c4bb05e-4478-5f83-aba9-c844ee64ec7e
STIX ID: report--5c4bb05e-4478-5f83-aba9-c844ee64ec7e
Feed Name: Bleeping Computer
Trend Micro observed Mustang Panda (aka Earth Preta) evolving its operations with new malware and tactics: a HIUPAN worm variant spreads PUBLOAD via removable drives, FDMTP is deployed via DLL side‑loading, and PTSOCKET or cURL is used for exfiltration; separate spear‑phishing campaigns deliver DOWNBAIT/PULLBAIT and a signed backdoor (CBROVER). The actor targets government and related organizations (primarily APAC), focuses on harvesting office documents and other sensitive files, and has published a comprehensive IoC list.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
