Chinese hacking groups target Russian government, IT firms
ID: 94163e44-f6b8-50df-8598-e3da86b7d114
STIX ID: report--94163e44-f6b8-50df-8598-e3da86b7d114
Feed Name: Bleeping Computer
Threat Score
Kaspersky uncovered "EastWind," a targeted July 2024 cyberespionage campaign attributed to APT31 and APT27 that used phishing with RAR attachments and DLL side‑loading to drop updated CloudSorcerer, GrewApacha, and a new PlugY backdoor; the malware employs VMProtect, machine‑bound key generation, and public-profile C2 techniques to evade detection, with observable indicators such as large DLLs in C:\Users\Public, unsigned msedgeupdate.dll, and per-user msiexec.exe processes.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
