logo

Chinese hacking groups target Russian government, IT firms

ID: 94163e44-f6b8-50df-8598-e3da86b7d114

STIX ID: report--94163e44-f6b8-50df-8598-e3da86b7d114

Feed Name: Bleeping Computer

Threat Score
85/100

Date Published: 2024-08-11

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Kaspersky uncovered "EastWind," a targeted July 2024 cyberespionage campaign attributed to APT31 and APT27 that used phishing with RAR attachments and DLL side‑loading to drop updated CloudSorcerer, GrewApacha, and a new PlugY backdoor; the malware employs VMProtect, machine‑bound key generation, and public-profile C2 techniques to evade detection, with observable indicators such as large DLLs in C:\Users\Public, unsigned msedgeupdate.dll, and per-user msiexec.exe processes.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.