logo

Chinese Cyberspies Employ Ransomware in Attacks for Diversion

ID: 9b12c2ae-0e4a-5c09-879d-17087928e8e4

STIX ID: report--9b12c2ae-0e4a-5c09-879d-17087928e8e4

Feed Name: Bleeping Computer

Threat Score
85/100

Date Published: 2024-06-27

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

SentinelLabs and Recorded Future describe activity by a suspected Chinese APT dubbed ChamelGang that has combined cyberespionage with ransomware (CatB) to target high-profile governments, healthcare and critical infrastructure between 2021–2023, while a related cluster used BestCrypt and BitLocker for mass encryption; analysts observed custom loaders (BeaconLoader), webshells (China Chopper), AD/DC compromise, and targeted intrusions affecting dozens of organizations and hundreds of systems.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.