Chinese Cyberspies Employ Ransomware in Attacks for Diversion
ID: 9b12c2ae-0e4a-5c09-879d-17087928e8e4
STIX ID: report--9b12c2ae-0e4a-5c09-879d-17087928e8e4
Feed Name: Bleeping Computer
SentinelLabs and Recorded Future describe activity by a suspected Chinese APT dubbed ChamelGang that has combined cyberespionage with ransomware (CatB) to target high-profile governments, healthcare and critical infrastructure between 2021–2023, while a related cluster used BestCrypt and BitLocker for mass encryption; analysts observed custom loaders (BeaconLoader), webshells (China Chopper), AD/DC compromise, and targeted intrusions affecting dozens of organizations and hundreds of systems.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
