Chinese hackers hide on military and govt networks for 6 years
ID: 9eb26b09-ea80-5440-8e87-722230828d2e
STIX ID: report--9eb26b09-ea80-5440-8e87-722230828d2e
Feed Name: Bleeping Computer
A Bitdefender investigation profiles "Unfading Sea Haze," a China-aligned APT active since 2018 against South China Sea military and government targets. Attacks begin with spear-phishing ZIPs containing LNK files that run obfuscated PowerShell, abuse msbuild.exe to load fileless C# backdoors (SerialPktdoor) from remote SMB shares, and deploy Gh0stRAT variants, keyloggers, and custom exfiltration tools; the group also uses RMM tool abuse, local administrator account manipulation, DLL side-loading, and evolving exfiltration methods. Recommended defenses include patching, MFA, network segmentation, traffic monitoring, and modern detection/response tooling.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
