China-nexus APT Targets the Tibetan Community
ID: b414ae2d-5efd-555a-9122-9ebf4719d484
STIX ID: report--b414ae2d-5efd-555a-9122-9ebf4719d484
Feed Name: Zscaler Security Research Blog
Operation GhostChat (June 2025) documents a targeted web compromise that replaced a legitimate tibetfund.org link with a fraudulent site (thedalailama90.niccenter.net) that lures users to download a backdoored Element client from tbelement.niccenter.net; the delivered TBElement.zip replaces legitimate ffmpeg.dll with a malicious ffmpeg.dll that loads embedded shellcode, performs ntdll mapping to evade hooks, injects shellcode into ImagingDevices.exe, establishes persistence via HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, reflectively loads a compressed stage 2 executable, and finally executes a Ghost RAT variant that communicates with C2 at 104.234.15.90:19999 using an RC4-like cipher and a custom "KuGou" packet header; the report includes technical details, C2 commands, a sample MD5 for a KuGou DLL, and observable IOCs (URLs, IP, MD5, registry paths).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
