logo

China-nexus APT Targets the Tibetan Community

ID: b414ae2d-5efd-555a-9122-9ebf4719d484

STIX ID: report--b414ae2d-5efd-555a-9122-9ebf4719d484

Feed Name: Zscaler Security Research Blog

Threat Score
78/100

Date Published: 2025-07-23

Date Updated: 2026-05-01

...
...

Operation GhostChat (June 2025) documents a targeted web compromise that replaced a legitimate tibetfund.org link with a fraudulent site (thedalailama90.niccenter.net) that lures users to download a backdoored Element client from tbelement.niccenter.net; the delivered TBElement.zip replaces legitimate ffmpeg.dll with a malicious ffmpeg.dll that loads embedded shellcode, performs ntdll mapping to evade hooks, injects shellcode into ImagingDevices.exe, establishes persistence via HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, reflectively loads a compressed stage 2 executable, and finally executes a Ghost RAT variant that communicates with C2 at 104.234.15.90:19999 using an RC4-like cipher and a custom "KuGou" packet header; the report includes technical details, C2 commands, a sample MD5 for a KuGou DLL, and observable IOCs (URLs, IP, MD5, registry paths).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.