logo

Chinese Cyber-Spies Use Espionage Tools for Ransomware Side Hustle

ID: c721be57-ec10-5df7-8e7c-272ebe9f26af

STIX ID: report--c721be57-ec10-5df7-8e7c-272ebe9f26af

Feed Name: Security Boulevard

Threat Score
75/100

Date Published: 2025-02-14

Date Updated: 2026-04-22

Author: Jeffrey Burt

...
...

Symantec linked a $2M RA World ransomware extortion against an Asian company to the same PlugX backdoor and toolset used in China-linked espionage campaigns (including Mustang Panda/Fireant). Attackers exploited CVE-2024-0012 in PAN-OS to steal admin and AWS S3 credentials, sideloaded a malicious DLL to deploy a custom PlugX variant, and may represent a case of espionage-tool “moonlighting” for financial gain; similar PlugX activity was later observed against multiple government and telecom targets.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.