logo

Web Server Exploits and Mimikatz Used in Attacks Targeting Asian Critical Infrastructure

ID: 024ca37e-2bf6-5b66-b520-dd7227e85711

STIX ID: report--024ca37e-2bf6-5b66-b520-dd7227e85711

Feed Name: The Hacker News

Threat Score
88/100

Date Published: 2026-03-09

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

Unit 42 describes a years-long Chinese-linked espionage campaign (CL-UNK-1068) targeting aviation, energy, government, law enforcement, pharmaceutical, technology, and telecommunications organizations across South, Southeast, and East Asia. The adversary employs a mix of custom malware, modified open-source utilities, web shells (e.g., Godzilla, ANTSWORD), Linux backdoors (Xnote), FRP for persistence, DLL side‑loading via legitimate Python binaries, and living‑off‑the‑land techniques to steal credentials and exfiltrate sensitive files (archived with WinRAR, Base64-encoded with certutil) while maintaining stealthy access.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.