Web Server Exploits and Mimikatz Used in Attacks Targeting Asian Critical Infrastructure
ID: 024ca37e-2bf6-5b66-b520-dd7227e85711
STIX ID: report--024ca37e-2bf6-5b66-b520-dd7227e85711
Feed Name: The Hacker News
Unit 42 describes a years-long Chinese-linked espionage campaign (CL-UNK-1068) targeting aviation, energy, government, law enforcement, pharmaceutical, technology, and telecommunications organizations across South, Southeast, and East Asia. The adversary employs a mix of custom malware, modified open-source utilities, web shells (e.g., Godzilla, ANTSWORD), Linux backdoors (Xnote), FRP for persistence, DLL side‑loading via legitimate Python binaries, and living‑off‑the‑land techniques to steal credentials and exfiltrate sensitive files (archived with WinRAR, Base64-encoded with certutil) while maintaining stealthy access.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
