logo

China-Linked Hackers Adopt Two-Stage Infection Tactic to Deploy Deuterbear RAT

ID: 2c7829ba-1609-5062-9635-57218126ccaf

STIX ID: report--2c7829ba-1609-5062-9635-57218126ccaf

Feed Name: The Hacker News

Threat Score
75/100

Date Published: 2024-05-17

Date Updated: 2026-05-05

Author: [email protected] (The Hacker News)

...
...

Security researchers detail that the China-linked BlackTech APT is deploying an evolved RAT called Deuterbear — a plugin- and shellcode-capable successor to Waterbear that uses DLL side-loading, dual-stage downloaders, and persistence mechanisms to conduct espionage in the Asia-Pacific region — while a separate, highly targeted campaign delivered SugarGh0st RAT to U.S. AI-related organizations likely to exfiltrate non-public AI information.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.