China-Linked Hackers Adopt Two-Stage Infection Tactic to Deploy Deuterbear RAT
ID: 2c7829ba-1609-5062-9635-57218126ccaf
STIX ID: report--2c7829ba-1609-5062-9635-57218126ccaf
Feed Name: The Hacker News
Threat Score
Security researchers detail that the China-linked BlackTech APT is deploying an evolved RAT called Deuterbear — a plugin- and shellcode-capable successor to Waterbear that uses DLL side-loading, dual-stage downloaders, and persistence mechanisms to conduct espionage in the Asia-Pacific region — while a separate, highly targeted campaign delivered SugarGh0st RAT to U.S. AI-related organizations likely to exfiltrate non-public AI information.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
