logo

Chinese Hackers Deploy SpiceRAT and SugarGh0st in Global Espionage Campaign

ID: 31539d5b-36d0-5597-b42e-e082e546c12c

STIX ID: report--31539d5b-36d0-5597-b42e-e082e546c12c

Feed Name: The Hacker News

Threat Score
85/100

Date Published: 2024-06-21

Date Updated: 2026-05-08

Author: [email protected] (The Hacker News)

...
...

**SneakyChef / Operation Diplomatic Specter**: A Chinese-speaking espionage cluster using SugarGh0st and a newly observed SpiceRAT has conducted targeted spear-phishing campaigns against government and AI-related organizations across Asia, EMEA, and beyond since at least late 2022/2023, employing lures (scanned diplomatic documents), RAR/SFX and HTA delivery, LNK shortcuts, DLL side-loading, scheduled tasks, and in-memory loaders to deploy RATs and maintain persistence.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.