Chinese Hackers Deploy SpiceRAT and SugarGh0st in Global Espionage Campaign
ID: 31539d5b-36d0-5597-b42e-e082e546c12c
STIX ID: report--31539d5b-36d0-5597-b42e-e082e546c12c
Feed Name: The Hacker News
Threat Score
**SneakyChef / Operation Diplomatic Specter**: A Chinese-speaking espionage cluster using SugarGh0st and a newly observed SpiceRAT has conducted targeted spear-phishing campaigns against government and AI-related organizations across Asia, EMEA, and beyond since at least late 2022/2023, employing lures (scanned diplomatic documents), RAR/SFX and HTA delivery, LNK shortcuts, DLL side-loading, scheduled tasks, and in-memory loaders to deploy RATs and maintain persistence.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
