China-linked Hackers Deploy New 'UNAPIMON' Malware for Stealthy Operations
ID: 36b55071-14cb-5821-b36b-88fe9996f967
STIX ID: report--36b55071-14cb-5821-b36b-88fe9996f967
Feed Name: The Hacker News
Trend Micro attributes a cluster called Earth Freybug (a subset of APT41) with deploying a new C++ backdoor named UNAPIMON against organizations across multiple regions and sectors. The reported intrusion chain leverages a legitimate vmtoolsd.exe to create scheduled tasks that run cc.bat scripts, DLL side‑loading via the SessionEnv service (TSMSISrv.DLL) to drop and inject UNAPIMON, and employs API unhooking using Microsoft Detours to evade sandbox monitoring, enabling remote command execution and espionage activities.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
