logo

China-linked Hackers Deploy New 'UNAPIMON' Malware for Stealthy Operations

ID: 36b55071-14cb-5821-b36b-88fe9996f967

STIX ID: report--36b55071-14cb-5821-b36b-88fe9996f967

Feed Name: The Hacker News

Threat Score
85/100

Date Published: 2024-04-02

Date Updated: 2026-05-05

Author: [email protected] (The Hacker News)

...
...

Trend Micro attributes a cluster called Earth Freybug (a subset of APT41) with deploying a new C++ backdoor named UNAPIMON against organizations across multiple regions and sectors. The reported intrusion chain leverages a legitimate vmtoolsd.exe to create scheduled tasks that run cc.bat scripts, DLL side‑loading via the SessionEnv service (TSMSISrv.DLL) to drop and inject UNAPIMON, and employs API unhooking using Microsoft Detours to evade sandbox monitoring, enabling remote command execution and espionage activities.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.