logo

Chinese APT41 Upgrades Malware Arsenal with DodgeBox and MoonWalk

ID: 429cd752-2958-5658-9eb7-3a7dd62c863e

STIX ID: report--429cd752-2958-5658-9eb7-3a7dd62c863e

Feed Name: The Hacker News

Threat Score
85/100

Date Published: 2024-07-11

Date Updated: 2026-05-08

Author: [email protected] (The Hacker News)

...
...

Zscaler ThreatLabz discovered DodgeBox, an improved variant of the StealthVector loader used by APT41 to deliver a modular backdoor named MoonWalk. DodgeBox employs DLL side-loading (via a signed taskhost.exe), DLL hollowing, call stack spoofing and other evasion techniques; MoonWalk leverages Windows Fibers, a plugin architecture, and a custom C2 protocol abusing Google Drive to blend with legitimate traffic. Samples were submitted from Thailand and Taiwan, and researchers assess the toolset as a sophisticated capability used for espionage and targeted intrusions.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.