Chinese State-Backed Cyber Espionage Targets Southeast Asian Government
ID: 70b5fa28-d5d7-5fee-9d7e-684fe1a8bf50
STIX ID: report--70b5fa28-d5d7-5fee-9d7e-684fe1a8bf50
Feed Name: The Hacker News
Sophos researchers disclosed "Crimson Palace", a complex, long-running Chinese state‑sponsored cyber espionage campaign against an unnamed Southeast Asian government entity, composed of three overlapping intrusion clusters that used undocumented and known malware (including PocoProxy, EAGERBEE, EtherealGh0st, NUPAKAGE and others), extensive DLL sideloading, AV-evasion techniques, and loaders like HUI Loader to deploy Cobalt Strike; the report links activity to multiple China-nexus actors and notes similar APT41 operations and government advisories on increasing Chinese cyber threats.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
