Chinese and N. Korean Hackers Target Global Infrastructure with Ransomware
ID: aa2f824c-710d-548e-9645-cbb59389ecf1
STIX ID: report--aa2f824c-710d-548e-9645-cbb59389ecf1
Feed Name: The Hacker News
Threat actors with suspected China and North Korea ties conducted ransomware and encryption attacks globally from 2021–2023 against government and critical-infrastructure targets; one cluster (ChamelGang/CamoFei) used CatB ransomware and custom backdoors, while a second set of intrusions leveraged BestCrypt/BitLocker and artifacts linked to APT41 and Andariel. Researchers observed sophisticated tooling (BeaconLoader, Cobalt Strike, DoorMe, DTrack, China Chopper), estimated ~37 organizations targeted (notably in manufacturing and public sector), and warn that ransomware is being used as a final-stage tactic to monetize, disrupt, misattribute, or remove forensic evidence of espionage.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
