logo

Chinese and N. Korean Hackers Target Global Infrastructure with Ransomware

ID: aa2f824c-710d-548e-9645-cbb59389ecf1

STIX ID: report--aa2f824c-710d-548e-9645-cbb59389ecf1

Feed Name: The Hacker News

Threat Score
85/100

Date Published: 2024-06-26

Date Updated: 2026-05-08

Author: [email protected] (The Hacker News)

...
...

Threat actors with suspected China and North Korea ties conducted ransomware and encryption attacks globally from 2021–2023 against government and critical-infrastructure targets; one cluster (ChamelGang/CamoFei) used CatB ransomware and custom backdoors, while a second set of intrusions leveraged BestCrypt/BitLocker and artifacts linked to APT41 and Andariel. Researchers observed sophisticated tooling (BeaconLoader, Cobalt Strike, DoorMe, DTrack, China Chopper), estimated ~37 organizations targeted (notably in manufacturing and public sector), and warn that ransomware is being used as a final-stage tactic to monetize, disrupt, misattribute, or remove forensic evidence of espionage.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.